Skip to content

Instantly share code, notes, and snippets.

@SolveSoul
Created August 18, 2021 08:56
Show Gist options
  • Select an option

  • Save SolveSoul/9be5d9599c8b4b59f7cfa4cd0ce79c9c to your computer and use it in GitHub Desktop.

Select an option

Save SolveSoul/9be5d9599c8b4b59f7cfa4cd0ce79c9c to your computer and use it in GitHub Desktop.
V380 Pro Activate ONVIF/RTSP
[CONST_PARAM]
rtsp = 1 ; RTSPЭ�飬0���ر� 1������
V380 Pro cameras have rtsp/onvif disabled by default. This can be unlocked by inserting an SD-card into the camera.
A step-by-step guide can be found below:
1) Download the V380 Pro app from the App Store or Google Play
2) Register or continue without registering
3) Boot your camera and couple it to the application
4) Set a custom username and password for your camera
5) Download the 'ceshi.ini' file and put it on the root of a micro SD card (so not in a subfolder)
6) Power down the camera, insert the SD card and boot the camera
7) The camera will talk in chinese, wait for 5 minutes (probably shorter, but to be sure)
8) Power down the camera, remove the SD card, delete the file and power up the camera
9) Connect to your camera using the protocol rtsp://username:password@ipaddress:554/live/ch00_0
10) DONE
A great way to test is downloading/using VLC and opening a network stream.
@AndryanZulfi

Copy link
Copy Markdown

I got mine working with a different ceshi.ini contents:

[CONST_PARAM]

rtsp_enable = 1

#MineToo!

1000097048

hello, can you send me product link?

@Arif285741

Copy link
Copy Markdown

Does anyone Onvif? If not, there is a 3-lens outdoor CCTV that does not have problems with the ceshi.ini file. Can you provide a link to purchase the product?

@jericjan

jericjan commented Dec 8, 2025

Copy link
Copy Markdown

https://github.com/prsyahmi/v380/

This application is for V380 cameras that do not have the RTSP protocol and cannot be activated (for example with the ceshi.ini file) and transmit through port 8800. Unfortunately, in the latest firmware versions, the stream was encrypted in some way and cannot be played yet. But there are people with knowledge in this field working on it.

Hi, was there any update on this? Although, I'm more interested in how it sends audio from the phone mic to the camera. I tried analyzing the packets but it just seems like random noise so that might also be encrypted

UPDATE: I did end up figuring out the encryption for the audio packets. I'm pretty sure it follows the same algorithm for the video packets as well, but I can't be bothered to look into it. Made a little python program that automates it (https://github.com/jericjan/v380-audio-player)

@cuenta1

cuenta1 commented Dec 8, 2025

Copy link
Copy Markdown

Hi, it seems they tried studying the code for both the phone and PC apps, but no one has been able to make the stream playable. I think the project is abandoned. I'd also like someone with the necessary skills to figure it out.

@zvhh

zvhh commented Dec 11, 2025

Copy link
Copy Markdown

i also have camera with 3 lens
when i try ceshi method the camera format itself and not runs until i remove sd card then format it self after removing sd card

anyone has the fix for this ?

@zvhh

zvhh commented Dec 11, 2025

Copy link
Copy Markdown

i also have camera with 3 lens when i try ceshi method the camera format itself and not runs until i remove sd card then format it self after removing sd card

anyone has the fix for this ?

https://image.made-in-china.com/202f0j00cRTePdVlANqh/V380-New-3-Lens-and-3-Screen-Sc28-G-Black-6MP-Security-CCTV-Wireless-IP-Security-4G-Network-PTZ-Triple-Lens-Camera-Sc28.webp

this exactly my camera

@AndryanZulfi

Copy link
Copy Markdown

Okay so I bought 3 V380 Pro cameras from 2 different sellers, and all 3 are different. It's the black unit with one static lens and one PTZ lens/sensor. Video comes out as one square (ish) feed. All cameras look identical. image Seller A: White cable image

