Live data from Hacker News

New security camera compromised by worm within minutes of installation

twitter.com

41–50 of 94 posts

Re: New security camera compromised by worm within minutes of installation

#41
post #29

Earlier quoted context omitted.

There is a lot of scanning going on by a lot of people

Back when I had an ISDN connection, I'd see 5-10 attempts a day (and I would sometimes send emails to the abuse@ address for that IP range). Now I see 5-10 a second and it's pointless to try and stop them at the source. I'm somewhat curious if all those attempts count against my data cap.

Same. I have about 500 different IP every month trying to RDP into my servers. I add them automatically to the firewall of my servers.

Re: New security camera compromised by worm within minutes of installation

#43
post #42

You can have the same problem with any OS that you install that is connected to the Internet before the updates are applied (ie: getting a compromised computer in a a few minutes, being Windows or Linux)

I thought that is only with old (like 1 year or older) OS versions?

Aren't remote exploits quite rare?

Re: New security camera compromised by worm within minutes of installation

#44
post #30
post #26

Earlier quoted context omitted.

Consumer grade gear is universally shit. Low end business gear is universally shit. My comcast business router is absolutely awful. I need to get around to putting it in bridge mode and putting a real router behind it. The best thing it could possibly be for me is a coax to ethernet paperweight.

My home "router" doesn't even have fucking bridge mode. I am mad about it.

not saying its the case for you, but it might be interesting to some:

some ISPs don't allow you to enable the bridge mode on the management website of the device. you need to logon to their website with your service account and either open an actual ticket or go through an automated process to "unlock" bridge-mode.

its kinda silly but understandable, as you need to have some understanding of networking for this but most people dont have any at all. and incorrectly configured bridge mode kills any chance of internet for consumers.

Re: New security camera compromised by worm within minutes of installation

#45
post #30
post #26

Earlier quoted context omitted.

Consumer grade gear is universally shit. Low end business gear is universally shit. My comcast business router is absolutely awful. I need to get around to putting it in bridge mode and putting a real router behind it. The best thing it could possibly be for me is a coax to ethernet paperweight.

My home "router" doesn't even have fucking bridge mode. I am mad about it.

Even so, I'd setup my own router/firewall and handle the ISP supplied device as essentially untrusted. It won't be pretty, but its at least tolerable solution until you can work out a better setup.

Re: New security camera compromised by worm within minutes of installation

#46

TL;DR: Guy bought a webcam, installed it, and within one and a half minute it was already infected and even kicked him off his telnet connection. The twitter stream narrates what he configured before turning the webcam on, and give details on how things unfolded.

It's like the old days of installing XP from a CD and then putting it online to get patches. You would have half a dozen viruses on the box before you finished connecting to Windows Update.

Re: New security camera compromised by worm within minutes of installation

#47
post #26

Earlier quoted context omitted.

What? Put a firewall in front of your firewall, because more firewalls is better? How about use a firewall that's not shit to begin with.

Consumer grade gear is universally shit. Low end business gear is universally shit. My comcast business router is absolutely awful. I need to get around to putting it in bridge mode and putting a real router behind it. The best thing it could possibly be for me is a coax to ethernet paperweight.

Low end business hardware is just consumer hardware with "business" written on the box and a couple of strings changed on the web interface.

I won't even buy an AP unless it has a DD-WRT/OpenWRT/Tomato image. I've had way too much pain with whatever shit the vendor crapped into the box before they shoved it out the door.

Re: New security camera compromised by worm within minutes of installation

#48

This is absolutely fascinating - and stunning that it only took ~90 seconds to be infected. Turns out the source code is... open source: https://github.com/jgamblin/Mirai-Source-Code/blob/6a5941be6...

Just to clarify it's not published by the author - the author got hacked and their source leaked.

Re: New security camera compromised by worm within minutes of installation

#49
post #42

You can have the same problem with any OS that you install that is connected to the Internet before the updates are applied (ie: getting a compromised computer in a a few minutes, being Windows or Linux)

I thought that is only with old (like 1 year or older) OS versions? Aren't remote exploits quite rare?

I don't think a rule of thumb like that is really valid. Someone could be scanning for hosts with zero days right now.

Re: New security camera compromised by worm within minutes of installation

#50
post #16

Note that this was a deliberate setup. The safest thing to do for home routers is to kill UPNP, so that random devices on the inside can't open listening ports to the outside.

Hmm, what do you mean by "deliberate setup"? Reading through it, it looks like the behavior any naive user would do while setting up the camera.

I think they mean that he didn't take reasonable precautions to prevent it being hacked, but as you said that's because most users won't take those precautions either. The intention was for this to get hacked though.
Post reply on HN