Live data from Hacker News

Hacker Pwns Police Cruiser and Lives to Tell the Tale

theregister.co.uk

1–10 of 39 posts

Re: Hacker Pwns Police Cruiser and Lives to Tell the Tale

#2
Our company had a security system installed with cameras and DVR. About a week after it was installed I scanned the internal network and found the device. Googled for the open port detected and found the software to access the device. Upon connecting to the device it asked for a user and password. I didn't enter any and it logged me in. I had control of the device. It's scary what "security" companies install on your network.

Re: Hacker Pwns Police Cruiser and Lives to Tell the Tale

#4

Our company had a security system installed with cameras and DVR. About a week after it was installed I scanned the internal network and found the device. Googled for the open port detected and found the software to access the device. Upon connecting to the device it asked for a user and password. I didn't enter any and it logged me in. I had control of the device. It's scary what "security" companies install on your…

I suppose that securing your security system is a comparatively new concept which requires a significant jump in technical understanding.

Re: Hacker Pwns Police Cruiser and Lives to Tell the Tale

#5

This is always good for a laugh: https://encrypted.google.com/search?q=intitle%3A%22Live+View... https://encrypted.google.com/search?q=inurl%3Aview%2Fview.sh... Never turned up anything as fun as a policecar though.

Every time I feel like I've got a grasp on just how insecure things are on the Internet, it's like someone hits me over the head with slice of lemon, wrapped around a large gold brick.

Re: Hacker Pwns Police Cruiser and Lives to Tell the Tale

#7

This is always good for a laugh: https://encrypted.google.com/search?q=intitle%3A%22Live+View... https://encrypted.google.com/search?q=inurl%3Aview%2Fview.sh... Never turned up anything as fun as a policecar though.

Every time I feel like I've got a grasp on just how insecure things are on the Internet, it's like someone hits me over the head with slice of lemon, wrapped around a large gold brick.

To be fair, 90% of them are just webcams of tourist destinations, they're probably linked from travel agency homepages. Google has to get to them somehow.

Sometimes though, you get one of someones office. Just very occasionally, you hit one with the controls to move the thing around, and you can make it wave at people and watch them freak out.

Re: Hacker Pwns Police Cruiser and Lives to Tell the Tale

#8
What troubles me about this story is not so much the lack of security protecting the camera's and the DVR, but the fact the police department was wasting scarce IPv4 addresses on laptops and security cameras. These devices should have been on a private internal network with private IP addresses.

Just saying. :)

Re: Hacker Pwns Police Cruiser and Lives to Tell the Tale

#9

Earlier quoted context omitted.

Every time I feel like I've got a grasp on just how insecure things are on the Internet, it's like someone hits me over the head with slice of lemon, wrapped around a large gold brick.

To be fair, 90% of them are just webcams of tourist destinations, they're probably linked from travel agency homepages. Google has to get to them somehow. Sometimes though, you get one of someones office. Just very occasionally, you hit one with the controls to move the thing around, and you can make it wave at people and watch them freak out.

Ah. The first hit I had appeared to be in someone's bedroom.

Re: Hacker Pwns Police Cruiser and Lives to Tell the Tale

#10

Our company had a security system installed with cameras and DVR. About a week after it was installed I scanned the internal network and found the device. Googled for the open port detected and found the software to access the device. Upon connecting to the device it asked for a user and password. I didn't enter any and it logged me in. I had control of the device. It's scary what "security" companies install on your…

Which would be quite entertaining if what you encountered was really a honeytrap, looking for the identities of the more, um, inquisitive folks on the local network.

But I'm guessing it wasn't that clever.

Post reply on HN