Arecont and Bosch - Default Security Risk

Author: IPVM Team, Published on Dec 14, 2015

Default passwords are a major security risk, enabling hackers around the world to access and control devices like IP cameras (using Shodan, turning devices into bitcoin miners, etc.). Because of that, many manufacturers now force changing the default password and using strong passwords.

But two very well known manufacturers, Arecont and Bosch, continue to take the opposite, risky and irresponsible route.

******* ********* *** * ***** ******** ****, ******** ******* ****** the ***** ** ****** *** ******* ******* **** ** ******* (using******, ******* ******* *********** ******, ***.). ******* ** ****, **** ************* *** ***** ******** the ******* ******** *** ***** ****** *********.

*** *** **** **** ***** *************, ******* *** *****, ******** to take *** ********, ***** *** ************* *****.

[***************]

*******

**** ** *******'* ********:

"******* ****** *******do *** **** **** ************** *******. To enable authentication, access the web interface of the camera and click either the 'Administration' or 'System' tabs. Passwords can then be configured for the Admin and Viewer user names. Note that custom usernames cannot be created, only the 'Admin' and 'Viewer' user names are available for usage.

******** ****limit ** * ********** MAX with letters and numbers only. No ******* ******."

*** **** *** ****** ****** ** ******* ****** ****** * user ********** ******* **************, ******* ***** ** **** ** *** up * ****** ********.

*****

***** **** ***** **** ** ************** *** **** ***** ** as * ****** ** * ******* '*** ***** ********* ******'************:

"** ***'* ******* ******* ******** ** *** **. ** **** telnet ****.... ***** ***** ** ******, ** *******, ***** **** you *** **** *********** ** ** *********."

**'* ********* ********, **** ******** * ***** ******* ******* *** locks ** *** *****.

UPDATE: ***** ********

******** ** *.** ********, ***** ******* ***** ** *** * password, **** **** ***** ********* **** ********** ** *** ******'* web *********. **** **** ** ******** ** *** ** ******* and **** ** ********, ****** ******* ** *********, ***** ***** users ** *** ***.

******** ** ***** ***** ** *** ******** ***** ****, **** a ***** ******* ******** "********." **** **** *** ******** ** this ******* *** * ********** **** *** ******** ********* *** lowercase *******, *******, *** * ******* *********, *** *** ***** only ******** ** "******." ****** ********* ******* ** ********** *** a *** ** ***** *****.

*******

*** ******* **** ********** ** ** ************** ** **** **** users *** *********** **** ***** *** ** * ******** ** not ********. ** * **** **** ****,**** * ***** ** ***** **** **** ***** ********* ********* ****** ** "**** ** *** time."** ******* ****, * **** **% **** **** ************* ****** ** ******* to ***** ****** *********.

**** ** **************/******* ********* *** ** ****** **** ** ******** incidents ** *** **** *-* *****, **** ******* ************ ********* ******* *******, ** ***** * ******* ********'* **** **** ******** ******** and ***** ****. *** ** *** ******** ******* *****, ********* consumers, ** **** (*** ** ****** ******** - ************* ******** *** *,*** ****** ************ ******* - * *******).

***** ***** **** ******* *********, *** **** *********** **** *******, *******, *** ********** ***** ** ******** ******** ** *** **** ****, ******* and *****'* ******** ***** *************, ** ****.

****

***** ***** ******** *** *** **** *********** **** ******** ****, Arecont *** ***** ***** ***** ********* ** *********** *** *********** competitive ****.

Comments (7)

**** * ***** ************* ******** ** ******** ******** *******. ***** devices *** ** ****** ** * ***** ** ****** ********. They *** ******* **** *** ** *** **** ** **'* network *** **** **** ** ********** **** **** **** **** may ** *** ****** ******* **** ****** ** *** **** video, *** *** **** ***-******* ** *** ******* ******* **** attacks. * ***** ***** ****** **** *** **** **** "******" the ******** ** **** *** ***** ** ********** **** ******* a ******** ***** ** (**** * ******* ****) ** * good **** ******* *********** **************.

