You can have the same problem with any OS that you install that is connected to the Internet before the updates are applied (ie: getting a compromised computer in a a few minutes, being Windows or Linux)
New security camera compromised by worm within minutes of installation
51–60 of 94 posts
Re: New security camera compromised by worm within minutes of installation
#52As a person just starting to explore ip cameras, can anyone suggest any resources to tell if my cameras are already infected? If so, what to do? If they are only accessible locally, within the home's local intranet, it that safer?
Re: New security camera compromised by worm within minutes of installation
#53Earlier quoted context omitted.
Consumer grade gear is universally shit. Low end business gear is universally shit. My comcast business router is absolutely awful. I need to get around to putting it in bridge mode and putting a real router behind it. The best thing it could possibly be for me is a coax to ethernet paperweight.
My home "router" doesn't even have fucking bridge mode. I am mad about it.
Re: New security camera compromised by worm within minutes of installation
#54I've had the same router (D-Link DSL) with the same config for a few years and never had that happen... can the be infected?!
Re: New security camera compromised by worm within minutes of installation
#55Earlier quoted context omitted.
My home "router" doesn't even have fucking bridge mode. I am mad about it.
Mikrotik. Or EdgeRouter Lite or X. $100, Debian-based, they even sell it with an SFP port. You can install FreeBSD if you like that better.
Mikrotiks are an amazing value! Usually they are way over spec'ed for their intended purpose as well, which means you're getting even more bang for your buck.
They have models for home users, businesses, all the way up to ISP "carrier grade" equipment.
They used to be difficult to configure (you needed to know quite a bit about networking and how Mikrotik's do things, since they originally targeted only WISP and more traditional ISP customers), but that's changed significantly in the past few years. They have 1-click setup wizards now, so even people with no networking experience can get up and running quickly, just like your run-of-the-mill Netgear router.
Also, you can run RouterOS (the OS on Mikrotiks/Routerboards) on x86 hardware, so you can build your own router if you have the need.
Re: New security camera compromised by worm within minutes of installation
#56Earlier quoted context omitted.
Consumer grade gear is universally shit. Low end business gear is universally shit. My comcast business router is absolutely awful. I need to get around to putting it in bridge mode and putting a real router behind it. The best thing it could possibly be for me is a coax to ethernet paperweight.
My home "router" doesn't even have fucking bridge mode. I am mad about it.
Maybe you mean your modem? Bridging a router doesn't make much sense... since it's not a router then.
Although I suppose you could have one of those dreaded "combo" modem/router things ISP's peddle these days. There certainly should be a bridge option in that case, and you're rightfully mad if it doesn't!
Re: New security camera compromised by worm within minutes of installation
#57Earlier quoted context omitted.
My home "router" doesn't even have fucking bridge mode. I am mad about it.
> My home "router" doesn't even have fucking bridge mode. Maybe you mean your modem? Bridging a router doesn't make much sense... since it's not a router then. Although I suppose you could have one of those dreaded "combo" modem/router things ISP's peddle these days. There certainly should be a bridge option in that case, and you're rightfully mad if it doesn't!
Re: New security camera compromised by worm within minutes of installation
#58You can have the same problem with any OS that you install that is connected to the Internet before the updates are applied (ie: getting a compromised computer in a a few minutes, being Windows or Linux)
These cameras are at risk because the run web servers and use UPnP to make themselves directly available on public IP addresses.
Re: New security camera compromised by worm within minutes of installation
#59Earlier quoted context omitted.
There is a lot of scanning going on by a lot of people
Back when I had an ISDN connection, I'd see 5-10 attempts a day (and I would sometimes send emails to the abuse@ address for that IP range). Now I see 5-10 a second and it's pointless to try and stop them at the source. I'm somewhat curious if all those attempts count against my data cap.
There is nothing inherently wrong with port scanning and it should not, by default, be considered "abuse".
Re: New security camera compromised by worm within minutes of installation
#60Earlier quoted context omitted.
> My home "router" doesn't even have fucking bridge mode. Maybe you mean your modem? Bridging a router doesn't make much sense... since it's not a router then. Although I suppose you could have one of those dreaded "combo" modem/router things ISP's peddle these days. There certainly should be a bridge option in that case, and you're rightfully mad if it doesn't!
I mean one of these dreaded combo modem/router thingies, hence the quotes. There is no bridge mode, and I cannot turn off NAT. It's also doubles as a completely fucked up DNS server which I have to override for resolv.conf.
I did this recently at home (saves money after owning it for a year, as it's "paid off" then in monthly modem rental fees), and although I have problems with the level of control my ISP has over the modem (there's no configurations or login, you activate it on their network and they control it fully), it's now just a "dumb modem" and does nothing else.