-
-
Save SolveSoul/9be5d9599c8b4b59f7cfa4cd0ce79c9c to your computer and use it in GitHub Desktop.
| [CONST_PARAM] | |
| rtsp = 1 ; RTSPЭ�飬0���ر� 1������ |
| V380 Pro cameras have rtsp/onvif disabled by default. This can be unlocked by inserting an SD-card into the camera. | |
| A step-by-step guide can be found below: | |
| 1) Download the V380 Pro app from the App Store or Google Play | |
| 2) Register or continue without registering | |
| 3) Boot your camera and couple it to the application | |
| 4) Set a custom username and password for your camera | |
| 5) Download the 'ceshi.ini' file and put it on the root of a micro SD card (so not in a subfolder) | |
| 6) Power down the camera, insert the SD card and boot the camera | |
| 7) The camera will talk in chinese, wait for 5 minutes (probably shorter, but to be sure) | |
| 8) Power down the camera, remove the SD card, delete the file and power up the camera | |
| 9) Connect to your camera using the protocol rtsp://username:password@ipaddress:554/live/ch00_0 | |
| 10) DONE | |
| A great way to test is downloading/using VLC and opening a network stream. |
Does anyone Onvif? If not, there is a 3-lens outdoor CCTV that does not have problems with the ceshi.ini file. Can you provide a link to purchase the product?
https://github.com/prsyahmi/v380/
This application is for V380 cameras that do not have the RTSP protocol and cannot be activated (for example with the ceshi.ini file) and transmit through port 8800. Unfortunately, in the latest firmware versions, the stream was encrypted in some way and cannot be played yet. But there are people with knowledge in this field working on it.
Hi, was there any update on this? Although, I'm more interested in how it sends audio from the phone mic to the camera. I tried analyzing the packets but it just seems like random noise so that might also be encrypted
UPDATE: I did end up figuring out the encryption for the audio packets. I'm pretty sure it follows the same algorithm for the video packets as well, but I can't be bothered to look into it. Made a little python program that automates it (https://github.com/jericjan/v380-audio-player)
Hi, it seems they tried studying the code for both the phone and PC apps, but no one has been able to make the stream playable. I think the project is abandoned. I'd also like someone with the necessary skills to figure it out.
i also have camera with 3 lens
when i try ceshi method the camera format itself and not runs until i remove sd card then format it self after removing sd card
anyone has the fix for this ?
i also have camera with 3 lens when i try ceshi method the camera format itself and not runs until i remove sd card then format it self after removing sd card
anyone has the fix for this ?
this exactly my camera
Okay so I bought 3 V380 Pro cameras from 2 different sellers, and all 3 are different. It's the black unit with one static lens and one PTZ lens/sensor. Video comes out as one square (ish) feed. All cameras look identical.
Seller A: White cable
Seller B: 2 units, black cable (but apparently different somehow), we'll name it QC2 and QC9.
QC9
All units are on latest firmware without need to update when arrived. In windows, I use a new, original, non-fake SD card, formatted as FAT32. I create a text document called ceshi.ini, and TYPED (not copied the above example with the random characters after rtsp=1) [CONST_PARAM] rtsp=1
Seller A, white cable version:
Onvif menu appears.
Label shows QR code, the device number, User:admin and random numbers as password (eg.123546673-9)
Seller B, QC9: QC9 DOES NOT NEED to use ceshi.ini as it is onvif-enabled by default, but...
RTSP audio option appears as well as ONVIF setting option like white cable version.
Label shows QR code, device number/id, User:admin and QC:09
Seller B, QC2:
rtsp=1 DOES NOT WORK. VLC can't access the stream.
Same as QC9, but this time it says QC:02
will try rtsp_enable=1 later... stupid sd card fell down and I can't find it :D EDIT: CONFIRMED, QC2 needs to use rtsp_enable=1 instead of rtsp=1. White Cable needs rtsp=1.
