w3b.cam

internet voyeurism

Tips

Table of Contents

Cam hunting

An exposed camera advertises itself. Its web UI ships a fixed page title (an Axis M1124 reports Live view - AXIS M1124 Network Camera), its stream and snapshot endpoints sit at fixed paths (the fragments from the vendor sections above), and its service banner names the software. Two search engines have already cataloged that for you. Google crawls the pages, so you hunt it there with dorks. Shodan scans the ports and keeps the banners, so you hunt it there with filters. Both lean on the same fingerprints.

Caution

Treat these as discovery for cameras meant to be public (traffic, weather, and storefronts). Do not authenticate against a device you do not own, and honor robots.txt and each site's terms.

Google dorks

Google Dorking is searching with advanced operators to surface pages an ordinary query buries. It finds cameras because both of a camera's tells, the page title and the endpoint path, get crawled and indexed whenever the device is exposed without auth. A query that pins the title, the path, or both pulls the live ones straight out of the index. Most fragments below are the same paths as the vendor schemes above, so a hit on the fragment is a hit on the camera family.

Build a query in layers:

  1. Path. Start from a fragment: inurl:axis-cgi/mjpg/video.cgi.
  2. Title. Anchor it to a real page title to drop non-camera hits: intitle:"Live view - AXIS".
  3. Sweep. Widen across models or channels with *, |, or numrange.
  4. Trim. Cut the vendor's own docs and demos with -.

Layered together that reads intitle:"Live view - AXIS" inurl:axis-cgi/mjpg/video.cgi -inurl:doc, which returns live Axis views instead of forum threads about them.

Operators

These six operators carry most camera queries. Each row pairs the operator with a camera-tuned example.

operator what it does camera example
inurl: match a fragment anywhere in the URL inurl:axis-cgi/mjpg/video.cgi
allinurl: require every keyword in the URL allinurl:cam realmonitor channel
intitle: match words in the page title intitle:"Network Camera"
allintitle: require every keyword in the title allintitle:live view axis
site: restrict to a host or TLD site:.jp intitle:"Network Camera"
numrange: match a number range, or the X..Y shorthand inurl:Streaming/Channels numrange:101-402

Combine them to go from a noisy fragment to a short list of live cameras.

Exact phrase ("..."). Quote a title to match it verbatim. An Axis M1124 reports Live view - AXIS M1124 Network Camera, so "Live view - AXIS" pins the vendor without locking to one model.

Force a term. Google retired the old + operator, so quote a token to insist it appears. intitle:"Network Camera" "mjpg" forces the literal mjpg.

OR (|). Widen across vendor titles: intitle:"Live view" | intitle:"Network Camera". Those two catch a large share of cameras on their own.

AND (&). Require a title and a path together: intitle:"Network Camera" & inurl:mjpg. A plain space already means AND, so intitle:"Network Camera" inurl:mjpg is identical.

Group with parens. Mix OR and AND: (inurl:cam/realmonitor | inurl:Streaming/Channels) intitle:"Network Camera".

Wildcard (*). Stand in for the model name. intitle:"* Network Camera" catches AXIS M1124 Network Camera, D-Link Network Camera, and the rest; inurl:"Streaming/Channels/*/picture" catches any Hikvision channel.

Synonyms (~). Pull related words: ~live inurl:view also reaches "webcam" and "streaming" pages. Google has mostly retired this, so quoting is more reliable.

Sweep numbers (..). Enumerate channels and stream indexes. inurl:media/video 1..8 reaches Uniview video1 through video8; inurl:Streaming/Channels/101..402 sweeps Hikvision channel and stream codes. The older numrange:101-402 form still shows up in dork lists, but Google has mostly dropped it in favor of ...

Fragments by vendor

Axis.

Dahua and Amcrest.

D-Link and Vivotek. The live*.sdp and *.mjpg family.

Hikvision.

INSTAR and hi3510.

LILIN.

Sony.

Trendnet.

Uniview.