***** *** ******* - *** * *****. **'* *** **** hard ** ****** **** ***** ******* *** ******** ** ****** tight ******** ** **** *******. ***** ** **** *********, *** your ****. ** **** ***'* **** *** ****** ** *********** to ****** *** ******** *** ****** ** **** ** *** bench *** ****-**, **** *** *******'* ** ******* ** **** in *** ***** *****.

****'* *** ****? **** ***** **** **** - ***'* ***** that ******* ***** ********** *** ****. *** *** ****** *** hacked * *** ***** **** - ** **** *** **** wasn't ******* *** **** ** ** ******* ******. *** **** VARS ******* *** ** ***** ****** ** *** ******** ********?

* ******** ********* **** ****** ******** ********** ** ******* **** IP ***** ******* *** ****** *********** ********* ** ****** ***** devices *** ********* ** *** *** **** *********'* ***** ************* to ****** **** ***** ********* ********* **** *** **** ***** end ********* *******.

*'** **** **** ******, *** ******** ******** ******** *** *** to *** **** *** *******, *****. **** ******* ***** *** it, *** **** *** ***** ******* *** ** ** ********** - **** ** *** ***-***** *** ***** ******* *** **** in *** *********** *** ********** *********** ** **** ***-*********, **** and *********. ** **** ** **** ** **** *** ************ of * ****** ********* ************.

***** ******* **** ** ********* **** ** **** *** ******* is *** *******. *** ******* ** * ****** ******* **** needs **** *** *******. ***'* ***** ****** ** ** *** name, ******** *** **** *** ** ***** ****** ***** ******** by ********** *** ****** **** ***** ***** *** **** ************.

******** **** **'* ****, * ***...

****, * ******* **** ******* *** ***** ******* ********:****** * ******* **********. **** *** *** ********* **** *** to**** **** ********, *** ** ** ****** *************** ********.

** *** ****** *** ******, ******* *** ***** ********* *** viewing ** *** ***** ****:**** ** *********.

* ***'* ******* **** ***** ***** **** ****** ****! **** is *****.

* ** ******* ** **** ******* **** *** **** **** allowing *** ** ************** ** ******* ** * **** ****. Here ** *** ***:

**'* * ***** ******** ** ****, ******* **** ** *** know ***** *** ***** ******* ********* *** **** *** *** easily **** *** ** ********.

***** ** ** *****, *** *** * ****** ** ********* this ***** **** * **** **. *** "*** *****" **** does *** ****** ** **** ***** *** ****** **** *** well ****** ***** *******. * **** *** ***** ******* ** the ************ *** **** ******* **** **** ** **** *** make ** **, **** ** *********. ** (******* ****** **** have **** ** *** ******** ******** *** **** **** **** minutes) *** ***** ******* ** *********, ********** *** *********** ** IP ******** ****** *** ** **** **** ***** ** *** quite **** ****. ** ** *** ***** ** *********** ** you ***** **** *** ***** *******. *****, ** ***'* ***** it *****, ** **** ******* ** *********** *** *** ** is ********* ** *** ******. * ** **** ********* **** there *** ****** ** ****** ****** *********** *** ********* ****** passwords. * ** ******* ** ********* (******* * **** *** entire *******) **** *** ***** ** ****** *** **** *** HVAC ****** ****** *** ********** **** ** *** **** ** their ***** *** **** *** **** ** **** **** ****** overworked. **** ****** *** ****** ** **** *********** *** **** happens ** ***** ******* ****** ****? ** ** ***** *** within ***** **** ********** *** ** ***** ** ***** ***** to ****** **** ****** *** ***** *********** ** ********* ***** customer ***** ******* *** ************ ** ******** ******* ** ***** vendor. ****** **** **** ***** **** *** ** ***** ******* vendors ** ******, ********* ** *********, ***** **** ***** ***** responsibility ** ******** *** ******** ** *********** *** *** *********** so **** ***** ********* *** ***** ***** ** ***** ******, which ** ********** ***** ***, *** **** **** ***** *** their ************.

* ** ******* ***** **** *********** *** *********** ********* (**). IA ** ** ***************** ***** ********* ********** ** ** ** an ***************** ***** ********* ********* ** ********, **********, **** **********, fraud ***********, ******** *******, ********** *******, ******* ***********, ******** ***********, and ***********, ** ******** ** ******** *******. ***** ** * perception ****** ** **** **** ***-***** *********** *** ******* **** men *** *** **** ************** ********* ** ******** ***** ***-***** concepts, **** ** **** ** **** ************ **********, ***** ** fact, ** **** ** ***** ******. ** *** ** *** not **** ** *******, *** *********** ********** *** *** ****** security *** ** **** *** ***** *** *** **** *** network.

* ** **** * ****** ******* ** **** ********** **** any ****** **** **** *** **** ** *** ******* ***** certification ** ****** *** ******* ***** ********* ****. **** ** those *** *** ****** ****** *** ******* ******** ********* ****** meet * ******** **** ***/*** ***** ********* ****** *** ******** of *** ******** ** ********* *** ******* ******** ******** *************. Where ** *** *******?

*** ***** ********** **** ** *** **** ***** ******? ** be ****. * ********** **** **** ********** *********** **** ******* security, ************ ****, ******* *** ** *** ************** *** *******.**** ** ** ** *** ********* *******.*** ** ** ***** *** ****? ** **** *** *********** fault? **** ** **** **** *** ********? * **** **** this *** *****, *** * **** **** ** ** **** board; ****** *** ***** ***** *** **** ****** ********* ******* (and * **** ** *** **** ** **** ** ******** codes - *** ***************) ***** ** ** *** ** *****.

***** **. *****, *** * ********* ** **** ******* *** sir, *** **** "*******" ***** * *** ****** ** **. But **** ***** ** ****** **** *** ***** **** * broad *****.

**** - * **** ** *******. *'* ******* **** ** "broad *****" ** ** ********** ** ** ******** *********** **** VARS *** ***********. * **** *** **** *** **** **** the ***** ** ** ***************. *'* ******* **** *** **** had, ***** **** **** ********, * ****** **********. ** *** whether *** ******** ** ** ** ***** (*** *** *****) - *'* **** ** ******** ********.

* ******* **** ******* (*************) **** * ************** ** **** their ****/********** ** *** ***** *********, *** ** ***** ****** than ** ******* *** ***-********.

***-*-*** ** (*********** *********), **** *** ******* ******** ** *** Manufacturers. **** * *** ** *** ****** ******** ** ******* camera ********* ** *** ******* **********, *** ******** ****** **** up, "** **** ******* ** *********?" - ** ** *********, there *** **** *** ** *** ******** **** ******** **** the **** ********** **** ** (**** * ******** ***********). * only ***** * ***** ******* ** ** ********** **** *********** edge *******. **** ***** ***** *** ** **** ******* ** passwords *** ******** ********** **** ******* *********, ********** *** ********* of ******. **'* *** ** *********** ** ***** ****** ***** as *** ***** *****.

** *******, * ******* ******** ********** ***** ******** ** **, the ******** ********, ****** ** ** *** ********* ** **** process *** ****** ** ****** ** *********** ********. ***** **, in *** *******, **** ******* *********** ** *** ******* *****. We *** **** ** ***** (**) ************** *** **** ** be **** ******** ** **** **************.