Hello sir, Currently I need a CCTV with QC9 specifications that supports RTSP audio. Can you provide the model name or provide a purchase link?
anyone from India ,who has used this process and was successfull,im planning to buy Tp plus cameras,it says the camera need v380 pro.
if someone from has used this method ,please provide links of the camera used,it will be very helpful
I had a talk with another v380 tech (probably a senior tech) and he mentioned that only dual cams v380 (prominent on outdoor models) have onvif & rtsp. So i decided to buy a dual cam v380 and it really has onvif and rtsp. But the downside is that both cameras are stacked and merged into a single stream (1920 x 2160) and unfortunately our NVR doesn't support that resolution.
I'm still finding ways to separate each cams into individual 1080p streams
![]()
May I know that rtsp stream url for that model, I also have the same one
Please can anyone find out the flags/switches to enable Humandoid AI detection?
I have a strong suspicion that these cameras actually have hardware support for Humanoid AI detection but because they are now selling a subscription to use DeepSeek Ai instead they are actively disabling them so it becomes a paid service. I have 2 exact camera models that have Humandoid AI detection built in. But sadly they don't have telnet open so I can't go digging into how this works.
i also have camera with 3 lens when i try ceshi.ini method the camera formats itself to factory settings then i turn off the camera and delete the file from the sdcard and put it back after i turn th camera back on. its useless because it has already reset to factory settings.
anyone has the fix for this ?
Any Solution Available we have the same cctv camera model? the thing is when we use this ceshi.ini method the camera reset itself to factory settings that is why it talk chinese. any help solution for this will be much appreciated thank you TS.

i also have camera with 3 lens when i try ceshi.ini method the camera formats itself to factory settings then i turn off the camera and delete the file from the sdcard and put it back after i turn th camera back on. its useless because it has already reset to factory settings.
anyone has the fix for this ?Any Solution Available we have the same cctv camera model? the thing is when we use this ceshi.ini method the camera reset itself to factory settings that is why it talk chinese. any help solution for this will be much appreciated thank you TS.
Still no luck unfortunately
Me funciono con una camara doble les comparto para crear el archivo con nombre y tipo ceshi.ini
[CONST_PARAM]
rtsp_enable = 1
No funciono con VLC
Si funciona IPCams de IOS Apple
Si funciona IP Camara Lite de IOS Apple
rtsp://IPCAM:554/live/ch00_1
or
rtsp://IPCAM/live/ch00_0
Datos de mi camara V380 Pro Modelo Desconocido Marca Desconocida
Dual Lens 2K 4MP Wireless PTZ Security Camera,2K 4MP
Saludos desde México
@LaloReyes, can you access the data stream without a password, even if one is set in the app?
@LaloReyes, can you access the data stream without a password, even if one is set in the app?
Asi es no requiere usuario y contraseña
worked well for this model
used
ceshi.ini file as follows
[CONST_PARAM]
rtsp = 1
rtsp_enable = 1
rtsp_ctrl = 1
I purchased one V380 Pro camera and tried to activate RTSP and ONVIF through ceshi.ini. Unfortunately, I could not see any option for doing so in Advanced Settings.
I read online that some later models may be encrypted and there is nothing we can do about it to make RTSP and ONVIF optionally enabled. Any help is greatly appreciated, thanks.
@popilirol There won't be any new menus or configuration on the settings menu after doing the mentioned steps but it will open up the RTSP feed so you can access the stream, only problem is it won't have a password I think there is option to set that too but in my case I'm writing the stream to Disk using Raspberry Pi everything is local so no problem with credentials.
Try this
create the ceshi.ini with
[CONST_PARAM]
rtsp = 1
rtsp_enable = 1
rtsp_ctrl = 1
Insert into camera power on it will speak something in Chinese after few min turn off the camera remove the SD card delete the ceshi.ini file and insert back to camera and power on it may ask for re-pair again with mobile device.
then try to access the stream like below
rtsp://192.168.1.108:554/live/ch00_1
from VLC you can test it out , It should work
@popilirol There won't be any new menus or configuration on the settings menu after doing the mentioned steps but it will open up the RTSP feed so you can access the stream, only problem is it won't have a password I think there is option to set that too but in my case I'm writing the stream to Disk using Raspberry Pi everything is local so no problem with credentials.