Mobotix. Guest and user view pages plus the fast M-JPEG API. Not yet in the vendor list above.

Panasonic / i-PRO. KX-HCM and BB/BL series network cameras. Not yet in the vendor list above.

Generic and unsorted. Broad fragments that match many brands, or ones not yet fingerprinted.

Shodan safari

Shodan is a search engine for internet-connected devices. Rather than crawl web pages like Google, it scans the internet, connects to each open port, and records the banner the service returns. A banner is the metadata a service volunteers on connection: the server software and version, the options it supports, a welcome message, and so on. Cameras leak their model straight into that banner, which turns Shodan into a fingerprinting tool. Match the banner and you have the model.

A query ANDs its terms together. A bare quoted string matches anywhere in the banner, a filter:value pair narrows to one field, and a leading - excludes; -401 drops the auth-required responses and leaves the open ones. Most filters need a free account.

filter matches camera example
"..." any text in the banner "Server: yawcam"
product: the software Shodan identified product:"D-Link DCS-930L"
html: text in the HTTP response body html:"AXIS M1124 Network Camera"
http.title: the page title http.title:"Network Camera"
http.component: a detected framework or library http.component:"mootools"
has_screenshot: devices with a captured screenshot has_screenshot:true
port: a specific service port port:554

Known-good queries to start from:

target query
Safari Zone! "Server: Camera"
Samsung electronic billboards "Server: Prismview Player"
Yawcam "Server: yawcam" "Mime-Type: text/html"
webcamXP / webcam7 ("webcam 7" OR "webcamXP") http.component:"mootools" -401
Android IP Webcam Server "Server: IP Webcam Server" "200 OK"
Security DVRs html:"DVR_H264 ActiveX"
Axis M1124 html:"AXIS M1124 Network Camera"
Apexis APM-H803-MPC product:"Apexis APM-H803-MPC"
D-Link DCS-5020L webcam http interface product:"D-Link DCS-5020L webcam http interface"
D-Link DCS-930L webcam http interface product:"D-Link DCS-930L webcam http interface"
D-Link DCS-930LB1 webcam http interface product:"D-Link DCS-930LB1 webcam http interface"
D-Link DCS-931L webcam http interface product:"D-Link DCS-931L webcam http interface"
D-Link DCS-932L webcam http interface product:"D-Link DCS-932L webcam http interface"
D-Link DCS-932LB1 webcam http interface product:"D-Link DCS-932LB1 webcam http interface"
D-Link DCS-5211L product:"D-Link DCS-5211L"
D-Link DCS-5222L product:"D-Link DCS-5222L"
D-Link DCS-930L product:"D-Link DCS-930L"
D-Link DCS-936L product:"D-Link DCS-936L"
D-Link DCS-942L product:"D-Link DCS-942L"
D-Link DCS-942LB1 product:"D-Link DCS-942LB1"
D-Link and Airlink IP "Server: Camera Web Server/1.0"
D-Link/Airlink IP webcam http config product:"D-Link/Airlink IP webcam http config"
D-Link webcams (others) "Server: alphapd"
Dahua-based CM-Hybrid NVR 3108-I3 product:"Dahua-based CM-Hybrid NVR 3108-I3"
Hikvision IP Camera product:"Hikvision IP Camera"
Panasonic BB-SC384B webcam http config product:"Panasonic BB-SC384B webcam http config"
Panasonic BB-SW172 webcam http config product:"Panasonic BB-SW172 webcam http config"
Panasonic DG-SP304 webcam http config product:"Panasonic DG-SP304 webcam http config"
Panasonic WV-SC385 webcam http config product:"Panasonic WV-SC385 webcam http config"
Panasonic WV-SF135 webcam http config product:"Panasonic WV-SF135 webcam http config"
Panasonic WV-SW158 webcam http config product:"Panasonic WV-SW158 webcam http config"
TRENDnet IP Camera product:"TRENDnet IP Camera"
Trendnet TV-IP572PI product:"Trendnet TV-IP572PI"
Trendnet TV-IP662WI product:"Trendnet TV-IP662WI"
Trendnet TV-IP672W product:"Trendnet TV-IP672W"
Trendnet TV-IP672WI product:"Trendnet TV-IP672WI"
Trendnet TV-IP862IC product:"Trendnet TV-IP862IC"
VCS-VideoJet-Webserver httpd product:"VCS-VideoJet-Webserver httpd"
Vivotek IP7131 Network Camera http config product:"Vivotek IP7131 Network Camera http config"
Yawcam webcam viewer httpd product:"Yawcam webcam viewer httpd"
webcam 7 httpd product:"webcam 7 httpd"
webcamXP 5 product:"webcamXP 5"

