This security camera was infected by malware 98 seconds after it was plugged in
techcrunch.com
techcrunch.com
I expect the IoT to go though a similar phase, but eventually get fixed and be secure enough.
IoT may always be plagued by cheap hardware with buggy software from fly-by-night companies.
This time, though, I don't see a tenable path to actually fix this. The IoT industry is terribly, terribly fragmented. Few business models incentivize providing ongoing maintenance once they've sold you their gizmo. Few consumers have the ability to detect that this is happening.
I suspect that security and compatibility issues will cripple a large chunk of the IoT industry, with bigger players slowly picking off the profitable/useful chunks with niche products customers will think of as 'safe' (read: Amazon/Google's many IoT products).
In the mean time, I'll continue avoiding smart/IoT devices in my house. The risks seem to far, far, outweigh the rewards.
I haven't been able to find a company who provides a quality POE device that allows me to control the feed into something like Zoneminder.
Do I have to use something more analog to be "safer" from something like this?
https://www.ubnt.com/unifi-video/unifi-video-camera-g3-dome/
I'm going to get some for my new house. I already have some of their other gear and it has been rock solid so far.
Wow.
I don't know about other ports, other than HTTP I don't have any open.
A server on slow home broadband in the UK is only receiving 100-300 attempts per day. It's almost identical to the one in Denmark, except the broadband is terrible.
Several servers in a university's IP space has about 5000-10000 attempts per day.
This seems like a bold claim, unless they define "better quality".
I suspect that it must be the central server that this camera reports to that is infected, either directly, or indirectly with some program sitting at a nearby router listening for traffic.
If a firmware update exists, its probably too technically challenging for Joe User to find and install. For a lot of these devices, there isn't even a published fix. These manufacturers are just rebranding some generic camera from a larger manufacturer or using the same camera and IoT guts and putting them into different cases. These companies probably don't even have a software developer on staff who has access to these firmwares, just perhaps a binary blob, assuming they have any software people on staff at all.
https://www.pentestpartners.com/blog/hacking-the-aldi-ip-cct...
Also Brian Krebs examined that Foscam camera and found it enabled a P2P protocol and opened a port on the firewall using UPnP as well:
https://krebsonsecurity.com/2016/02/this-is-why-people-fear-...
If you knew about the risk, you would have secured your router firewall. If you did not know, you wouldn't be rushing to install the firmware.
Once the camera is compromised, it can modify the firmware being transmitted (to compromise it) or prevent its install.
I suppose there's a follow-up story to be had on routers that come with UPNP enabled by default, because wherever that's the case, your firewall has a hole poked in it as soon as the device powers up and connects to the LAN.
Usually much less than 5 minutes. There's just that much Internet scanning.
If NAT is configured properly, then there is no risk.
Put your shit behind firewalls and change the default user name and password to something secure. This is common sense stuff, people. Port scanners have existed for ages.
Does the camera firmware open a UPNP tunnel in AP to its telnet port?
Does this guy's Wifi router enable anyone one to open tunnels in his AP router?
Question: interesting tweets Rob, is it used Dynamic DNS when it is initially setup? If no , how is it exposed to internet?
Answer: I had to map the external port 23 on the firewall to the device.