New security camera compromised by worm within minutes of installation
twitter.com
twitter.com
https://github.com/jgamblin/Mirai-Source-Code/blob/6a5941be6...
I'm writing personal home automation stuff and will be wiring up a handful of IoT SmartPlugs.
With all this IoT stuff i'm starting to wonder if buying a 2nd router to isolate the IoT, or perhaps a "really good" router with features designed for monitoring IoT.
Regardless, this is a problem i won't be able to ignore. So any advice is appreciated :)
Or, if you have a non-switching hub, you can use that instead of a PC with two NICs.
2 are they? have you scanned yourself? even something from the kooky Gibson should be enough https://www.grc.com/shieldsup
The safest thing to do for home routers is to kill UPNP, so that random devices on the inside can't open listening ports to the outside.
How can I verify that upnp is really disabled? (I don't trust my router to do it correctly)
But even if you do that properly there is always a high chance your router will be compromised and you won't be able to fix it.
To be extra sure just treat it as such and put a firewall between it and your LAN. That requires time to configure, but may satisfy the paranoid.
How about use a firewall that's not shit to begin with.
Low end business gear is universally shit. My comcast business router is absolutely awful. I need to get around to putting it in bridge mode and putting a real router behind it. The best thing it could possibly be for me is a coax to ethernet paperweight.
some ISPs don't allow you to enable the bridge mode on the management website of the device. you need to logon to their website with your service account and either open an actual ticket or go through an automated process to "unlock" bridge-mode.
its kinda silly but understandable, as you need to have some understanding of networking for this but most people dont have any at all. and incorrectly configured bridge mode kills any chance of internet for consumers.
Mikrotiks are an amazing value! Usually they are way over spec'ed for their intended purpose as well, which means you're getting even more bang for your buck.
They have models for home users, businesses, all the way up to ISP "carrier grade" equipment.
They used to be difficult to configure (you needed to know quite a bit about networking and how Mikrotik's do things, since they originally targeted only WISP and more traditional ISP customers), but that's changed significantly in the past few years. They have 1-click setup wizards now, so even people with no networking experience can get up and running quickly, just like your run-of-the-mill Netgear router.
Also, you can run RouterOS (the OS on Mikrotiks/Routerboards) on x86 hardware, so you can build your own router if you have the need.
WebFig, GUI WinBox, and SSH/Telnet feature parity and a config I can export and read as text, fully featured boxes with gigabit for ~$50 USD, need I go on?
Maybe you mean your modem? Bridging a router doesn't make much sense... since it's not a router then.
Although I suppose you could have one of those dreaded "combo" modem/router things ISP's peddle these days. There certainly should be a bridge option in that case, and you're rightfully mad if it doesn't!
I did this recently at home (saves money after owning it for a year, as it's "paid off" then in monthly modem rental fees), and although I have problems with the level of control my ISP has over the modem (there's no configurations or login, you activate it on their network and they control it fully), it's now just a "dumb modem" and does nothing else.
I won't even buy an AP unless it has a DD-WRT/OpenWRT/Tomato image. I've had way too much pain with whatever shit the vendor crapped into the box before they shoved it out the door.
These days that's MikroTik/RouterBoard for me.
This is great! Maybe we can repackage old Wi-Fi routers and sell them as connected IoT paperweights! Makes about as much sense as every other IoT device on the market.
No no no!!!! This is going about it completely the wrong way and is setting us up for failure come IPv6 (if it's not already a thing for you).
We need half-decent security practices not a temporary workaround that requires user intervention.
In this case a randomly generated password printed somewhere inside the device's box or on the device itself is enough to stop Mirai and similar dumb botnets.
An internet that requires devices to be publicly exposed to the entire internet, and directly addressable at all times, is not an internet I want to participate in.
You WILL negotiate a firewall, before learning anything about the devices I use.
ESPECIALLY if I am prevented from knowing their internals, whether by willful disclosure or unlawful reverse engineering.
I control The Spice.
