Big Security Hole in Surveillance CamerasAuthor: Ethan Ace, Published on Feb 06, 2012
The mainstream press has been abuzz with an IP camera vulnerability that allows people from anywhere on the Internet to directly and easily access TRENDnet cameras without any authentication. In this note, we explain how it was done, why we believe Trendnet engineers had to know about it and what implications this has for the rest of the surveillance industry.
While it took real skill for an outsider to find the exploit, usig the exploit itself is very simple. Basically, a standard URL exists that if entered provides direct access to the MJPEG video stream without any restrictions.
The hacker deconstructed Trendnet's firmware, manually inspecting the enclosed files. This inspection revealed multiple CGI scripts used for requesting live video. Trendnet had left a folder called 'anony' (as in anonymous access). In that folder is a file named mjpg.cgi. A request to that file returns a live video stream (e.g., http://192.168.1.17/anony/mjpg.cgi). Here's what the basic queries look like on a Linux distrobution:
The hacker then detailed a method by which users were able to search for Trendnet cameras available on the internet. Taking this information, active internet messageboards, such as Reddit and 4chan, set about finding as many open camera feeds as possible, sharing lists of IP addresses of cameras as they were found. This led to likely hundreds of readers of these sites viewing feeds and capturing stills from hundreds of IP cameras, many in private residences, along with businesses.
Some of these captures are extremely disconcerting, looking directly into users' homes:
We suspect that Trendnet engineers knew about this security flaw, simply because it is an obvious, "in plain sight" feature for an engineer, likely used as a backdoor or a shortcut by their internal team to do testing.
Trendnet has since released an apology and firmware update for affected cameras. However, notice of this firmware update was sent only to those users which registered their Trendnet camera, which is typically a small percentage. Additionally, given Trendnet's position in the industry, as a low-cost manufacturer often used for residential and small business systems by less tech-savvy users, many users will be unlikely to ever hear about this issue and subsequent fix, leaving them vulnerable indefinitely.
Implications for the Industry
While this exploit was performed on cameras from Trendnet, a minor presence in the professional surveillance industry, the implications it has for the industry as a whole are potentially huge. With so many different IP cameras available, chances are high that issues such as this exist in other manufactuers' lines. The exact hole will likely not be the same but the end result may be.
Cameras in corporate environments may be of less concern, as they are most often running on networks behind firewalls, internal to a facility. However, an attacker who gains access to the network could still use holes such as these to view feeds directly from cameras.
Author: Ethan Ace, Published on Feb 06, 2012
Other Update on Trendnet
Most Recent Industry Updates
Resolution: 4K vs 2160p vs 8.3MP on Apr 24, 2015
4K, 2160p and 8.3MP all basically refer to the same 'thing', just different dimensions of it. Wh...
Genetec Ends SMC, Replaces with Cloud Link on Apr 23, 2015
Genetec is ending the main platform it uses to integrate most access control, the Synergis Master...
Top Reasons Sales Proposals Are Rejected on Apr 22, 2015
A survey of 100 security sales professionals named 3 top reasons sales proposals are rejected: ...
Google / Nest Dealer Program Unveiled At ISC West on Apr 21, 2015
A year after Dropcam's puzzling appearance at ISC West 2014, now-parent company Google/Nest is ba...
Panasonic Free VMS Licenses Program on Apr 21, 2015
Looks like Tyco is a trendsetter. Weeks after Tyco starting giving free Exacq licenses, Digital ...
Small Chinese Manufacturers at ISC West on Apr 20, 2015
There were ~100 small Chinese, Taiwanese and Korean vendors with tiny booths at ISC West 2015. I...
Product / Tech Roundup ISC West 2015 on Apr 20, 2015
IPVM visited dozens of booths at ISC West. Inside is a roundup of many, but not all, of our visit...
Axis Goes Out With a Whimper (Q1 2015 Financials) on Apr 20, 2015
Their worst financial results, perhaps ever. In weeks, independent Axis likely be no more, becom...
Worst ISC West Showing on Apr 20, 2015
Here are the top 4 candidates: Arecont IDIS Milestone ONVIF Let's break down the cases f...
H.265 Cameras at ISC West on Apr 17, 2015
People have been waiting for H.265 for nearly 2 years now. At ISC West 2015, a lot of manufactur...