Live data from Hacker News

This security camera was infected by malware 98 seconds after it was plugged in

techcrunch.com

11–20 of 37 posts

Re: This security camera was infected by malware 98 seconds after it was plugged in

#11
From the tweet pics, it looks like the outside IP was able to connect to the camera via telnet.

Does the camera firmware open a UPNP tunnel in AP to its telnet port?

Does this guy's Wifi router enable anyone one to open tunnels in his AP router?

Re: This security camera was infected by malware 98 seconds after it was plugged in

#13

From the tweet pics, it looks like the outside IP was able to connect to the camera via telnet. Does the camera firmware open a UPNP tunnel in AP to its telnet port? Does this guy's Wifi router enable anyone one to open tunnels in his AP router?

UPnP is turned on by default on almost all access points.

Re: This security camera was infected by malware 98 seconds after it was plugged in

#14
post #5

How would the malware even know that the camera was connected in? Especially if you're on a home network (which is firewalled / has NAT on). I suspect that it must be the central server that this camera reports to that is infected, either directly, or indirectly with some program sitting at a nearby router listening for traffic.

Assuming the router is somehow allowing NAT punctures or port forwarding, or if there is no router, then any easily compromised device will be compromised within 5 minutes of connecting it to the Internet.

Usually much less than 5 minutes. There's just that much Internet scanning.

If NAT is configured properly, then there is no risk.

Re: This security camera was infected by malware 98 seconds after it was plugged in

#15
post #5

How would the malware even know that the camera was connected in? Especially if you're on a home network (which is firewalled / has NAT on). I suspect that it must be the central server that this camera reports to that is infected, either directly, or indirectly with some program sitting at a nearby router listening for traffic.

Because the camera requests port forwarding from your firewall using UPnP. Now your mobile app connects directly to port 83785 and streams video from the camera without any firewall hassles. The problem now is that hackers can also connect to port 83785 and exploit unpatched security holes. If a firmware update exists, its probably too technically challenging for Joe User to find and install. For a lot of these devic…

so are you stating the hacker was notified, or was the hacker polling to check the port?

Re: This security camera was infected by malware 98 seconds after it was plugged in

#18

News flash: If you expose a device web-accessible port to an internet IP with no firewall and leave the default user name and password intact, it will get hacked. Put your shit behind firewalls and change the default user name and password to something secure. This is common sense stuff, people. Port scanners have existed for ages.

What if the device opens up some random port via UPnP? What then? Do you turn off UPnP? If you did, why did you even buy this camera?

Re: This security camera was infected by malware 98 seconds after it was plugged in

#19
post #6

What is a good security camera? Who makes good ones? I haven't been able to find a company who provides a quality POE device that allows me to control the feed into something like Zoneminder. Do I have to use something more analog to be "safer" from something like this?

We use Ubiquiti Unifi. We use their software with it, but I'm sure you could feed it into Zoneminder. Very happy with it.
Post reply on HN