Slightly off topic, but could anyone suggest how my laptop on my home network could get portscanned by my router? I've had the same router (D-Link DSL) with the same config for a few years and never had that happen... can the be infected?!
New security camera compromised by worm within minutes of installation
71–80 of 94 posts
Re: New security camera compromised by worm within minutes of installation
#72Earlier quoted context omitted.
They do it so they can view the camera remotely, like when they're on vacation.
Take a look at Axis Secure Remote Access solution for a way to avoid port forwarding (with its issues) and still get remote access, basically no configuration at all except from actually initially adding the camera to your site. Only works on Axis cameras though with Axis client software I should mention.
Re: New security camera compromised by worm within minutes of installation
#73Slightly off topic, but could anyone suggest how my laptop on my home network could get portscanned by my router? I've had the same router (D-Link DSL) with the same config for a few years and never had that happen... can the be infected?!
How do you know your laptop is being portscanned?
Having traffic from the router blocked was a PITA though!
Re: New security camera compromised by worm within minutes of installation
#74Earlier quoted context omitted.
>The safest thing to do for home routers is to kill UPNP No no no!!!! This is going about it completely the wrong way and is setting us up for failure come IPv6 (if it's not already a thing for you). We need half-decent security practices not a temporary workaround that requires user intervention. In this case a randomly generated password printed somewhere inside the device's box or on the device itself is enough to…
Yes. Yes. Yes. An internet that requires devices to be publicly exposed to the entire internet, and directly addressable at all times, is not an internet I want to participate in. You WILL negotiate a firewall, before learning anything about the devices I use. ESPECIALLY if I am prevented from knowing their internals, whether by willful disclosure or unlawful reverse engineering. I control The Spice. I control the un…
NAT, and uPnP, is not that. In the case of uPnP: if uPnP was SOP, wouldn't the camera (needing to be "remotely accessible" because the Internet of Crap) just make the requisite uPnP calls, likely making everything accessible?
NAT, in particular, is terrible. Trying to explain to a normal user how to establish NAT port-forwarding for devices or applications is a UX nightmare. NAT, in particular, kills off entire classes of protocol design, necessitating hacking around NAT by routing traffic through untrustable third-party servers.
NAT is further not a firewall: one anything inside your NAT gets remotely exploited, and everything else is wide open. (And that's at best; depending on the protocol in use, you might not even need remote code execution.)
(And uPnP's support in my experience has been utterly pathetic.)
Re: New security camera compromised by worm within minutes of installation
#75Earlier quoted context omitted.
Consumer grade gear is universally shit. Low end business gear is universally shit. My comcast business router is absolutely awful. I need to get around to putting it in bridge mode and putting a real router behind it. The best thing it could possibly be for me is a coax to ethernet paperweight.
Low end business hardware is just consumer hardware with "business" written on the box and a couple of strings changed on the web interface. I won't even buy an AP unless it has a DD-WRT/OpenWRT/Tomato image. I've had way too much pain with whatever shit the vendor crapped into the box before they shoved it out the door.
These days that's MikroTik/RouterBoard for me.
Re: New security camera compromised by worm within minutes of installation
#76Earlier quoted context omitted.
Mikrotik. Or EdgeRouter Lite or X. $100, Debian-based, they even sell it with an SFP port. You can install FreeBSD if you like that better.
> Mikrotik. Mikrotiks are an amazing value! Usually they are way over spec'ed for their intended purpose as well, which means you're getting even more bang for your buck. They have models for home users, businesses, all the way up to ISP "carrier grade" equipment. They used to be difficult to configure (you needed to know quite a bit about networking and how Mikrotik's do things, since they originally targeted only W…
WebFig, GUI WinBox, and SSH/Telnet feature parity and a config I can export and read as text, fully featured boxes with gigabit for ~$50 USD, need I go on?
Re: New security camera compromised by worm within minutes of installation
#77Re: New security camera compromised by worm within minutes of installation
#78Earlier quoted context omitted.
>The safest thing to do for home routers is to kill UPNP No no no!!!! This is going about it completely the wrong way and is setting us up for failure come IPv6 (if it's not already a thing for you). We need half-decent security practices not a temporary workaround that requires user intervention. In this case a randomly generated password printed somewhere inside the device's box or on the device itself is enough to…
Yes. Yes. Yes. An internet that requires devices to be publicly exposed to the entire internet, and directly addressable at all times, is not an internet I want to participate in. You WILL negotiate a firewall, before learning anything about the devices I use. ESPECIALLY if I am prevented from knowing their internals, whether by willful disclosure or unlawful reverse engineering. I control The Spice. I control the un…
Re: New security camera compromised by worm within minutes of installation
#79Earlier quoted context omitted.
Yes. Yes. Yes. An internet that requires devices to be publicly exposed to the entire internet, and directly addressable at all times, is not an internet I want to participate in. You WILL negotiate a firewall, before learning anything about the devices I use. ESPECIALLY if I am prevented from knowing their internals, whether by willful disclosure or unlawful reverse engineering. I control The Spice. I control the un…
I wouldn't/don't mind better research/work into better permission systems for OS's/processes; allowing the user control over what gets exposed to incoming connections and what is allowed to make outgoing connections is fine and good. NAT, and uPnP, is not that. In the case of uPnP: if uPnP was SOP, wouldn't the camera (needing to be "remotely accessible" because the Internet of Crap) just make the requisite uPnP call…
Obscurity and inscrutability certainly will never supplant the Objective Ideological Truth that "Security" tries to be, but it's often useful as a source of leverage when all other leverage would be denied to you.
You could never ever claim to endorse obscurity for its own sake during a daily stand-up or a conference call, because people woud rip you to shreds for any number of valid reasons, but when push comes to shove, and you find yourself on the losing side of someone else's moral hazard, being able to throw a smoke screen up, where a brick wall would be preferred, is sometimes all you can do.
Re: New security camera compromised by worm within minutes of installation
#80Earlier quoted context omitted.
I mean one of these dreaded combo modem/router thingies, hence the quotes. There is no bridge mode, and I cannot turn off NAT. It's also doubles as a completely fucked up DNS server which I have to override for resolv.conf.
Does your ISP allow you to get your own modem? I did this recently at home (saves money after owning it for a year, as it's "paid off" then in monthly modem rental fees), and although I have problems with the level of control my ISP has over the modem (there's no configurations or login, you activate it on their network and they control it fully), it's now just a "dumb modem" and does nothing else.