Seller B: 2 units, black cable (but apparently different somehow), we'll name it QC2 and QC9. image QC9

image QC2

All units are on latest firmware without need to update when arrived. In windows, I use a new, original, non-fake SD card, formatted as FAT32. I create a text document called ceshi.ini, and TYPED (not copied the above example with the random characters after rtsp=1) [CONST_PARAM] rtsp=1

Seller A, white cable version: image

Onvif menu appears. image Label shows QR code, the device number, User:admin and random numbers as password (eg.123546673-9)

Seller B, QC9: QC9 DOES NOT NEED to use ceshi.ini as it is onvif-enabled by default, but... image RTSP audio option appears as well as ONVIF setting option like white cable version. image Label shows QR code, device number/id, User:admin and QC:09

Seller B, QC2: image rtsp=1 DOES NOT WORK. VLC can't access the stream. image Same as QC9, but this time it says QC:02

will try rtsp_enable=1 later... stupid sd card fell down and I can't find it :D EDIT: CONFIRMED, QC2 needs to use rtsp_enable=1 instead of rtsp=1. White Cable needs rtsp=1.

Hello sir, Currently I need a CCTV with QC9 specifications that supports RTSP audio. Can you provide the model name or provide a purchase link?

@Aientasar

Copy link
Copy Markdown

anyone from India ,who has used this process and was successfull,im planning to buy Tp plus cameras,it says the camera need v380 pro.

if someone from has used this method ,please provide links of the camera used,it will be very helpful

@gvxb21788

Copy link
Copy Markdown

I had a talk with another v380 tech (probably a senior tech) and he mentioned that only dual cams v380 (prominent on outdoor models) have onvif & rtsp. So i decided to buy a dual cam v380 and it really has onvif and rtsp. But the downside is that both cameras are stacked and merged into a single stream (1920 x 2160) and unfortunately our NVR doesn't support that resolution.

I'm still finding ways to separate each cams into individual 1080p streams 20240104_123637 20240104_112816

May I know that rtsp stream url for that model, I also have the same one

@Dobeywantsacracker

Copy link
Copy Markdown

Please can anyone find out the flags/switches to enable Humandoid AI detection?

I have a strong suspicion that these cameras actually have hardware support for Humanoid AI detection but because they are now selling a subscription to use DeepSeek Ai instead they are actively disabling them so it becomes a paid service. I have 2 exact camera models that have Humandoid AI detection built in. But sadly they don't have telnet open so I can't go digging into how this works.

@browserait

browserait commented Jan 22, 2026

Copy link
Copy Markdown

i also have camera with 3 lens when i try ceshi.ini method the camera formats itself to factory settings then i turn off the camera and delete the file from the sdcard and put it back after i turn th camera back on. its useless because it has already reset to factory settings.
anyone has the fix for this ?

Any Solution Available we have the same cctv camera model? the thing is when we use this ceshi.ini method the camera reset itself to factory settings that is why it talk chinese. any help solution for this will be much appreciated thank you TS.
3lens 3screen camera

@zvhh

zvhh commented Jan 22, 2026

Copy link
Copy Markdown

i also have camera with 3 lens when i try ceshi.ini method the camera formats itself to factory settings then i turn off the camera and delete the file from the sdcard and put it back after i turn th camera back on. its useless because it has already reset to factory settings.
anyone has the fix for this ?

Any Solution Available we have the same cctv camera model? the thing is when we use this ceshi.ini method the camera reset itself to factory settings that is why it talk chinese. any help solution for this will be much appreciated thank you TS. 3lens 3screen camera

Still no luck unfortunately

@LaloReyes

LaloReyes commented Jan 28, 2026

Copy link
Copy Markdown

Me funciono con una camara doble les comparto para crear el archivo con nombre y tipo ceshi.ini


[CONST_PARAM]
rtsp_enable = 1


No funciono con VLC
Si funciona IPCams de IOS Apple
Si funciona IP Camara Lite de IOS Apple
rtsp://IPCAM:554/live/ch00_1
or
rtsp://IPCAM/live/ch00_0

Datos de mi camara V380 Pro Modelo Desconocido Marca Desconocida
Dual Lens 2K 4MP Wireless PTZ Security Camera,2K 4MP
IMG_2403

Saludos desde México

@rraallvv

Copy link
Copy Markdown

@LaloReyes, can you access the data stream without a password, even if one is set in the app?