Tip

Shodan captures a screenshot from many camera services. Append has_screenshot:true to jump straight to the ones you can preview, and narrow to a region with country:, city:, or org:. Censys and ZoomEye index the same banners with similar filters.


Tips for viewing web cams

How to use this section

Every URL below uses these placeholders. Substitute your camera's real values.

Main vs sub stream. Most cameras publish at least two streams. The main stream is full resolution. The sub stream is a lower-resolution copy that is cheaper to decode and lighter on bandwidth, so reach for it when you only need thumbnails or a multi-camera wall.


Generic patterns

Try these before you know the brand. They work on a large share of ONVIF-compliant cameras.

Some cameras use /h264Preview_01_main and /h264Preview_01_sub in place of /stream1 and /stream2. HTTP snapshot and MJPEG paths are almost always vendor-specific, so drop down to By vendor when the generic ones fail.

Check the codec

Some clients only decode Motion JPEG or H.264. MATLAB is one, and several lightweight players and libraries are the same. Confirm the codec in VLC before wiring a stream into anything:

By vendor

Each entry lists the vendor's path scheme and any specific models confirmed to use it.

Axis
CP Plus

CP Plus speaks the Dahua realmonitor API, so treat it as Dahua-family (see Dahua and Amcrest).

Dahua and Amcrest

Both use the Dahua HTTP and RTSP API. subtype selects the stream (0 main, 1 sub); channel is 1-based.

Foscam
Hikvision

Hikvision uses the ISAPI/Streaming scheme. The channel number encodes both channel and stream: 101 is channel 1 main, 102 is channel 1 sub.

INSTAR

RTSP streams use numeric paths and HTTP snapshots live under /tmpfs/. INSTAR HD models run the hi3510 chipset, so the CGI paths below turn up on rebadged cameras from other brands too (see By chipset or pattern).

LILIN
Sony
Trendnet
Uniview

Uniview (UNV) covers both standalone cameras (IPC) and NVRs, and the paths differ between the two.

NVR

IPC (standalone camera)

Multi-sensor bodies

Vivotek

By chipset or pattern

For cameras you cannot pin down to an exact model, record the URL scheme and any chipset fingerprint. These families cross brands, so a match narrows the guess even with no model number.

When you find a new one, note the working URL, the protocol, the codec (from VLC), the default port, and anything the login page or HTTP response headers reveal (the Server header, the auth realm, or on-page branding). That is usually enough to slot the camera into a family later.


Protecting your anonymity

Caution

I don't advise poking around other people's webcams (open or not) using your real IP. I suggest using a VPN or proxy. VPNs are virtual private networks that encrypt all web activity and device IP addresses. A proxy server, on the other hand, is a computer that stands between the user and their server. It hides only their device's IP address, not all of their web activity.

Common Types of Proxy Servers:

Tip

Use a VPN to bypass transparent proxy servers and circumvent access restrictions.

VPNs versus proxies

Similar characteristics:

Key differences:

Finding fresh proxies

I use the proxychains-ng terminal application. It's designed for using proxies, not sourcing them. You need to provide your own list via a config file.

The Fresh Proxies project publishes new hosts daily. The following bash script automates the process of downloading and formatting them into a valid configuration file.

