Big Security Hole in Surveillance Cameras

Author: Ethan Ace, Published on Feb 06, 2012

The mainstream press has been abuzz with an IP camera vulnerability that allows people from anywhere on the Internet to directly and easily access TRENDnet cameras without any authentication. In this note, we explain how it was done, why we believe Trendnet engineers had to know about it and what implications this has for the rest of the surveillance industry.

Firmware Exploit

While it took real skill for an outsider to find the exploit, usig the exploit itself is very simple. Basically, a standard URL exists that if entered provides direct access to the MJPEG video stream without any restrictions.

The hacker deconstructed Trendnet's firmware, manually inspecting the enclosed files. This inspection revealed multiple CGI scripts used for requesting live video. Trendnet had left a folder called 'anony' (as in anonymous access). In that folder is a file named mjpg.cgi. A request to that file returns a live video stream (e.g., http://192.168.1.17/anony/mjpg.cgi). Here's what the basic queries look like on a Linux distrobution:

The hacker then detailed a method by which users were able to search for Trendnet cameras available on the internet. Taking this information, active internet messageboards, such as Reddit and 4chan, set about finding as many open camera feeds as possible, sharing lists of IP addresses of cameras as they were found. This led to likely hundreds of readers of these sites viewing feeds and capturing stills from hundreds of IP cameras, many in private residences, along with businesses.

Some of these captures are extremely disconcerting, looking directly into users' homes:

We suspect that Trendnet engineers knew about this security flaw, simply because it is an obvious, "in plain sight" feature for an engineer, likely used as a backdoor or a shortcut by their internal team to do testing.

Trendnet's Response

Trendnet has since released an apology and firmware update for affected cameras. However, notice of this firmware update was sent only to those users which registered their Trendnet camera, which is typically a small percentage. Additionally, given Trendnet's position in the industry, as a low-cost manufacturer often used for residential and small business systems by less tech-savvy users, many users will be unlikely to ever hear about this issue and subsequent fix, leaving them vulnerable indefinitely.

Implications for the Industry

While this exploit was performed on cameras from Trendnet, a minor presence in the professional surveillance industry, the implications it has for the industry as a whole are potentially huge. With so many different IP cameras available, chances are high that issues such as this exist in other manufactuers' lines. The exact hole will likely not be the same but the end result may be.

Cameras in corporate environments may be of less concern, as they are most often running on networks behind firewalls, internal to a facility. However, an attacker who gains access to the network could still use holes such as these to view feeds directly from cameras.

Comments : PRO Members only. Login. or Join.

Other Report on Trendnet

Most Recent Industry Reports

Arecont and SIA Failing Cybersecurity Efforts on Jul 22, 2016
Do as we say, not as we do. The effective motto of the Security Industry Association and their cyber board member Arecont Vision. Today, the two...
Video Surveillance Hard Drive Failure Statistics 2016 on Jul 22, 2016
Hard drive failures are decreasing and lifespans are getting longer, according to new IPVM statistics. Failing hard drives have historically been...
Intrusion Sensor Selection guide on Jul 21, 2016
When designing intrusion systems, a number of sensor types can be selected, including: Magnetic Acceleromteter Glass Break PE/PIR/Laser...
What The Run Over Child Means For The Future of Security Robots on Jul 21, 2016
Robot security guards recently received unprecedented news coverage. Unfortunately, not good: CNN: 300-pound mall robot runs over toddler WSJ:...
Axis Camera Hack Tested on Jul 21, 2016
Full disclosure by the researcher of the Axis critical security vulnerability has been made. But what does this mean? Does it even work? What can...
The Chinese / Ingram Micro Deal Has A Significance Chance of Being Killed on Jul 20, 2016
A Chinese airline / shipping company buying a Western IT distributor? Sounds like a bad deal. Nonetheless, earlier this year, Ingram negotiated a...
Logipix 20MP, 140MP and 200MP Cameras Examined on Jul 20, 2016
Looking for an Avigilon alternative? Logipix, based in Hungary, has created their own super high resolution end-to-end solution, featuring 20MP -...
Major US City Satisfied With 20% Continuously Broken Cameras on Jul 20, 2016
Is 20% continuously broken cameras reasonable? Yes, it is, according to one major US city. In this note, we examine the city, the challenges...
Ring Buys Installs For New Customers on Jul 19, 2016
Q: "When is DIY not really DIY?" A: "When Ring offers to buy professional install for you." Yes, it is that simple.  Ring is offering to pay an...
How To Sell Your Security Integrator on Jul 19, 2016
Consider this a tutorial in how to sell a security integrator. If you own an integrator, want to buy one or even are thinking of starting your own...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact