Subscriber Discussion

Camera (Device) Info On Shodan

U
Undisclosed #1
May 24, 2016

Dear IPVM friends,

Any checked your camera exposed on IoT search engine Shodan. Two of my cameras ( one IPcam one NVR) found shodan and give details about the device, IP geolocation, server location etc.

On the device details : For NVR (Hikvision brand)

HTTP/1.1 200 OK
Date: Sat, 21 May 2016 06:33:45 GMT
Server: DNVRS-Webs 
ETag: "0-949-1e0"
content-length: 480
Content-Type: text/html
Connection: keep-alive
Keep-Alive: timeout=60, max=99
Last-Modified: Tue, 05 May 2015 03:32:54 GMT

For standalone IP Camera

HTTP/1.1 401 Unauthorized
Date: Sun, 15 May 2016 10:58:57 GMT
Last-Modified: Sun, 15 May 2016 10:58:57 GMT
Connection: close
Cache-Control: no-cache,no-store
WWW-Authenticate: Basic realm="index.html"
content-length: 436

1.What is server DNVRS means?

2. For camera basic realm should be similar to "IPcam". Not sure why it shown as index.html How to change to this info? If I change this info, I can advertise my device as IPcam or something else...though can not fool the Shodan completely but try to change the device type.

Any thoughts welcome.
Thanks

Avatar
Jon Dillabaugh
May 25, 2016
Pro Focus LLC

Index.html is the root page of the built in web server. That likely can't be changed.

U
Undisclosed #1
May 26, 2016

Thanks Jon. My guess is correct.

Cheers!

U
Undisclosed #2
May 26, 2019
(1)
MD
Matthew Del Salto
May 26, 2019
Hudson Security

Close those ports!

(1)
Avatar
Anton Miller
May 29, 2019
Shaked Projects

Just don't use the default ports.

(2)
MD
Matthew Del Salto
May 29, 2019
Hudson Security

That is not true. Shodan can index by service signature. 

(1)
(2)
Avatar
Sean Patton
May 29, 2019

Changing the default ports is only likely to frustrate technicians or users who are legitimately accessing the cameras/NVRs. A quick search for Hikvision using 8080 (a common non-default port 80 replacement) returns 193 devices in the US:

We have a reference Directory of Video Surveillance Cybersecurity Vulnerabilities and Exploits which lists many vulnerabilities that include hardcoded admin accounts and passwords that would still work even with non-default ports. 

Locating cameras behind a firewall/requiring a VPN to connect (IPVM VPNs for Surveillance) is a much better way to provide remote access without port forwarding/exposing devices to the Internet.

(1)
BP
Bas Poiesz
May 29, 2019

Choose an end-to-end VPN. Works a lot better than closing or changing ports.

(1)
New discussion

Ask questions and get answers to your physical security questions from IPVM team members and fellow subscribers.

Newest discussions