You can have the same problem with any OS that you install that is connected to the Internet before the updates are applied (ie: getting a compromised computer in a a few minutes, being Windows or Linux)
Except that these devices do not have updates and are impossible to fix.
New security camera compromised by worm within minutes of installation
61–70 of 94 posts
Re: New security camera compromised by worm within minutes of installation
#62Earlier quoted context omitted.
Probably sniffing the packets should work. But even if you do that properly there is always a high chance your router will be compromised and you won't be able to fix it. To be extra sure just treat it as such and put a firewall between it and your LAN. That requires time to configure, but may satisfy the paranoid.
What? Put a firewall in front of your firewall, because more firewalls is better? How about use a firewall that's not shit to begin with.
Re: New security camera compromised by worm within minutes of installation
#63I don't understand how the bot net found his camera so instantly when he turned it on or installed it. Within moments/seconds, it was attempting to infiltrate a brand new device.
You might be too young to remember Blaster Worm. There was a time in 2003-2004 you couldnt install Windows XP/2000 when directly connected to the internet (no nat/firewall), you got infected (= reboot after 60 seconds) as soon as install process fired up RPC service.
Re: New security camera compromised by worm within minutes of installation
#64Earlier quoted context omitted.
I mean one of these dreaded combo modem/router thingies, hence the quotes. There is no bridge mode, and I cannot turn off NAT. It's also doubles as a completely fucked up DNS server which I have to override for resolv.conf.
Does your ISP allow you to get your own modem? I did this recently at home (saves money after owning it for a year, as it's "paid off" then in monthly modem rental fees), and although I have problems with the level of control my ISP has over the modem (there's no configurations or login, you activate it on their network and they control it fully), it's now just a "dumb modem" and does nothing else.
Re: New security camera compromised by worm within minutes of installation
#65As a person just starting to explore ip cameras, can anyone suggest any resources to tell if my cameras are already infected? If so, what to do? If they are only accessible locally, within the home's local intranet, it that safer?
Re: New security camera compromised by worm within minutes of installation
#66I don't understand how the bot net found his camera so instantly when he turned it on or installed it. Within moments/seconds, it was attempting to infiltrate a brand new device.
Re: New security camera compromised by worm within minutes of installation
#67Note that this was a deliberate setup. The safest thing to do for home routers is to kill UPNP, so that random devices on the inside can't open listening ports to the outside.
No no no!!!! This is going about it completely the wrong way and is setting us up for failure come IPv6 (if it's not already a thing for you).
We need half-decent security practices not a temporary workaround that requires user intervention.
In this case a randomly generated password printed somewhere inside the device's box or on the device itself is enough to stop Mirai and similar dumb botnets.
Re: New security camera compromised by worm within minutes of installation
#68This is absolutely fascinating - and stunning that it only took ~90 seconds to be infected. Turns out the source code is... open source: https://github.com/jgamblin/Mirai-Source-Code/blob/6a5941be6...
Re: New security camera compromised by worm within minutes of installation
#69Earlier quoted context omitted.
What? Put a firewall in front of your firewall, because more firewalls is better? How about use a firewall that's not shit to begin with.
Consumer grade gear is universally shit. Low end business gear is universally shit. My comcast business router is absolutely awful. I need to get around to putting it in bridge mode and putting a real router behind it. The best thing it could possibly be for me is a coax to ethernet paperweight.
This is great! Maybe we can repackage old Wi-Fi routers and sell them as connected IoT paperweights! Makes about as much sense as every other IoT device on the market.
Re: New security camera compromised by worm within minutes of installation
#70Note that this was a deliberate setup. The safest thing to do for home routers is to kill UPNP, so that random devices on the inside can't open listening ports to the outside.
>The safest thing to do for home routers is to kill UPNP No no no!!!! This is going about it completely the wrong way and is setting us up for failure come IPv6 (if it's not already a thing for you). We need half-decent security practices not a temporary workaround that requires user intervention. In this case a randomly generated password printed somewhere inside the device's box or on the device itself is enough to…
An internet that requires devices to be publicly exposed to the entire internet, and directly addressable at all times, is not an internet I want to participate in.
You WILL negotiate a firewall, before learning anything about the devices I use.
ESPECIALLY if I am prevented from knowing their internals, whether by willful disclosure or unlawful reverse engineering.
I control The Spice.
I control the universe.