Eagle Eye Networks

Vulnerabilities in WiFi Cameras

March 14, 2017 Eagle Eye Networks

Vulnerabilities-WIFI-Cameras-FI

Inexpensive WiFi cameras are widely available over the internet. That might sound compelling, but it’s important to understand their security holes and the risk they bring to your network.

Pierre Kim, an IT security blogger, has recently discovered 1,250 different camera models that are modified and branded by hundreds of companies.

These cameras have many vulnerabilities:

  • They contain backdoor accounts that will allow the manufacturer full access to your information
  • They connect to the cloud for the mobile app using clear text passwords
  • Anyone who has the serial number of the camera can access that camera

If you have a camera on this list, Kim recommends immediately removing it from the Internet and disposing of it.  Kim states, “I advise to IMMEDIATELY DISCONNECT cameras to the Internet. Hundreds of thousands of cameras are affected by the 0day Info-Leak. Millions of them are using the insecure Cloud network.”

Furthermore, Kim implies that the millions of cameras actually include bonnet code already: “This “cloud” protocol seems to be more a botnet protocol than a legit remote access protocol and has indeed weakness (everything in clear text, i.e. an attacker can attack cameras within the cloud and leverage potential access to hack internal networks).”

We recommend doing your research before purchasing new cameras – don’t buy cheap cameras from unknown manufacturers. Purchasing from a trusted source, even if it’s more expensive, will benefit you in the long run.

Vulnerabilities-WIFI-Cameras-FI

Tags

Other posts that might interest you

loading

DDOS Cyber Attacks Update

Last week hackers forced Brian Krebs to take down his security journalism site because of a large scale Denial of Service Attack - likely one of the largest ever seen.…

September 29, 2016 Eagle Eye Networks

WannaCry Ransomware

Unfortunately, hackers are always coming up with new ways to make money and exploit systems. Cyber is no different. The WannaCry ransomware breaks new ground in its reach, use of…

May 23, 2017 Eagle Eye Networks

Devil’s Ivy Likely Widespread

A recently discovered vulnerability labeled “Devil’s Ivy” is expected to impact millions of cameras that support the ONVIF protocol. The initial exploit was discovered on an Axis Camera and then…

July 24, 2017 Eagle Eye Networks