Xiaomi Cameras Connected to Google Nest Expose Video Feeds From Others

Internet-connected devices have been one of the most remarkable developments that have happened to humankind in the last decade. Although this development is a good thing, it also stipulates a high security and privacy risk to personal information.

In… Continue reading Xiaomi Cameras Connected to Google Nest Expose Video Feeds From Others

Reverse Engineering A Modern IP Camera

Security cameras used to be analog devices feeding back into a room full of tiny screens and commercial grade VCRs. As technology moved forward, IP cameras began to proliferate. Early models simply presented a video stream and configuration page to the local network. Modern models aimed at the home market …read more

Continue reading Reverse Engineering A Modern IP Camera

Axis Cameras Riddled With Vulnerabilities Enabling “Full Control”

The IP cameras have a slew of bugs allowing bad actors to control them, add them to a botnet, or render them useless. Continue reading Axis Cameras Riddled With Vulnerabilities Enabling “Full Control”

Three Vulnerabilities Found in Foscam IP Cameras (CVE-2018-6830)

Three vulnerabilities have been found in Foscam security cameras. Owners of such cameras are urged to update as soon as possible. The flaws are described as an arbitrary file-deletion bug, a shell command-injection bug and a stack-based buffer oferflow… Continue reading Three Vulnerabilities Found in Foscam IP Cameras (CVE-2018-6830)

Easy Time-lapse Video via Phone and Command Line

A good time-lapse video can be useful visual documentation, and since [Tommy]’s phone is the best camera he owns he created two simple shell scripts to grab time-lapse images and assemble them into a video. [Tommy]’s work is just the glue between two other things: an app that turns the phone into an IP camera with a web server on the local network, and the ability to grab a still image from that server on demand.

The app he uses for his iPhone normally serves video but has an undocumented feature that allows single frames to be downloaded by adding …read more

Continue reading Easy Time-lapse Video via Phone and Command Line

Hard-coded Passwords Make Hacking Foscam ‘IP Cameras’ Much Easier

Security researchers have discovered over a dozen of vulnerabilities in tens of thousands of web-connected cameras that can not be protected just by changing their default credentials.

Vulnerabilities found in two models of IP cameras from China-based… Continue reading Hard-coded Passwords Make Hacking Foscam ‘IP Cameras’ Much Easier

Yet Another IoT Botnet

[TrendMicro] are reporting that yet another IoT botnet is emerging. This new botnet had been dubbed Persirai and targets IP cameras. Most of the victims don’t even realize their camera has access to the Internet 24/7 in the first place.

Trend Micro, have found 1,000 IP cameras of different models that have been exploited by Persirai so far. There are at least another 120,000 IP cameras that the botnet could attack using the same method. The problem starts with the IP cameras exposing themselves by default on TCP Port 81 as a web server — never a great idea.

Most …read more

Continue reading Yet Another IoT Botnet