Live data from Hacker News

Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

threatpost.com

1–10 of 37 posts

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#2
My house security and automation systems are all behind a firewall and access to them is proxied, including the video feed concentrator for the security cameras. I've had folks call this overkill but I won't directly expose any IoT-like thing to the Internet these days.

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#4
Somewhat off-topic:

Recently I watched a news segment in Korea about CCTVs connected to the internet without proper security: so many were wide open, and some could even record sound and play it real-time, and their lists were plainly accessible on some websites. The reporter said that the government had responded by blocking these websites from the Korean internet but people still found ways to access them via VPN.

As if that's the crux of the problem.

The mind boggles.

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#5
“It’s unfortunate, but each camera will need to be updated manually by users,”

So most people aren't going to bother unless they get an alarming email from the manufacturer (assuming they even have a list of customer email addresses). Although these appear to be DVR systems for commercial use so it's more likely that a business would have a service contract with someone to manage these things. The service vendor would probably be more inclined to patch the thing than the business owner would.

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#7
Calling the second one a bug is ridiculous. “If the file /tmp/moses/ exists on the file system then an unauthenticated remote attacker can list all of the non-admin users and change their passwords“. That functionality is way too intentional.

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#9
post #4

Somewhat off-topic: Recently I watched a news segment in Korea about CCTVs connected to the internet without proper security: so many were wide open, and some could even record sound and play it real-time, and their lists were plainly accessible on some websites. The reporter said that the government had responded by blocking these websites from the Korean internet but people still found ways to access them via VPN.…

There is or was a subreddit for linking to such potentially unintentionally accessible live feeds. One way to find them was to google certain terms/directory structures/page names that the viewing pages contained. Sometimes they even had panels that let you control the camera's direction.
Post reply on HN