Thursday, April 18, 2024
spot_img
spot_img

Is This Cam Inviting Hackers into Your Home?

spot_img
spot_img
- Advertisement -

The insecurity of the IoT isn’t just some theoretical concept to be dealt with in the future when everything is connected. A new F-Secure report “Vulnerabilities in Foscam IP Cameras” finds multiple vulnerabilities plaguing tens of thousands of web-connected cameras around the globe.

In this young century, webcams have transitioned from a futuristic novelty to being, well, everywhere. The ability to capture images and video of anything anywhere played a key role in the explosion of social media, but our camera-drenched society also can make us feel uniquely vulnerable. The idea of a hacker being able to co-opt these digital eyes to capture us in our most intimate moments makes our ability to secure these digital eyes especially worrisome.

The utility of cameras, especially for physical security purposes, has made them one of the most common devices being connected to the so-called Internet of Things or, as Mikko Hypponen, F-Secure’s Chief Research Officer calls it, “the Internet of Insecure Things.”

And the insecurity of the IoT isn’t just some theoretical concept to be dealt with in the future when everything is connected. A new F-Secure report “Vulnerabilities in Foscam IP Cameras” finds multiple vulnerabilities plaguing tens of thousands of web-connected cameras around the globe.

“Foscam-made IP cameras have multiple vulnerabilities that can lead to full device compromise,” the report says. “An unauthenticated attacker can persistently compromise these cameras by employing a number of different methods leading to full loss of confidentiality, integrity and availability, depending on the actions of the attacker.”

These vulnerabilities — 18 in total, with all 18 found in the Opticam i5, and several in the Foscam C2, as well — make it possible to remotely take control of these stand-alone cams, which are often used to detect unwanted visitors.

“For example, an attacker can view the video feed, control the camera operation, and upload and download files from the built-in FTP server.” Not only that, with the help of some malicious code, attackers can leverage this camera to access the rest of the network it’s in.

Foscam has been notified about the findings, and F-Secure is going public after receiving no response for months. Foscam has a history of bugs allowing access to video feeds on IP cameras and baby monitors.

Janne Kauhanen of F-Secure Cyber Security Services advises that all users of all smart devices change their default passwords, always. No exceptions. But even that would not necessarily be enough to protect these vulnerable Foscam-made cameras, which include factory hard-coded credentials that cannot be changed by the user. An attacker who knows these hard-coded credentials (by finding them published on the internet, for example, which often happens) can use them to bypass the user’s own unique credentials.

And this is just one of the crops of vulnerabilities. Harry Sintonen of Cyber Security Services, who discovered them, describes them as “as bad as it gets.” The sheer number of vulnerabilities allows an attacker to pick and choose from multiple ways to take over the camera.

If you happen to have one of these cameras in your home, make sure that it is NOT exposed to the public internet. A firewall significantly reduces the risk of infection. And a smart security router like F-Secure SENSE —which uses artificial intelligence to sense the traffic of all your connected home devices — can also detect if your cameras or baby monitors are being misused.

The intimacy we grant cameras presents a unique opportunity to highlight the dangers of putting everything online without prioritizing security. And it’s an issue that needs highlighting now.

Even after co-opted IoT devices were used as part of the largest denial of service attack in history, manufacturers have demonstrated no eagerness to address this growing problem.

“The problem is bigger than this camera, this manufacturer,” said Janne said. “Smart devices, in general, are vulnerable. I think this is because manufacturers don’t consider security a selling point. And consumers certainly aren’t demanding it.”

Perhaps the idea of tens of thousands of vulnerable cameras might begin to change that.

- Advertisement -

133 COMMENTS

  1. Oh my goodness! Awesome article dude! Many thanks, However I am experiencing troubles with your RSS. I donít know why I am unable to subscribe to it. Is there anybody else getting the same RSS issues? Anybody who knows the solution will you kindly respond? Thanx!!

  2. Hi, I do think this is an excellent site. I stumbledupon it 😉 I’m going to come back yet again since i have saved as a favorite it. Money and freedom is the greatest way to change, may you be rich and continue to guide other people.

  3. Having read this I thought it was really enlightening. I appreciate you taking the time and energy to put this article together. I once again find myself spending a significant amount of time both reading and commenting. But so what, it was still worthwhile!

  4. You’re so awesome! I do not believe I’ve truly read through something like that before. So good to find another person with a few unique thoughts on this subject matter. Seriously.. thank you for starting this up. This web site is something that’s needed on the web, someone with a bit of originality!

  5. Hi, I do think this is a great website. I stumbledupon it 😉 I am going to come back once again since i have saved as a favorite it. Money and freedom is the greatest way to change, may you be rich and continue to help other people.

  6. Iím amazed, I have to admit. Rarely do I encounter a blog thatís both equally educative and engaging, and without a doubt, you have hit the nail on the head. The issue is something not enough people are speaking intelligently about. I’m very happy I found this during my search for something relating to this.

  7. The next time I read a blog, Hopefully it won’t fail me as much as this particular one. I mean, I know it was my choice to read through, nonetheless I genuinely thought you would probably have something interesting to talk about. All I hear is a bunch of crying about something you could fix if you weren’t too busy looking for attention.

  8. Aw, this was a really nice post. Finding the time and actual effort to generate a really good articleÖ but what can I sayÖ I hesitate a lot and don’t seem to get nearly anything done.

  9. I think this is one of the most important info for me. And i’m glad reading your article. But want to remark on some general things, The web site style is great, the articles is really great : D. Good job, cheers|

  10. We absolutely love your blog and find many of your post’s to be exactly what I’m looking for. Do you offer guest writers to write content for yourself? I wouldn’t mind composing a post or elaborating on most of the subjects you write regarding here. Again, awesome site!|

  11. Write more, thats all I have to say. Literally, it seems as though you relied on the video to make your point. You definitely know what youre talking about, why throw away your intelligence on just posting videos to your weblog when you could be giving us something informative to read?|

  12. Hey I know this is off topic but I was wondering if you knew of any widgets I could add to my blog that automatically tweet my newest twitter updates. I’ve been looking for a plug-in like this for quite some time and was hoping maybe you would have some experience with something like this. Please let me know if you run into anything. I truly enjoy reading your blog and I look forward to your new updates.|

  13. Hey are using WordPress for your site platform? I’m new to the blog world but I’m trying to get started and create my own. Do you need any coding expertise to make your own blog? Any help would be really appreciated!|

  14. Good day! I simply wish to offer you a huge thumbs up for the excellent info you have right here on this post. I will be returning to your site for more soon.|

  15. Undeniably believe that which you stated. Your favourite justification appeared to be on the internet the simplest thing to remember of. I say to you, I definitely get irked at the same time as folks consider concerns that they plainly don’t recognise about. You controlled to hit the nail upon the top and also outlined out the entire thing with no need side effect , folks can take a signal. Will probably be back to get more. Thanks|

LEAVE A REPLY

Please enter your comment!
Please enter your name here

spot_img
spot_img
spot_img
spot_img