Live data from Hacker News

New security camera compromised by worm within minutes of installation

twitter.com

21–30 of 94 posts

Re: New security camera compromised by worm within minutes of installation

#21
post #18
post #14

Earlier quoted context omitted.

Possibly stupid question: How can I verify that upnp is really disabled? (I don't trust my router to do it correctly) edit: https://www.grc.com/su/UPnP-Rejected.htm

Probably sniffing the packets should work. But even if you do that properly there is always a high chance your router will be compromised and you won't be able to fix it. To be extra sure just treat it as such and put a firewall between it and your LAN. That requires time to configure, but may satisfy the paranoid.

What? Put a firewall in front of your firewall, because more firewalls is better?

How about use a firewall that's not shit to begin with.

Re: New security camera compromised by worm within minutes of installation

#22
post #15

Earlier quoted context omitted.

There aren't so many IPv4 addresses and connections are fast enough even for residential users. If considering a botnet, even faster. There is even services that scan the whole ipv4 in less than 5 minutes: https://zmap.io/ And a list of how to do it: http://www.securitynewspaper.com/2015/10/15/how-to-scan-whol...

I don't get it: how does the attacker initiate contact with a 192.168.0.0/16 address? Is part of the installation instructions "On your WAN router, DNAT your external address and a port to your internal address and telnet port."?

Sort of. Do you know what uPNP is? It allows a device to automatically do exactly that.

https://en.wikipedia.org/wiki/Universal_Plug_and_Play

Re: New security camera compromised by worm within minutes of installation

#25

Why do people connect their security camera to the internet? You shouldn't connect security anything to the internet

They do it so they can view the camera remotely, like when they're on vacation.

This, and with the camera it looks like it automatically opened up firewall ports by itself using UPNP

Re: New security camera compromised by worm within minutes of installation

#26
post #18

Earlier quoted context omitted.

Probably sniffing the packets should work. But even if you do that properly there is always a high chance your router will be compromised and you won't be able to fix it. To be extra sure just treat it as such and put a firewall between it and your LAN. That requires time to configure, but may satisfy the paranoid.

What? Put a firewall in front of your firewall, because more firewalls is better? How about use a firewall that's not shit to begin with.

Consumer grade gear is universally shit.

Low end business gear is universally shit. My comcast business router is absolutely awful. I need to get around to putting it in bridge mode and putting a real router behind it. The best thing it could possibly be for me is a coax to ethernet paperweight.

Re: New security camera compromised by worm within minutes of installation

#27

I don't understand how the bot net found his camera so instantly when he turned it on or installed it. Within moments/seconds, it was attempting to infiltrate a brand new device.

You might be too young to remember Blaster Worm. There was a time in 2003-2004 you couldnt install Windows XP/2000 when directly connected to the internet (no nat/firewall), you got infected (= reboot after 60 seconds) as soon as install process fired up RPC service.

Re: New security camera compromised by worm within minutes of installation

#28
post #26

Earlier quoted context omitted.

What? Put a firewall in front of your firewall, because more firewalls is better? How about use a firewall that's not shit to begin with.

Consumer grade gear is universally shit. Low end business gear is universally shit. My comcast business router is absolutely awful. I need to get around to putting it in bridge mode and putting a real router behind it. The best thing it could possibly be for me is a coax to ethernet paperweight.

Is it better to just build a home network box for a software defined network: router, firewall, possibly cable modem, etc.?

Re: New security camera compromised by worm within minutes of installation

#29

I don't understand how the bot net found his camera so instantly when he turned it on or installed it. Within moments/seconds, it was attempting to infiltrate a brand new device.

There is a lot of scanning going on by a lot of people

Back when I had an ISDN connection, I'd see 5-10 attempts a day (and I would sometimes send emails to the abuse@ address for that IP range). Now I see 5-10 a second and it's pointless to try and stop them at the source.

I'm somewhat curious if all those attempts count against my data cap.

Re: New security camera compromised by worm within minutes of installation

#30
post #26

Earlier quoted context omitted.

What? Put a firewall in front of your firewall, because more firewalls is better? How about use a firewall that's not shit to begin with.

Consumer grade gear is universally shit. Low end business gear is universally shit. My comcast business router is absolutely awful. I need to get around to putting it in bridge mode and putting a real router behind it. The best thing it could possibly be for me is a coax to ethernet paperweight.

My home "router" doesn't even have fucking bridge mode. I am mad about it.
Post reply on HN