Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. the best part about it is that from my experience, cameras are often embedded devices, and they have abysmal security.

the best part about it is that from my experience, cameras are often embedded devices, and they have abysmal security.

Scheduled Pinned Locked Moved Uncategorized
10 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • da_667@infosec.exchangeD This user is from outside of this forum
    da_667@infosec.exchangeD This user is from outside of this forum
    da_667@infosec.exchange
    wrote last edited by
    #1

    RE: https://mas.to/@PrivacyDigest/116206811518592253

    the best part about it is that from my experience, cameras are often embedded devices, and they have abysmal security. Most of the time, you can just point to their RTSP streams and get a video feed without auth. and technically that's "hacking" it, I guess.

    and if you want code execution, many have hardcoded backdoors, or if you manage to get in with default creds, many sources for command injection, and other fun things.

    da_667@infosec.exchangeD viss@mastodon.socialV 2 Replies Last reply
    0
    • da_667@infosec.exchangeD da_667@infosec.exchange

      RE: https://mas.to/@PrivacyDigest/116206811518592253

      the best part about it is that from my experience, cameras are often embedded devices, and they have abysmal security. Most of the time, you can just point to their RTSP streams and get a video feed without auth. and technically that's "hacking" it, I guess.

      and if you want code execution, many have hardcoded backdoors, or if you manage to get in with default creds, many sources for command injection, and other fun things.

      da_667@infosec.exchangeD This user is from outside of this forum
      da_667@infosec.exchangeD This user is from outside of this forum
      da_667@infosec.exchange
      wrote last edited by
      #2

      many will have the ability to communicate via SMB or maybe NFS. I remember a story from two years ago where a ransomware group got exec on a camera, mounted an SMB share, and just... encrypted everything from the camera.

      winterknight1337@infosec.exchangeW 1 Reply Last reply
      0
      • da_667@infosec.exchangeD da_667@infosec.exchange

        RE: https://mas.to/@PrivacyDigest/116206811518592253

        the best part about it is that from my experience, cameras are often embedded devices, and they have abysmal security. Most of the time, you can just point to their RTSP streams and get a video feed without auth. and technically that's "hacking" it, I guess.

        and if you want code execution, many have hardcoded backdoors, or if you manage to get in with default creds, many sources for command injection, and other fun things.

        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.social
        wrote last edited by
        #3

        @da_667

        - YouTube

        Auf YouTube findest du die angesagtesten Videos und Tracks. Außerdem kannst du eigene Inhalte hochladen und mit Freunden oder gleich der ganzen Welt teilen.

        favicon

        (www.youtube.com)

        - YouTube

        Auf YouTube findest du die angesagtesten Videos und Tracks. Außerdem kannst du eigene Inhalte hochladen und mit Freunden oder gleich der ganzen Welt teilen.

        favicon

        (www.youtube.com)

        thepacketrat@infosec.exchangeT 1 Reply Last reply
        0
        • da_667@infosec.exchangeD da_667@infosec.exchange

          many will have the ability to communicate via SMB or maybe NFS. I remember a story from two years ago where a ransomware group got exec on a camera, mounted an SMB share, and just... encrypted everything from the camera.

          winterknight1337@infosec.exchangeW This user is from outside of this forum
          winterknight1337@infosec.exchangeW This user is from outside of this forum
          winterknight1337@infosec.exchange
          wrote last edited by
          #4

          @da_667 for uh, no reason in particular also turn off SMB and RDP on your printers. Please.

          viss@mastodon.socialV 1 Reply Last reply
          0
          • winterknight1337@infosec.exchangeW winterknight1337@infosec.exchange

            @da_667 for uh, no reason in particular also turn off SMB and RDP on your printers. Please.

            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.social
            wrote last edited by
            #5

            @winterknight1337 @da_667 mmmm rdp into the printer

            kajer@infosec.exchangeK 1 Reply Last reply
            0
            • viss@mastodon.socialV viss@mastodon.social

              @winterknight1337 @da_667 mmmm rdp into the printer

              kajer@infosec.exchangeK This user is from outside of this forum
              kajer@infosec.exchangeK This user is from outside of this forum
              kajer@infosec.exchange
              wrote last edited by
              #6

              @Viss @winterknight1337 @da_667

              teenage hijinks - "wardriving" but it was early 2000s and bestbuy sold default-open linksys APs. Driving by, connecting to the printer and printing haha pwn3d before speeding off...

              viss@mastodon.socialV 1 Reply Last reply
              0
              • viss@mastodon.socialV viss@mastodon.social

                @da_667

                - YouTube

                Auf YouTube findest du die angesagtesten Videos und Tracks. Außerdem kannst du eigene Inhalte hochladen und mit Freunden oder gleich der ganzen Welt teilen.

                favicon

                (www.youtube.com)

                - YouTube

                Auf YouTube findest du die angesagtesten Videos und Tracks. Außerdem kannst du eigene Inhalte hochladen und mit Freunden oder gleich der ganzen Welt teilen.

                favicon

                (www.youtube.com)

                thepacketrat@infosec.exchangeT This user is from outside of this forum
                thepacketrat@infosec.exchangeT This user is from outside of this forum
                thepacketrat@infosec.exchange
                wrote last edited by
                #7

                @Viss @da_667 I can relate.

                viss@mastodon.socialV 1 Reply Last reply
                0
                • kajer@infosec.exchangeK kajer@infosec.exchange

                  @Viss @winterknight1337 @da_667

                  teenage hijinks - "wardriving" but it was early 2000s and bestbuy sold default-open linksys APs. Driving by, connecting to the printer and printing haha pwn3d before speeding off...

                  viss@mastodon.socialV This user is from outside of this forum
                  viss@mastodon.socialV This user is from outside of this forum
                  viss@mastodon.social
                  wrote last edited by
                  #8

                  @kajer @winterknight1337 @da_667 you can still do that now, haha - i see printer wifi networks from home, and also in nearly every office building i go to, some restaurants etc - that shit is still everywhere

                  1 Reply Last reply
                  0
                  • thepacketrat@infosec.exchangeT thepacketrat@infosec.exchange

                    @Viss @da_667 I can relate.

                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.social
                    wrote last edited by
                    #9

                    @thepacketrat @da_667 same. ive seen infosec bullshit turn over like, four maybe five times now. last go-around i tried to warn people of the frauds and grifters, but they turned on me, because HOLY SHIT THERES A LOT OF EM. twitter burning down seemed to mark another 'churn', and this time around they can fend for themselves. im done trying to help 'the community'.

                    thepacketrat@infosec.exchangeT 1 Reply Last reply
                    0
                    • viss@mastodon.socialV viss@mastodon.social

                      @thepacketrat @da_667 same. ive seen infosec bullshit turn over like, four maybe five times now. last go-around i tried to warn people of the frauds and grifters, but they turned on me, because HOLY SHIT THERES A LOT OF EM. twitter burning down seemed to mark another 'churn', and this time around they can fend for themselves. im done trying to help 'the community'.

                      thepacketrat@infosec.exchangeT This user is from outside of this forum
                      thepacketrat@infosec.exchangeT This user is from outside of this forum
                      thepacketrat@infosec.exchange
                      wrote last edited by
                      #10

                      @Viss @da_667 Pepperidge Fahms Remembahhhhs

                      1 Reply Last reply
                      1
                      0
                      • R relay@relay.infosec.exchange shared this topic
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups