Risk
7/25/2013
08:53 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Somebody's Watching You: Hacking IP Video Cameras

Major holes in network video recorders (NVRs) could result in a major physical security and privacy FAIL

Turns out those IP cameras used for physical security in businesses and homes can be easily hijacked by bad guys.

A researcher next week at the BSides Las Vegas conference will detail some key vulnerabilities he discovered in D-Link's mydlink Network Video Recorder (NVR), a storage device used to record video from cameras. The flaws, which D-Link fixed in a firmware upgrade last Friday, could allow an attacker to hack into the device and remotely control the video cameras.

Bharat Jogi, who discovered the bugs, says an NVR device is the heart of an IP video camera network. "If you want to monitor a room or something, you have eight to 10 cameras connected to" it to monitor and record video of a room or location, says Jogi, a security engineer at Qualys.

One of the flaws in the NVR leaks information from the device, including the credentials of all of the IP cameras connected to it. So a hacker could control the cameras by easily capturing usernames and passwords associated with the devices, and wrest control of them.

The NVR also can be cheated to cough up the video feeds it has stored, Jogi says. "It will give you all the details of video feeds," he says.

Another vulnerability Jogi discovered is that the device accepts any firmware: "You don't have to answer any credentials to update firmware on the device. You can upload malicious firmware" to shut it down and stop it from recording, for example, he says.

But the biggest bug he found was that the device could allow remote attackers to establish administrative accounts on the device. "You can become an admin of that device from anywhere," he says. "An attacker could send a malicious request and become admin of the device. He could [even then] view IP camera feeds from a mobile phone" remotely, he says.

"These systems are supposed to be very secure. But when you connect them to your environment, you are exposing a lot. Anyone can view it and do anything with it" if they exploit the flaws, he says.

Jogi, who will release free tools he created to test for these flaws in IP video camera networks, says the vulnerabilities could be exploited by attackers who want to target a specific company or location. "If they want to view what's going on inside a company, or if they want to have information on a company and are planning some attacks on them, this is a very good start," he says.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Senior Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise Magazine, ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
MichaelHyatt_
50%
50%
MichaelHyatt_,
User Rank: Apprentice
7/26/2013 | 7:11:19 PM
re: Somebody's Watching You: Hacking IP Video Cameras
The 'Internet of Things' is going to be the primary guarantor of job security in the InfoSec field for years to come...
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0103
Published: 2014-07-29
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

CVE-2014-0475
Published: 2014-07-29
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

CVE-2014-0889
Published: 2014-07-29
Multiple cross-site scripting (XSS) vulnerabilities in IBM Atlas Suite (aka Atlas Policy Suite), as used in Atlas eDiscovery Process Management through 6.0.3, Disposal and Governance Management for IT through 6.0.3, and Global Retention Policy and Schedule Management through 6.0.3, allow remote atta...

CVE-2014-2226
Published: 2014-07-29
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtains sensitive information via unspecified vectors.

CVE-2014-3020
Published: 2014-07-29
install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.

Best of the Web
Dark Reading Radio