Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

12/7/2016
04:20 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Researchers Find Backdoors, Bugs In Sony, White Box IP Cameras

New vulnerabilities discovered by SEC Consult and Cybereason highight increasing IoT threat to enterprises.

Two alerts this week about vulnerabilities in widely used IP cameras should help dispel any lingering notions about the Internet of Things (IoT) security threat being largely a consumer problem.

One of the alerts was from Austrian security firm SEC Consult, while the other was from Cybereaon.

In research published Tuesday, SEC Consult said it had found a backdoor in as many as 80 Sony IPELA Engine IP camera models.

The backdoor gives attackers a way to take complete control of vulnerable devices and use them to spy, to launch attacks on other enterprise systems, disrupt camera functionality or to make the devices part of a Mirai-like botnet.  Sony’s website shows that the cameras range in price from under $500 to over $6,000 and appear designed for monitoring purposes in commercial and industrial settings.

Sony has updated its firmware to address the issue after SEC Consult informed the company of its discovery.

Enterprises need to view this as the canary in the coal mine for IoT security,” says Brian NeSmith, the founder and CEO of Arctic Wolf Networks. “Hacking consumer video cameras don’t pose a huge risk, but as more enterprises try to leverage IoT technology and put more devices online, they need to understand they are significantly increasing the attack surface for cyberattacks,” he cautions.

SEC Consult said it stumbled upon the issue when uploading a firmware update from a Sony IP camera into SEC’s IoT Inspector firmware analysis system.

The analysis uncovered two hardcoded passwords in the firmware, one for user administration and the other for gaining root access.  Further investigation showed the presence of two user accounts one named ‘primana’ and the other ‘debug’.

Depending on the services that are started at runtime, an attacker could use the accounts to log in via the serial port or via Secure Shell and Telnet, SEC Consult said.

The backdoor does not appear to have been installed by an unauthorized third party, according to the company. Rather Sony developers seem to have created the accounts on purpose likely in order to give them a way to debug devices or to run functionality tests on them.

Johannes Greil, head of SEC Consult’s vulnerability lab, says attackers can use the backdoor in the IP cameras to attack other systems on the network. “If an attacker successfully compromises the IP camera remotely, it can be used as a jump host to attack other internal systems, depending on the network and firewall configuration of course,” Greil says.

SEC Consult’s analysis shows that an attacker can use the backdoor ‘primana’ account to remotely target undocumented functionality within the web interface of the Sony IP cameras to enable Telnet and SSH on them.

The ‘primana’ account has access to other functionality as well such as for picture manipulation, calibrating settings for or turning the device heater on, if it has one, Greil says. Similarly, the ‘debug’ user accounts has access to undocumented functions that SEC Consult did not investigate.

Organizations using the vulnerable devices should immediately install the updated Sony firmware, he says. In addition, they should restrict access to the devices as much as possible and disallow Internet access via VLANs and firewalls, Greil says.

Cybereason’s alert meanwhile involved two zero-day bugs that it says is present in hundreds of thousands of low-cost IP cameras.

The first zero day bug enables information disclosure and authentication bypass. An attacker can exploit the flaw to basically request any file from vulnerable devices including the password people use to access the camera. So even if a user had set an extremely hard password, an attacker would simply be able to ask the device for it. The other bug enables attackers to gain root access to a vulnerable device after authenticating themselves using the password obtained.

The bugs exist in software developed by a company that assembles the cameras for so-called white box vendors who distribute the devices often without a manufacturer’s name or logo.

Cybereason did not release technical details of the flaws, or how they can be exploited because of how widespread the issue is and the difficulty involved in identifying the suppliers of the devices and getting them to update. And even if they were willing to update, the cameras are not designed to receive updates so the zero-days cannot be patched.

“The only way to guarantee that an affected camera is safe from these exploits is to throw it out,” says Amit Serper principal security researcher at Cybereason.

In comments to Dark Reading, Serper says bugs like these show its high time for organizations to stop viewing the IoT as some sort of a separate Internet. Organizations need to treat IoT devices as just other computers on the network that can have vulnerabilities and need to be protected, he says, adding that the focus, as always needs to be on security and not just price.  “People need to stop buy cheap crap, just because it is cheap,” he says.

Related stories:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
cyclepro
100%
0%
cyclepro,
User Rank: Strategist
12/8/2016 | 9:29:14 AM
Sony Camera
In the article it says that the IoT backdoor should be a lesson for people in not buying cheap items. In the case for Sony the camera's affected range in price from $500.00 to $6,000.00

Pretty cheap huh?

 
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17210
PUBLISHED: 2019-07-20
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass t...
CVE-2019-12934
PUBLISHED: 2019-07-20
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.
CVE-2019-9229
PUBLISHED: 2019-07-20
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can...
CVE-2019-12815
PUBLISHED: 2019-07-19
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
CVE-2019-13569
PUBLISHED: 2019-07-19
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.