I control the universe.
NAT, and uPnP, is not that. In the case of uPnP: if uPnP was SOP, wouldn't the camera (needing to be "remotely accessible" because the Internet of Crap) just make the requisite uPnP calls, likely making everything accessible?
NAT, in particular, is terrible. Trying to explain to a normal user how to establish NAT port-forwarding for devices or applications is a UX nightmare. NAT, in particular, kills off entire classes of protocol design, necessitating hacking around NAT by routing traffic through untrustable third-party servers.
NAT is further not a firewall: one anything inside your NAT gets remotely exploited, and everything else is wide open. (And that's at best; depending on the protocol in use, you might not even need remote code execution.)
(And uPnP's support in my experience has been utterly pathetic.)
Obscurity and inscrutability certainly will never supplant the Objective Ideological Truth that "Security" tries to be, but it's often useful as a source of leverage when all other leverage would be denied to you.
You could never ever claim to endorse obscurity for its own sake during a daily stand-up or a conference call, because people woud rip you to shreds for any number of valid reasons, but when push comes to shove, and you find yourself on the losing side of someone else's moral hazard, being able to throw a smoke screen up, where a brick wall would be preferred, is sometimes all you can do.
For some people, it's just worth $150 + 10/mo to not have something else to think about.
It's common knowledge in the industry that all of these devices likely have government backdoors or (likely deliberate) critical security flaws at any moment.
Virtually all CCTV hardware comes from ruthless and unregulated Chinese markets where the goal is to obfuscate the price (and source) as much as possible, to prevent price discovery by the end user and allow 2-4x markups on the equipment by the integrator.
Usually these manufacturers will sell to separate companies for their name brand, off-brand, and offer custom branding to distributors.
Due to the obfuscstion of manufacturing source, and at the same time a desire to "stand out" amonst the rest, the industry is rife with knockoffs, third-shift products, stolen technology, unauthorized distribution, you name it.
As an example: Every single Hikvision camera on amazon.com is an illegal sale and void of any official support from Hikvision. Go ahead and try to call them with a serial number for a product you bought on amazon and see what happens. It doesn't matter that the company selling the product on amazon is also named Hikvision (its an imposter).
Point being, the surveillance camera market is so rife with corruption that you generally accept that everything is compromised.
But none of it matters, because as long as the features work and the equipment is reliable, you simply throw it all behind an isolated network and call it a day.
There is even services that scan the whole ipv4 in less than 5 minutes: https://zmap.io/
And a list of how to do it: http://www.securitynewspaper.com/2015/10/15/how-to-scan-whol...
https://nakedsecurity.sophos.com/2013/01/29/what-if-your-sec...
https://en.wikipedia.org/wiki/Universal_Plug_and_Play#Proble...
I'm somewhat curious if all those attempts count against my data cap.
I don't see why they wouldn't. IP (which is really the layer ISPs should operate at) does not distinguish between packets that you have "requested" and unsolicited packets, being connectionless protocol and all.
There is nothing inherently wrong with port scanning and it should not, by default, be considered "abuse".
Aren't remote exploits quite rare?
These cameras are at risk because the run web servers and use UPnP to make themselves directly available on public IP addresses.
I've had the same router (D-Link DSL) with the same config for a few years and never had that happen... can the be infected?!
Having traffic from the router blocked was a PITA though!
The twitter stream narrates what he configured before turning the webcam on, and give details on how things unfolded.
Otherwise, if you get robbed, and they happen to steal your NAS, you've lost the main reason to have a security camera in the first place - to identify the perp.
Only works on Axis cameras though with Axis client software I should mention.
I much prefer this model, because then I don't have to trust all these terrible cameras; simply isolate them on a private wifi network that only your Blue Iris server can reach.
Regarding servers vs cameras: To oversimplify; servers can have exponentially more capacity. Either how, in this case, the traffic is encrypted in each end so there's nothing to be done by "the middle man servers", they can't decrypt anything cause they don't possess the keys.