Try this create the ceshi.ini with
[CONST_PARAM] rtsp = 1 rtsp_enable = 1 rtsp_ctrl = 1Insert into camera power on it will speak something in Chinese after few min turn off the camera remove the SD card delete the ceshi.ini file and insert back to camera and power on it may ask for re-pair again with mobile device.
then try to access the stream like below
rtsp://192.168.1.108:554/live/ch00_1from VLC you can test it out , It should work
Jobin, thanks for your reply. I tried VLC and ODM, and I tried all URLs:
rtsp://username:password@IPaddress:554/live/ch00_0
rtsp://username:password@IPaddress:554/live/ch00_1
rtsp://username:password@IPaddress:554/11
rtsp://username:password@IPaddress:554
rtsp://IPaddress:554
I managed to add a custom username and password from the menu, but none of these could allow the camera to stream.
P.S. Today V380 replied to me and told me that my model does not support RTSP/ONVIF. This sucks because I hate the V380 app because it is so limited and basic, and I already have purchased in the past Blue Iris, an amazing piece of software for managing all kinds of IP cameras.
Hi did you check the V380 pro app under advanced settings? Try turning on Onvif support.
Otherwise try requesting RTSP support on this email address: v380technical@gmail.com
Not a scam but good on you to be cautious. I used them as well although I didn't get far.
I got the email from the parent company of the V380 camera system it's called M@crovideo
https://www.macro-video.com/en-us/1/0/4/service.html
And the same email is referenced on other forums related to V380 camera modding stuff, like this one:
https://community.netcamstudio.com/t/v380-stream-url/2778/47?page=2
@popilirol ......
Try this create the ceshi.ini with
[CONST_PARAM] rtsp = 1 rtsp_enable = 1 rtsp_ctrl = 1
Just reporting so that it helps any one who search
it works on V380 BQ8 Dual camera lens model (from my batch any ways i bought 3, 2 dual camera lens, 1 tri camera lens )
prior to tyhe ceshi file it does not show onvif toggle, now it is visible even after reboot
rtsp also works.
Model: V380 BQ8 Dual Lens
Software version:AppEV3L_V2_V1.0.5.2_20250102
Firmware version:Hw_HsAkQQVL_WF_QQ_20240412
if you notice they also have a tri lens model, i have also bought it, and will let you know the result soon.
I have confirmed that this setup works...
[CONST_PARAM]
rtsp = 1
rtsp_enable = 1
rtsp_ctrl = 1
make sure to strictly follow this steps
Insert into camera power on it will speak something in Chinese after few min turn off the camera remove the SD card delete the ceshi.ini file and insert back to camera and power on it may ask for re-pair again with mobile device.
BIGGEST DOWN FALL... when I was done setting up everything including adding the camera to Frigate, I decided to transfer the camera to it's original position, I had to unplug it, screw it in the ceiling, then turn it on... then I noticed that the 554 and 8899 PORT is closed again... so it's basically not a permanent solution... maybe I had to enable something else to make it persist.
Hello i have the new model with three Lens camera and cannot activate onvif with .ini file. When i insert the memory and power on the camera, i hear the chinnesse voice but onvif port does not up. i run port scanner also and only ports 8800 and 9800 appears do you know if parameters on ini file was changed?
Exact same happened here. Model LS-CS7-10X
It did a bunch of beeping as well. Then put old SDcard back in. No changes in active ports. Still 8800 and 9800
How to activate password on RSTP stream, I have password set on the camera but still stream is accessible unautheticated
Dude how did you even find this out?
How did you figure out that planting this format of a file onto the SD card would open the RTSP feature in the camera?!
@SolveSoul
Hey! So i did some digging, and got some results about the new app, and this information is quite valuable to the person making an update to
https://github.com/prsyahmi/v380
So, that old repo would not work anymore as the app and encryption keys and all changed.
Firstly some prior information, I have a 3 lens PTZ camera from maizic, and I also have a 2 lens ptz camera from Dr Vision. Though the 2 lens worked perfectly on Onvif, the 3 lens one did not do so. I did the sd card trick which got no results, tried to mess with the file a lot but that did not do anything.
I knew that the camera is broadcasting the stream on local host ip, and the app is fetching that and showing me the stream, so I decided to find open ports on this. None of the ports worked, except 8800 and 9800.