@LaloReyes

Copy link
Copy Markdown

@LaloReyes, can you access the data stream without a password, even if one is set in the app?

Asi es no requiere usuario y contraseña

@Jobinjose01

Copy link
Copy Markdown

worked well for this model
used
ceshi.ini file as follows

[CONST_PARAM]
rtsp = 1
rtsp_enable = 1
rtsp_ctrl = 1

@popilirol

popilirol commented Mar 4, 2026

Copy link
Copy Markdown

I purchased one V380 Pro camera and tried to activate RTSP and ONVIF through ceshi.ini. Unfortunately, I could not see any option for doing so in Advanced Settings.

I read online that some later models may be encrypted and there is nothing we can do about it to make RTSP and ONVIF optionally enabled. Any help is greatly appreciated, thanks.

IMG_2324

@Jobinjose01

Copy link
Copy Markdown

@popilirol There won't be any new menus or configuration on the settings menu after doing the mentioned steps but it will open up the RTSP feed so you can access the stream, only problem is it won't have a password I think there is option to set that too but in my case I'm writing the stream to Disk using Raspberry Pi everything is local so no problem with credentials.

Try this
create the ceshi.ini with

[CONST_PARAM]
rtsp = 1
rtsp_enable = 1
rtsp_ctrl = 1

Insert into camera power on it will speak something in Chinese after few min turn off the camera remove the SD card delete the ceshi.ini file and insert back to camera and power on it may ask for re-pair again with mobile device.

then try to access the stream like below

rtsp://192.168.1.108:554/live/ch00_1

from VLC you can test it out , It should work

@popilirol

popilirol commented Mar 5, 2026

Copy link
Copy Markdown

@popilirol There won't be any new menus or configuration on the settings menu after doing the mentioned steps but it will open up the RTSP feed so you can access the stream, only problem is it won't have a password I think there is option to set that too but in my case I'm writing the stream to Disk using Raspberry Pi everything is local so no problem with credentials.

Try this create the ceshi.ini with

[CONST_PARAM]
rtsp = 1
rtsp_enable = 1
rtsp_ctrl = 1

Insert into camera power on it will speak something in Chinese after few min turn off the camera remove the SD card delete the ceshi.ini file and insert back to camera and power on it may ask for re-pair again with mobile device.

then try to access the stream like below

rtsp://192.168.1.108:554/live/ch00_1

from VLC you can test it out , It should work

Jobin, thanks for your reply. I tried VLC and ODM, and I tried all URLs:
rtsp://username:password@IPaddress:554/live/ch00_0
rtsp://username:password@IPaddress:554/live/ch00_1
rtsp://username:password@IPaddress:554/11
rtsp://username:password@IPaddress:554
rtsp://IPaddress:554

I managed to add a custom username and password from the menu, but none of these could allow the camera to stream.

P.S. Today V380 replied to me and told me that my model does not support RTSP/ONVIF. This sucks because I hate the V380 app because it is so limited and basic, and I already have purchased in the past Blue Iris, an amazing piece of software for managing all kinds of IP cameras.

@pergolafabio

Copy link
Copy Markdown

hmm, got myself an v380 pro mini, but seems this ini hack doesnt work? anyone tried it on the v380 pro mini?

image

@Dobeywantsacracker

Copy link
Copy Markdown

Hi did you check the V380 pro app under advanced settings? Try turning on Onvif support.

Otherwise try requesting RTSP support on this email address: v380technical@gmail.com

@zvhh

zvhh commented Mar 16, 2026 via email

Copy link
Copy Markdown

@Dobeywantsacracker

Copy link
Copy Markdown

Not a scam but good on you to be cautious. I used them as well although I didn't get far.