#!/usr/bin/env bash## freshproxies: fetch fresh public proxies and print a complete proxychains-ng# config to stdout (or write it atomically with -o).## author: xero (https://x-e.ro)# sources: https://vakhov.github.io/fresh-proxy-list/## usage:#   ./freshproxies > ~/.config/proxychains/config#   sudo ./freshproxies -o /etc/proxychains.conf#   ./freshproxies --types "socks5,socks4" --chain round_robin_chain --len 2#set -euo pipefail# Overridable via env for testing / mirrors.BASE_URL="${FRESHPROXIES_BASE_URL:-https://vakhov.github.io/fresh-proxy-list}"CURL_MAX_TIME="${FRESHPROXIES_CURL_MAX_TIME:-20}"# Defaults. A zero-arg run = dump every proxy, one random proxy per connection.CHAIN="random_chain"CHAINLEN=1TYPES="socks5 socks4 http https"OUTPUT=""SCRIPT_DIR="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)"TEMPLATE="$SCRIPT_DIR/proxychains-default.conf"die() { printf 'freshproxies: %s\n' "$1" >&2; exit "${2:-1}"; }usage() {  cat <<'EOF'freshproxies — generate a proxychains-ng config from fresh public proxiesUSAGE:  freshproxies [options]            print config to stdout  freshproxies -o FILE [options]    write config atomically to FILEOPTIONS:  -o, --output FILE   write to FILE (atomic; safe for /etc) instead of stdout      --chain MODE    random_chain (default) | strict_chain | dynamic_chain | round_robin_chain      --len N         chain_len value (default 1; only used by random/round_robin)      --types LIST    subset of: socks5 socks4 http https (default: all)      --template FILE header template (default: proxychains-default.conf next to script)  -h, --help          show this helpEXAMPLES:  freshproxies > ~/.config/proxychains/config  sudo freshproxies -o /etc/proxychains.conf  freshproxies --types "socks5,socks4"EOF}# Full documented header generated only when the bundled conf is missing (e.g. the# script was copied somewhere on its own), so output stays complete and portable.embedded_header() {  cat <<'PCHDR'# proxychains.conf  VER 4.x# HTTP, SOCKS4a, SOCKS5 tunneling proxifier with DNS.## Examples:# socks5 192.168.67.78 1080 lamer secret# http   192.168.89.3  8080 justu hidden# socks4 192.168.1.49  1080# http   192.168.39.93 8080## proxy types: http, socks4, socks5, raw# * raw: The traffic is simply forwarded to the proxy without modification.# ( auth types supported: "basic"-http  "user/pass"-socks )#PCHDR}while [[ $# -gt 0 ]]; do  case "$1" in    -o|--output)  shift; OUTPUT="${1-}";   [[ -n "$OUTPUT"   ]] || die "-o/--output requires a value" 2;;    --chain)      shift; CHAIN="${1-}";    [[ -n "$CHAIN"    ]] || die "--chain requires a value" 2;;    --len)        shift; CHAINLEN="${1-}"; [[ -n "$CHAINLEN" ]] || die "--len requires a value" 2;;    --types)      shift; TYPES="${1-}";    [[ -n "$TYPES"    ]] || die "--types requires a value" 2;;    --template)   shift; TEMPLATE="${1-}"; [[ -n "$TEMPLATE" ]] || die "--template requires a value" 2;;    -h|--help)    usage; exit 0;;    --)           shift; break;;    -*)           usage >&2; die "unknown option: $1" 2;;    *)            usage >&2; die "unexpected argument: $1" 2;;  esac  shiftdone# validationcase "$CHAIN" in  random_chain|strict_chain|dynamic_chain|round_robin_chain) ;;  *) die "invalid --chain '$CHAIN' (random_chain|strict_chain|dynamic_chain|round_robin_chain)" 2;;esac[[ "$CHAINLEN" =~ ^[1-9][0-9]*$ ]] || die "--len must be a positive integer (got '$CHAINLEN')" 2TYPES="${TYPES//,/ }"tmp="$(mktemp "${TMPDIR:-/tmp}/freshproxies.XXXXXX")"final="$(mktemp "${TMPDIR:-/tmp}/freshproxies.XXXXXX")"out_tmp=""cleanup() { rm -f "$tmp" "$final" "${out_tmp:-}"; }trap cleanup EXITfetch_list() {  local emit="$1" file="$2" body  if body="$(curl -fsL --max-time "$CURL_MAX_TIME" "$BASE_URL/$file" 2>/dev/null)"; then    printf '%s\n' "$body" | tr -d '\r' \      | awk -F: -v t="$emit" '/^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+:[0-9]+$/ { print t, $1, $2 }' \      >> "$tmp"  else    printf 'freshproxies: warning: could not fetch %s (skipping)\n' "$file" >&2  fi}for t in $TYPES; do  case "$t" in    socks5) fetch_list socks5 socks5.txt;;    socks4) fetch_list socks4 socks4.txt;;    http)   fetch_list http   http.txt;;    https)  fetch_list http   https.txt;;   # proxychains has no https type    *)      die "invalid type '$t' in --types (use: socks5 socks4 http https)" 2;;  esacdone# deduplicationawk '!seen[$0]++' "$tmp" > "$final"count="$(wc -l < "$final" | tr -d '[:space:]')"[[ "$count" -gt 0 ]] || die "no proxies fetched. refusing to write an empty config"if [[ -f "$TEMPLATE" ]]; then  header_raw="$(awk '/^\[ProxyList\]/{exit} {print}' "$TEMPLATE")"else  header_raw="$(embedded_header)"fiheader="$(printf '%s\n' "$header_raw" \  | sed -E 's/^(strict_chain|dynamic_chain|round_robin_chain|random_chain|chain_len)/#&/')"chain_block="$CHAIN"if [[ "$CHAIN" == "random_chain" || "$CHAIN" == "round_robin_chain" ]]; then  chain_block="$chain_block"$'\n'"chain_len = $CHAINLEN"finow="$(date -u '+%Y-%m-%dT%H:%MZ')"render() {  printf '%s\n' "$header"  printf '\n# --- chain mode (set by freshproxies) ---\n'  printf '%s\n' "$chain_block"  printf '\n# generated by freshproxies | %s proxies | chain=%s len=%s | %s\n' \    "$count" "$CHAIN" "$CHAINLEN" "$now"  printf '%s\n' '[ProxyList]'  cat "$final"}if [[ -n "$OUTPUT" ]]; then  dir="$(dirname -- "$OUTPUT")"  [[ -d "$dir" ]] || die "output directory does not exist: $dir"  out_tmp="$(mktemp "$dir/.freshproxies.XXXXXX")" \    || die "cannot create temp file in $dir (permission? try sudo)"  render > "$out_tmp"  mv -- "$out_tmp" "$OUTPUT" || die "could not move config into place: $OUTPUT"  out_tmp=""  printf 'freshproxies: wrote %s proxies to %s\n' "$count" "$OUTPUT" >&2else  renderfi

Usage Examples

Many programs work transparently by just prefixing the command with proxychains4:

freshproxies > ~/.config/proxychains/configproxychains4 curl icanhazip.comproxychains4 firefox

To use with Google Chrome, you must disable sandboxing, otherwise the preloaded proxying library crashes.

freshproxies > ~/.config/proxychains/configproxychains4 google-chrome --no-sandbox

To run vlc media player, you must use a tcp-based socks4/5 proxy in your configuration, as proxychains does not support udp.

freshproxies --types "socks5,socks4" > ./pchains.cfgproxychains4 -f ./pchains.cfg vlc

To use with nmap you need the -sT flags for TCP Connect scans, as SYN/UDP scans require raw sockets that proxychains cannot route.

sudo freshproxies -o /etc/proxychains.confsudo proxychains4 nmap -sT -Pn -p 80 192.168.1.1