On some more messing around, tryna fetch the packets which were sent and received by the app, I used PCAPdroid to save the info and sent it to claude which accessed it along with the entire situation. here is a claude generated summary of everything, it would explain better than I can. Here is the entire situation summary and what all I did (Keep in mind its ai generated, but its just a summary of what all I did and told it)
Notes: trying to get RTSP/ONVIF (or any local stream) out of a newer 3-lens V380 (Xiongmai-based) camera
Sharing a full breakdown of what I found trying to pull a local video feed from a newer 3-lens V380 PTZ camera (sold under a rebrand, but it's a generic Xiongmai board running the V380 Pro app). Goal was to add it to an NVR/XVR over ONVIF. Posting everything so the next person doesn't start from zero. TL;DR: the local video is AES-encrypted and the key is inside a Qihoo-360-Jiagu-packed app, so it can't be pulled with network captures or static tools alone. But the protocol framing that causes the -11 error is now understood — details below.
The camera
- App: V380 Pro (
com.macrovideo.v380pro). - Chip vendor: Xiongmai (the "Equipment Model" string in the app started with
HsXM...— the XM = Xiongmai). - It is cloud/P2P only. On a clean boot it works perfectly in the app but exposes almost nothing on the LAN.
Step 1 — Port scan (do this first)
Full scan (nmap -p- <cam_ip>) on a normal boot showed only:
8800/tcp open
9800/tcp open
Nothing else. No 554 (RTSP), no 8899 (ONVIF), no 23 (telnet), no 80 (web), no 34567 (Xiongmai Sofia/DVRIP), no 9527/9530 (Xiongmai debug shells).
Warning: if you scan and see a block of email ports "open" (25, 110, 143, 465, 587, 993, 995, etc.), that is NOT the camera — it's your ISP/router/AV intercepting standard mail ports. Prove it by scanning an empty IP with
nmap -Pn -p 25,110,143,993,8800,9800 <unused_ip>: the email ports show "open" even there, but 8800/9800 showfiltered. Only 8800/9800 are the real camera.
Step 2 — Things that DON'T work on this generation
- ceshi.ini SD card trick (
[CONST_PARAM] rtsp=1etc.): the camera reads it and announces test mode in Chinese ("ceshi" = test), reports WiFi OK, but opens no new ports. Addingonvif=1,telnet=1,ssh=1,web=1changed nothing. The firmware accepts the file but doesn't contain the services to switch on. NOTE: test mode makes the camera drop off the network — any scan done while the ceshi card is inserted is invalid. Delete the file, reboot normally, then scan. - Telnet / Sofia / web / 9527 / 9530: all closed. So
python-dvr, CMS tools, telnet shells — none have a port to connect to. - OpenIPC / custom firmware over the network: impossible, because there's no open port to push it through. Would require UART/flash-chip hardware access.
Step 3 — Port 8800 with prsyahmi/v380 (this partly works)
The tool github.com/prsyahmi/v380 connects on 8800. Build the C++ version (Makefile is inside the v380/ subfolder). --discover correctly returns the camera's ID, IP, and MAC. So discovery and the initial auth work.
But streaming fails with:
Login response: unsupported -11, continuing
Unknown 0x9c command
Stream stopped, restarting stream
Notes on this:
- There are two login stages in the code: a first auth (
command 1167, returns codes 1001/1011/1012/1018) and a stream login (command 301). The-11happens at the stream login, not the first auth. - Someone in an earlier thread found setting the login field
unknown2from2to31helped on their firmware. On this newer 3-lens firmware, changingunknown2to31made the FIRST auth fail with code 1011 instead — so leaveunknown2 = 2for this generation. It's not the fix here. - The tool's stream parser only knows packet types
0x7f,0x00,0x01,0x16,0x1f,0x6f. The camera sends0x9c, which didn't exist in the old firmware, so the tool bails.
I patched the tool's default: case to hex-dump the unknown packet. The 0x9c "packet" turned out to be a rejection carrying the -11 code (9c ff ff ff f5 ff ff ff ... = signed -1 / -11 little-endian) followed by zero padding, then the connection closes. So the camera is refusing to start the stream because the stream-login handshake format is newer than the tool sends.
