The real cost of Made in China

Discuss life, the universe, and everything with other members of this site. Get to know your fellow polywell enthusiasts.

Moderators: tonybarry, MSimon

Post Reply
DeltaV
Posts: 2245
Joined: Mon Oct 12, 2009 5:05 am

The real cost of Made in China

Post by DeltaV »

More Than A Dozen Brands Of Security Camera Systems Vulnerable To Hacker Hijacking
Eighteen brands of security camera digital video recorders (DVRs) are vulnerable to an attack that would allow a hacker to remotely gain control of the devices to watch, copy, delete or alter video streams at will, as well as to use the machines as jumping-off points to access other computers behind a company’s firewall, according to tests by two security researchers. And one of the researchers, security firm Rapid7′s chief security officer H.D. Moore, has discovered that 58,000 of the hackable video boxes, all of which use firmware provided by the Guangdong, China-based firm Ray Sharp, are accessible via the Internet.

“The DVR gives you access to all their video, current and archived,” says Moore. “You could look at videos, pause and play, or just turn off the cameras and rob the store.”
“It’s just a boneheaded decision on the part of [Ray Sharp],” says Moore. “Fifty-eight thousand homes and businesses are exposed because of the way these things cut holes in the firewall.”
Not boneheaded. Clever.
By checking the web interfaces of the vulnerable devices and analyzing the Ray Sharp firmware he downloaded from Swann’s website, Moore was able to identify 18 companies that seem to use the faulty code: Swann, Lorex, URMET, KGuard, Defender, DSP Cop, SVAT, Zmodo, BCS, Bolide, EyeForce, Atlantis, Protectron, Greatek, Soyo, Hi-View, Cosmos, and J2000.
I hope EMC2 doesn't have one of these.

hanelyp
Posts: 2261
Joined: Fri Oct 26, 2007 8:50 pm

Post by hanelyp »

Sounds like it you need to have these cameras on a network, put them behind a firewall and use a VPN if you must reach them from outside.

palladin9479
Posts: 388
Joined: Mon Jan 31, 2011 5:22 am

Post by palladin9479 »

hanelyp wrote:Sounds like it you need to have these cameras on a network, put them behind a firewall and use a VPN if you must reach them from outside.
This should be standard practice. No end device should be directly accessible from the internet, it's dangerous and incredibly unsafe. For best security use a SSL based VPN solution like OpenVPN, beats the hell out of L2TP and IPSEC implementations. Properly configured it's not even detectable.

krenshala
Posts: 914
Joined: Wed Jul 16, 2008 4:20 pm
Location: Austin, TX, NorAm, Sol III

Post by krenshala »

Yeah, this sounds more like a study of sites with poor network security not sites with vulnerable security cameras. A simple rule on the external interface of your firewall(s) that drops incoming packets destined for the cameras removes the vulnerability described.

JoeP
Posts: 525
Joined: Sat Jun 25, 2011 5:10 am

Post by JoeP »

Right. Poor network security. No firewall; the cameras were installed on open wireless networks.

One could make the same complaints about how there are thousands of hackable wide-open routers out there and not tell the story about how the users just didn't bother to set up WPA or better security.

Post Reply