***** *** *** **** ******** -

**

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

No Hack, Still Liable, Court Finds ADT on Jun 20, 2017
Recently, ADT has been in the news for a $16 million settlement for a cyber security vulnerability class action suit. One of the most important...
Hikvision: IPVM Is "Destined To Fail" on Jun 14, 2017
Hikvision has accused IPVM of 'cyberbullying' them, declaring IPVM 'destined to fail.' This is the 3rd anti-IPVM Hikvision post in 2 weeks,...
Morten Tor Nielsen Defends Hikvision on Jun 12, 2017
Morten Tor Nielsen, veteran software developer for Prescienta working for OnSSI, has posted "In Defence of Hikvision". As Nielsen explains...
How To Hack Your Company's Hikvision Recorder on May 29, 2017
Here's how easy it is to hack your company's Hikvision recorder: It does not matter how hard or secret the admin password is. Hikvision will...
Anti-Hack Access Card Shields Tested on May 26, 2017
Keeping your access control card information secure is becoming a big priority, especially since cheaper copiers can hack details easily. Multiple...
Hikvision Marketer Caught Spamming, Fails at Coverup, Fired on May 23, 2017
A Hikvision marketing employee was caught by IPCamTalk trying to surreptitiously disparage IPVM and IPCamTalk. This is an outgrowth of Hikvision's...
Axis Criticizes OEMs: "When You Buy An Axis Camera, An Axis Camera Is What You Get!" on May 19, 2017
When you buy a Honeywell camera, you likely get a Hikvision, Dahua or some other company's product. The same goes for easily 100 different...
Hackable 125kHz Access Control Migration Guide on May 19, 2017
Despite being one of the most popular credentials, 125 kHz credentials are easily copied and insecure as we showed in our test results, video...
Cisco: Hikvision Hired Us on May 16, 2017
The day after Hikvision's backdoor was confirmed by the US Department of Homeland Security, Hikvision issued a press release about a...
Hikvision Blaming Backdoor On Others, Cannot Hide From DHS on May 11, 2017
Numerous Hikvision employees are blaming their backdoor on others but Hikvision cannot hide from the US Department of Homeland Security. Blaming...

Most Recent Industry Reports

Avigilon VP Communications Exits on Jun 27, 2017
In 2016, Avigilon hired an executive, Darren Seed to: build and maintain strategic relationships with the investment community and to...
Hikvision H.265+ Tested on Jun 27, 2017
Hikvision, which in the past few years released H.264+ (see test results) has now released H.265+, that claims even greater bandwidth savings. We...
Milestone / Canon Launch Cloud Startup Arcus Global on Jun 27, 2017
Milestone has spun off a business, Arcus Global, funded by their parent company Canon. The new company aims to transform the VSaaS market with an...
Biometrics Pros and Cons For Electronic Access Control on Jun 26, 2017
Biometrics has been long sought as an alternative to the security risks of cards, pins and passwords. While biometrics has improved somewhat over...
Manufacturer Sales People Are Very Important - Statistics on Jun 26, 2017
IPVM's new integrator statistics show what sales people say regularly: Sales people are very important. From 150 integrator...
No Personal Opinions About Work on Jun 26, 2017
One rising trend is the tendency for people to disclaim their statements on work related topics as their own 'opinions' or 'personal...
Importance of Sales To Integrators - Statistics on Jun 23, 2017
One of the top trends in the industry over the past few years has been the rise of across-the-board sales (e.g.: Hikvision Sales, Dahua Sale,...
Deep Learning Surveillance Startups Deep Problem on Jun 23, 2017
The undeniably good news for the video surveillance market is that we are seeing the rise of more startups than in many years. The cause of this...
Avigilon Announces RADAR-Based Presence Detector on Jun 22, 2017
RADAR is gaining momentum within physical security. Two months after Axis announced a network radar detector, Avigilon has announced a RADAR-Based...
Covert Cloud Camera Service Launching (KJB) on Jun 22, 2017
Cloud IP cameras, for consumers, has become increasingly commonplace. However, covert cameras, lag there, with few options. Now, North America's...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact