Skip to main content

Introducing CamScan: A New IP Camera Discovery Tool for Linux

Finding every IP camera, NVR, and DVR on a local network can be surprisingly difficult. Devices may advertise themselves through ONVIF or mDNS, expose only an RTSP service, use a vendor-specific web endpoint, or respond on an unexpected port. CamScan brings these clues together in one Bash-based discovery tool designed for networks you own or are authorized to test.

The open-source project is available on GitHub at error0327/CamScanner. It is designed and tested around Kali Linux, while also including fallback package mappings for other supported systems where possible.

What makes CamScan useful?

CamScan does more than look for a single port. It combines multiple discovery and fingerprinting signals, then scores each host as a possible, likely, or confirmed camera device. This helps reduce noise while still surfacing devices that may not identify themselves in an obvious way.

  • Scans a subnet, IP range, or individual host.
  • Uses ARP discovery when available, with an Nmap ping sweep as a fallback.
  • Sends ONVIF WS-Discovery probes for strong camera detection.
  • Checks mDNS and Bonjour advertisements.
  • Scans common camera, recorder, RTSP, HTTP, and vendor ports.
  • Fingerprints HTTP titles, server headers, RTSP responses, and known vendor paths.
  • Exports structured results to CSV and JSON.
  • Can open an RTSP stream or capture a snapshot when valid credentials and a stream path are supplied.

Getting started

Clone or download the repository, make the script executable, and run it with the privileges required for local network discovery:

chmod +x camscan.sh
sudo ./camscan.sh

To run a single scan and export the findings:

sudo ./camscan.sh --once -o cams

For a deeper scan of a specific subnet:

sudo ./camscan.sh -t 192.168.1.0/24 -m deep

When an output prefix is provided, CamScan creates both CSV and JSON files. Results can include the IP and MAC addresses, vendor, confidence score, classification, relevant open ports, ONVIF URL, HTTP title or banner, RTSP server, detected model, and supporting evidence.

Requirements and optional integrations

The core requirements are Bash, Nmap, curl, the ip utility from iproute2, and timeout from GNU coreutils. Optional tools improve specific workflows: arp-scan speeds up local discovery, socat enables ONVIF probing, avahi-browse adds mDNS discovery, and players such as ffplay, mpv, or VLC can open live streams.

Built for responsible auditing

CamScan is intended for inventory, troubleshooting, and security auditing on authorized networks. Normal scans do not attempt to log in to devices. The optional --find-creds mode checks known default credentials and should be used only on equipment you own or have explicit permission to test.

This safety boundary matters. Camera systems can expose private video and sensitive network information, so discovery results and credentials should be handled carefully. CamScan is most valuable as a defensive tool: locating forgotten devices, documenting exposed services, verifying recorder deployments, and identifying systems that still rely on default paths or credentials.

A practical approach to camera inventory

By combining discovery protocols, service fingerprints, vendor clues, and confidence scoring, CamScan turns a messy manual process into a repeatable terminal workflow. If you manage cameras on a home lab, office network, or authorized security assessment, the project offers a practical starting point for building a clearer inventory.

Explore the source code, usage options, and latest updates on the CamScan GitHub repository.

 

Comments

Popular posts from this blog

ESP32-C6 Wi-Fi Logger with Browser GPS + Heat Map Dashboard

This project is an ESP-IDF firmware for the Seeed Studio XIAO ESP32-C6 that turns the board into a self-hosted, secure Wi-Fi scanning logger. It creates its own access point, serves a responsive HTTPS web UI, logs nearby Wi-Fi access points, optionally tags rows with GPS coordinates (provided by the client browser), and exposes battery status from the on-board LiPo input. The end result is a pocket Wi-Fi “survey” tool: scan, track, export logs as CSV, and generate a heat map view to visualize RSSI vs location. Project overview and feature set: :contentReference[oaicite:1]{index=1} What it does AP + Station mode so the device can serve the dashboard while scanning nearby Wi-Fi networks. HTTPS web interface using a bundled certificate/key for local secure access. Single scan and continuous tracking modes. CSV export for analysis and archiving. Persistent logging to SPIFFS at /spiffs/logs.csv . Battery monitoring via ADC with voltage/percentage/status sh...

סלקום ממש לא כדאי לקנות מאצלכם מודים

סלקום באמת מבאס לגלוש אתכם !! בשעה טובה ומצלחת קניתי מודם סלולארי על מנת שאוכל לגלוש באינטרנט בעזרתו. בעמדת המכירה הציעו לי את מסלול תשלום מראש הידוע כtalkman, מסלול זה התאים לצרכי כך שאוכל לדעת מראש כמה אשלם ובחרתי לבצע את העיסקה. כאשר התחלתי לגלוש לשרתים המספקים תוכן כגון rapidshare , megaupload , zshare ועוד גיליתי כי כתובת הIP ממנה אני גולש חסומה, או עברה את כמות השימוש המותרת אולם זה קורה לפני שאני ביצעתי שימוש כלשהוא. ניסיתי להשתמש בכתובות אחרות באמצעות קבלת כתובת IP אחרת (הוצאה והכנסה של המכשיר נותנת כתובת חדשה), אולם בכל ניסיון הכתובות היו חסומות, כלומר לא יכלתי להשתמש כלל בשירות. נתון זה שהכתבות כבר בשימוש ומי שמתמש בכתובת דינאמיות חסום לא נאמר לי ולא הועלה בעת המכירה. מה שקורה שבכל אתר שאני רוצה להשתמש בו אני חסום ולא יכול להשתמש. דברתי עם מספר חברים שיש להם מודמים כאלה כבר זמן רב , כששאלתי איך לפתור : אמרו כי הבעייה נפתרה לנו ע"י שינוי בתוך המודם ל: ABN = intereal ו זה בשפה המקצועית אומר " IP קבוע" שמחתי ל פתרון ו נגשתי ל סלקום אחרי 30 דקות המתנה...

Ollama Voice Chat — A Local, Talking AI Assistant for Windows

  Ollama Voice Chat — A Local, Talking AI Assistant for Windows I’m excited to share my latest open-source project: Ollama Voice Chat — a simple but powerful local voice chat assistant that runs fully on your machine using open-source AI tools. It lets you talk to a Large Language Model (LLM) and hear its responses spoken back out loud — no cloud APIs, no monthly fees, and full control of your data. 👉 GitHub repository: https://github.com/error0327/ollama-voice-chat 🚀 What Is It? Ollama Voice Chat is an interactive client for Windows that connects to a locally running LLM (via Ollama), converts user speech to text, sends it to the model, and uses Coqui TTS to speak the replies. It includes an automated setup script to streamline installation and configuration. Instead of typing, you can talk to your AI assistant and get spoken answers — great for hands-free use cases, prototyping voice UIs, or just having a more natural interaction with your models. 🧠 Why This Matte...