I got the email from the parent company of the V380 camera system it's called M@crovideo

https://www.macro-video.com/en-us/1/0/4/service.html

And the same email is referenced on other forums related to V380 camera modding stuff, like this one:

https://community.netcamstudio.com/t/v380-stream-url/2778/47?page=2

@pergolafabio

Copy link
Copy Markdown

hmm, i dont see any onvif or rtsp setting , under advanced settings there is only static/dhcp ip
gonna send them a mail...

image

@milkboy007

Copy link
Copy Markdown

@popilirol ......

Try this create the ceshi.ini with

[CONST_PARAM]
rtsp = 1
rtsp_enable = 1
rtsp_ctrl = 1

Just reporting so that it helps any one who search
it works on V380 BQ8 Dual camera lens model (from my batch any ways i bought 3, 2 dual camera lens, 1 tri camera lens )

prior to tyhe ceshi file it does not show onvif toggle, now it is visible even after reboot
rtsp also works.

Model: V380 BQ8 Dual Lens
Software version:AppEV3L_V2_V1.0.5.2_20250102
Firmware version:Hw_HsAkQQVL_WF_QQ_20240412

WhatsApp Image 2026-04-18 at 22 40 48 WhatsApp Image 2026-04-18 at 22 40 02

if you notice they also have a tri lens model, i have also bought it, and will let you know the result soon.

@yob-yob

yob-yob commented May 3, 2026

Copy link
Copy Markdown

I have confirmed that this setup works...

[CONST_PARAM]
rtsp = 1
rtsp_enable = 1
rtsp_ctrl = 1

make sure to strictly follow this steps

Insert into camera power on it will speak something in Chinese after few min turn off the camera remove the SD card delete the ceshi.ini file and insert back to camera and power on it may ask for re-pair again with mobile device.

BIGGEST DOWN FALL... when I was done setting up everything including adding the camera to Frigate, I decided to transfer the camera to it's original position, I had to unplug it, screw it in the ceiling, then turn it on... then I noticed that the 554 and 8899 PORT is closed again... so it's basically not a permanent solution... maybe I had to enable something else to make it persist.

@arcane47

arcane47 commented May 6, 2026

Copy link
Copy Markdown

Hello i have the new model with three Lens camera and cannot activate onvif with .ini file. When i insert the memory and power on the camera, i hear the chinnesse voice but onvif port does not up. i run port scanner also and only ports 8800 and 9800 appears do you know if parameters on ini file was changed?

Exact same happened here. Model LS-CS7-10X
It did a bunch of beeping as well. Then put old SDcard back in. No changes in active ports. Still 8800 and 9800

@khawajamechatronics

Copy link
Copy Markdown

How to activate password on RSTP stream, I have password set on the camera but still stream is accessible unautheticated

@NaseemSrour

Copy link
Copy Markdown

Dude how did you even find this out?
How did you figure out that planting this format of a file onto the SD card would open the RTSP feature in the camera?!
@SolveSoul

@brahmtej2009

Copy link
Copy Markdown

Hey! So i did some digging, and got some results about the new app, and this information is quite valuable to the person making an update to
https://github.com/prsyahmi/v380

So, that old repo would not work anymore as the app and encryption keys and all changed.

Firstly some prior information, I have a 3 lens PTZ camera from maizic, and I also have a 2 lens ptz camera from Dr Vision. Though the 2 lens worked perfectly on Onvif, the 3 lens one did not do so. I did the sd card trick which got no results, tried to mess with the file a lot but that did not do anything.

I knew that the camera is broadcasting the stream on local host ip, and the app is fetching that and showing me the stream, so I decided to find open ports on this. None of the ports worked, except 8800 and 9800.

