The article mentions Nmap as a way of identifying cameras on the network. Does anyone know how robust of a solution this is, or if there are other ways of ensuring that any cameras are found?
Edit: for example, my home network has an IP cam. So when I run the following to scan my home subnet:
nmap 10.0.0.0/24
I get an output that includes: Nmap scan report for ipcam_00626E4E5B97_1.local (10.0.0.50)
Host is up (0.023s latency).
Not shown: 999 closed ports
PORT STATE SERVICE
80/tcp open http
From that I can deduce that 10.0.0.50 is a camera and serving some sort of management web page.