Step 4 — Capturing the app's real handshake (the useful part)
Captured the V380 Pro app talking to the camera on the LAN using PCAPdroid (Android, no root, app-filter set to V380 Pro), then analysed the .pcap.
The main video connection (phone → camera:8800) received ~700 KB in ~30 s, so video does flow locally over 8800. The key discovery is the framing. Every packet in the new protocol is wrapped in a 30-byte header:
00 00 01 07 20 21 00 00 28 4a "V380 Pro"(ASCII, 8 bytes) 00-padding <4 varying bytes>
i.e. magic 00 00 01 07 20 21 00 00 28 4a, then the literal ASCII string V380 Pro, then zero padding, then a per-packet value. The old prsyahmi tool sends none of this — that mismatch is what produces -11. So to get past -11, the tool would need to be rewritten to speak this V380 Pro-framed protocol (magic + identifier header) for the 301 stream login.
Step 5 — Is the video encrypted? (yes)
Reassembled the camera→phone payload and measured entropy: ~7.92 bits/byte (8.0 = random/encrypted). No consistent H.264 NAL structure (the few 00 00 00 01 start codes are coincidental, not a real SPS/PPS/IDR/P sequence). Conclusion: the media payload is encrypted, not just reframed.
From the app's native lib libaes.so I found the export:
Java_com_macrovideo_sdk_tools_AESUtils_aes128_ecb_encrypt
So the crypto is AES-128-ECB via com.macrovideo.sdk.tools.AESUtils — same class family the 2020 write-ups documented. I tested the old publicly-known keys (macrovideo+*#!^@, 8pV39QG114F230qW) against the payload in AES-128-ECB: entropy went UP to 8.0, meaning wrong keys. The old keys are dead on this firmware.
Step 6 — Why you can't just read the key out of the APK
Decompiled the real V380 Pro APK. jadx only recovered ~6 classes: com.stub.StubApp, com.tianyu.util.DtcLoader, Configuration. The real 35 MB classes.dex is a stub, and the assets contain libjiagu.so + libjiagu_a64.so and two encrypted .dat blobs.
That's Qihoo 360 Jiagu, a commercial packer. The actual app code (including AESUtils and the key/derivation) is encrypted on disk and only decrypted in memory at runtime, with anti-debug / anti-Frida protection. So static analysis cannot reach the key. grep/strings/jadx will all come up empty for the stream key — this is expected, not a mistake.
Where the next person should start
The remaining path to the key is runtime unpacking, not static or network work:
- Rooted Android phone or emulator.
- Use a memory-dex dumper (e.g. BlackDex or FRIDA-DEXDump) to dump the decrypted
classes.dexfrom the running V380 Pro process, fighting Jiagu's anti-hook defenses. - jadx the recovered dex, read
com.macrovideo.sdk.tools.AESUtilsand its callers to find the AES-128-ECB key and how it's derived (may be per-device, from the device ID/password, or a new static key). - Once the key + the
V380 Proframe format are known, you can decrypt the 8800 stream, strip the 30-byte headers, and get H.264 out — then restream it as RTSP for an NVR.
Alternatively, if you just want the camera on an NVR and don't care about this specific unit: use a camera that supports ONVIF out of the box, or one on an OpenIPC-supported chip that you can reflash via UART/SPI.
Summary of what's confirmed
- Newer 3-lens V380 (Xiongmai) = cloud/P2P only, ports 8800/9800 only, encrypted.
- ceshi.ini does nothing on this generation; no telnet/Sofia/web/ONVIF/RTSP.
- Local video does stream on 8800, wrapped in a 30-byte
00 00 01 07 20 21 00 00 28 4a "V380 Pro"header. -11 / 0x9cerror = the old tool doesn't speak the newV380 Pro-framed handshake.- Media is AES-128-ECB (
AESUtils); old public keys don't work; current key is inside a 360 Jiagu-packed, anti-Frida app → needs runtime dex dumping to recover.
Hope this saves someone a few days. If anyone gets past the Jiagu unpacking and finds the current key/derivation, please post it that's the last missing piece.
I hope this helps, im not a master in this, but ig adding more information here is never bad, Il post this same thing at the https://github.com/prsyahmi/v380 repo too.
















hello, can you send me product link?