On some more messing around, tryna fetch the packets which were sent and received by the app, I used PCAPdroid to save the info and sent it to claude which accessed it along with the entire situation. here is a claude generated summary of everything, it would explain better than I can. Here is the entire situation summary and what all I did (Keep in mind its ai generated, but its just a summary of what all I did and told it)

Notes: trying to get RTSP/ONVIF (or any local stream) out of a newer 3-lens V380 (Xiongmai-based) camera

Sharing a full breakdown of what I found trying to pull a local video feed from a newer 3-lens V380 PTZ camera (sold under a rebrand, but it's a generic Xiongmai board running the V380 Pro app). Goal was to add it to an NVR/XVR over ONVIF. Posting everything so the next person doesn't start from zero. TL;DR: the local video is AES-encrypted and the key is inside a Qihoo-360-Jiagu-packed app, so it can't be pulled with network captures or static tools alone. But the protocol framing that causes the -11 error is now understood — details below.

The camera

  • App: V380 Pro (com.macrovideo.v380pro).
  • Chip vendor: Xiongmai (the "Equipment Model" string in the app started with HsXM... — the XM = Xiongmai).
  • It is cloud/P2P only. On a clean boot it works perfectly in the app but exposes almost nothing on the LAN.

Step 1 — Port scan (do this first)

Full scan (nmap -p- <cam_ip>) on a normal boot showed only:

8800/tcp open
9800/tcp open

Nothing else. No 554 (RTSP), no 8899 (ONVIF), no 23 (telnet), no 80 (web), no 34567 (Xiongmai Sofia/DVRIP), no 9527/9530 (Xiongmai debug shells).

Warning: if you scan and see a block of email ports "open" (25, 110, 143, 465, 587, 993, 995, etc.), that is NOT the camera — it's your ISP/router/AV intercepting standard mail ports. Prove it by scanning an empty IP with nmap -Pn -p 25,110,143,993,8800,9800 <unused_ip>: the email ports show "open" even there, but 8800/9800 show filtered. Only 8800/9800 are the real camera.

Step 2 — Things that DON'T work on this generation

  • ceshi.ini SD card trick ([CONST_PARAM] rtsp=1 etc.): the camera reads it and announces test mode in Chinese ("ceshi" = test), reports WiFi OK, but opens no new ports. Adding onvif=1, telnet=1, ssh=1, web=1 changed nothing. The firmware accepts the file but doesn't contain the services to switch on. NOTE: test mode makes the camera drop off the network — any scan done while the ceshi card is inserted is invalid. Delete the file, reboot normally, then scan.
  • Telnet / Sofia / web / 9527 / 9530: all closed. So python-dvr, CMS tools, telnet shells — none have a port to connect to.
  • OpenIPC / custom firmware over the network: impossible, because there's no open port to push it through. Would require UART/flash-chip hardware access.

Step 3 — Port 8800 with prsyahmi/v380 (this partly works)

The tool github.com/prsyahmi/v380 connects on 8800. Build the C++ version (Makefile is inside the v380/ subfolder). --discover correctly returns the camera's ID, IP, and MAC. So discovery and the initial auth work.

But streaming fails with:

Login response: unsupported -11, continuing
Unknown 0x9c command
Stream stopped, restarting stream

Notes on this:

  • There are two login stages in the code: a first auth (command 1167, returns codes 1001/1011/1012/1018) and a stream login (command 301). The -11 happens at the stream login, not the first auth.
  • Someone in an earlier thread found setting the login field unknown2 from 2 to 31 helped on their firmware. On this newer 3-lens firmware, changing unknown2 to 31 made the FIRST auth fail with code 1011 instead — so leave unknown2 = 2 for this generation. It's not the fix here.
  • The tool's stream parser only knows packet types 0x7f, 0x00, 0x01, 0x16, 0x1f, 0x6f. The camera sends 0x9c, which didn't exist in the old firmware, so the tool bails.

I patched the tool's default: case to hex-dump the unknown packet. The 0x9c "packet" turned out to be a rejection carrying the -11 code (9c ff ff ff f5 ff ff ff ... = signed -1 / -11 little-endian) followed by zero padding, then the connection closes. So the camera is refusing to start the stream because the stream-login handshake format is newer than the tool sends.

Step 4 — Capturing the app's real handshake (the useful part)

Captured the V380 Pro app talking to the camera on the LAN using PCAPdroid (Android, no root, app-filter set to V380 Pro), then analysed the .pcap.

The main video connection (phone → camera:8800) received ~700 KB in ~30 s, so video does flow locally over 8800. The key discovery is the framing. Every packet in the new protocol is wrapped in a 30-byte header:

00 00 01 07 20 21 00 00 28 4a   "V380 Pro"(ASCII, 8 bytes)   00-padding   <4 varying bytes>

i.e. magic 00 00 01 07 20 21 00 00 28 4a, then the literal ASCII string V380 Pro, then zero padding, then a per-packet value. The old prsyahmi tool sends none of this — that mismatch is what produces -11. So to get past -11, the tool would need to be rewritten to speak this V380 Pro-framed protocol (magic + identifier header) for the 301 stream login.

Step 5 — Is the video encrypted? (yes)

Reassembled the camera→phone payload and measured entropy: ~7.92 bits/byte (8.0 = random/encrypted). No consistent H.264 NAL structure (the few 00 00 00 01 start codes are coincidental, not a real SPS/PPS/IDR/P sequence). Conclusion: the media payload is encrypted, not just reframed.

From the app's native lib libaes.so I found the export:

Java_com_macrovideo_sdk_tools_AESUtils_aes128_ecb_encrypt

So the crypto is AES-128-ECB via com.macrovideo.sdk.tools.AESUtils — same class family the 2020 write-ups documented. I tested the old publicly-known keys (macrovideo+*#!^@, 8pV39QG114F230qW) against the payload in AES-128-ECB: entropy went UP to 8.0, meaning wrong keys. The old keys are dead on this firmware.

Step 6 — Why you can't just read the key out of the APK

Decompiled the real V380 Pro APK. jadx only recovered ~6 classes: com.stub.StubApp, com.tianyu.util.DtcLoader, Configuration. The real 35 MB classes.dex is a stub, and the assets contain libjiagu.so + libjiagu_a64.so and two encrypted .dat blobs.

That's Qihoo 360 Jiagu, a commercial packer. The actual app code (including AESUtils and the key/derivation) is encrypted on disk and only decrypted in memory at runtime, with anti-debug / anti-Frida protection. So static analysis cannot reach the key. grep/strings/jadx will all come up empty for the stream key — this is expected, not a mistake.

Where the next person should start

The remaining path to the key is runtime unpacking, not static or network work:

  1. Rooted Android phone or emulator.
  2. Use a memory-dex dumper (e.g. BlackDex or FRIDA-DEXDump) to dump the decrypted classes.dex from the running V380 Pro process, fighting Jiagu's anti-hook defenses.
  3. jadx the recovered dex, read com.macrovideo.sdk.tools.AESUtils and its callers to find the AES-128-ECB key and how it's derived (may be per-device, from the device ID/password, or a new static key).
  4. Once the key + the V380 Pro frame format are known, you can decrypt the 8800 stream, strip the 30-byte headers, and get H.264 out — then restream it as RTSP for an NVR.

Alternatively, if you just want the camera on an NVR and don't care about this specific unit: use a camera that supports ONVIF out of the box, or one on an OpenIPC-supported chip that you can reflash via UART/SPI.

Summary of what's confirmed

  • Newer 3-lens V380 (Xiongmai) = cloud/P2P only, ports 8800/9800 only, encrypted.
  • ceshi.ini does nothing on this generation; no telnet/Sofia/web/ONVIF/RTSP.
  • Local video does stream on 8800, wrapped in a 30-byte 00 00 01 07 20 21 00 00 28 4a "V380 Pro" header.
  • -11 / 0x9c error = the old tool doesn't speak the new V380 Pro-framed handshake.
  • Media is AES-128-ECB (AESUtils); old public keys don't work; current key is inside a 360 Jiagu-packed, anti-Frida app → needs runtime dex dumping to recover.

Hope this saves someone a few days. If anyone gets past the Jiagu unpacking and finds the current key/derivation, please post it that's the last missing piece.

I hope this helps, im not a master in this, but ig adding more information here is never bad, Il post this same thing at the https://github.com/prsyahmi/v380 repo too.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment