Quote Originally Posted by automation View Post
You're thinking incredibly naively. The days of hackerrs just trying to cause mischief for INDIVIDUALS (e.g., by erasing your hard drive or stealing your address book) are decades past.

No one really gives a damn what goes on in your house -- except google, of course (but for different reasons; they're trying to HELP you! <rolls eyes>)!

But, your camera(s) -- and other bits of "smart technology" -- are ripe for lending beachheads to malware that can interact with other devices IN YOUR HOUSE (like your PC's). Would you let that chinese hacker sit in your bedroom with full access to your network, indefinitely, patiently and single-mindedly looking for exploits in the other deviecs that you have attached to it?? Why would you let him sit in your CAMERA??

Also, they can be used to create botnets that then are deployed to attack specific targets (how'd you like to discover that YOUR camera played a role in attacking your BANK?) A worthwhile read: https://www.wired.com/story/reaper-i...lion-networks/

A bit of time researching how attacks and exploits have been deployed IN THE PAST might cause you to invest in some tinfoil of your own!

Recall, there's no "antivirus" software for your camera(s), thermostat, etc. And, are you sure their firmware is up-to-date? Even if so, google "zero day exploit" and wonder why YOU will be the lucky soul who is NOT hacked.

[Hint: I design this sort of stuff for a living. The number of exploits that you don't hear about -- cuz your more interested in football/basketball scores -- is staggering. And, where there's evidence of ONE flaw in a design, there are likely many MORE!]

From https://www.vdoo.com/blog/working-wi...olink-cameras/:



From https://github.com/threat9/routersploit/issues/242:

List of vulnerabilities & exploits

  • Intellinet NFC-30IR Camera - Multiple Vulnerabilities
    Netwave IP Camera - Password Disclosure
    Komfy Switch with Camera DKZ-201S/W - WiFi Password Disclosure
  • AVTECH IP Camera, NVR, and DVR Devices - Multiple Vulnerabilities
    VideoIQ Camera - Local File Disclosure
    Vanderbilt IP-Camera CCPW3025-IR / CVMW3025-IR - Local File Disclosure
  • JVC IP-Camera VN-T216VPRU - Local File Disclosure
    Honeywell IP-Camera HICC-1100PT - Local File Disclosure
  • MESSOA IP-Camera NIC990 - Authentication Bypass / Configuration Download
    SIEMENS IP Cameras (Multiple Models) - Credential Disclosure / Configuration Download
  • Vanderbilt IP-Camera CCPW3025-IR / CVMW3025-IR - Credentials Disclosure
    MESSOA IP Cameras (Multiple Models) - Unauthenticated Password Change
  • JVC IP-Camera VN-T216VPRU - Credentials Disclosure
    TOSHIBA IP-Camera IK-WP41A - Authentication Bypass / Configuration Download
  • Honeywell IP-Camera HICC-1100PT - Credentials Disclosure
    SIEMENS IP Camera CCMW1025 x.2.2.1798 - Remote Admin Credentials Change
  • SIEMENS IP-Camera CVMS2025-IR / CCMS2025 - Credentials Disclosure
    Samsung Smart Home Camera SNH-P-6410 - Command Injection
  • Multiple JVC HDRs and Net Cameras - Multiple Vulnerabilities
    Merit Lilin IP Cameras - Multiple Vulnerabilities
  • TH692 Outdoor P2P HD Waterproof IP Camera - Hard-Coded Credentials
    Brickcom Corporation Network Cameras - Multiple Vulnerabilities
  • Axis Network Cameras - Multiple Vulnerabilities
    PLANET Technology IP Surveillance Cameras - Multiple Vulnerabilities
  • ADH-Web Server IP-Cameras - Multiple Vulnerabilities
    TP-Link NC200/NC220 Cloud Camera 300Mbps Wi-Fi - Hard-Coded Credentials
  • Keeper IP Camera 3.2.2.10 - Authentication Bypass
    Security IP Camera Star Vision DVR - Authentication Bypass
  • IPUX CS7522/CS2330/CS2030 IP Camera - 'UltraHVCamX.ocx' ActiveX Stack Buffer Overflow
    IPUX Cube Type CS303C IP Camera - 'UltraMJCamX.ocx' ActiveX Stack Buffer Overflow
  • IPUX CL5452/CL5132 IP Camera - 'UltraSVCamX.ocx' ActiveX Stack Buffer Overflow
    TRENDnet SecurView Wireless Network Camera TV-IP422WN - 'UltraCamX.ocx' Stack Buffer Overflow
  • Foscam IP Camera - Predictable Credentials Security Bypass
    Vivotek IP Cameras - RTSP Authentication Bypass
  • Loftek Nexus 543 IP Cameras - Multiple Vulnerabilities
    Hikvision IP Cameras 4.1.0 b130111 - Multiple Vulnerabilities
  • TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
    FOSCAM IP-Cameras - Improper Access Restrictions
  • Airlive IP Cameras - Multiple Vulnerabilities
    MayGion IP Cameras Firmware 09.27 - Multiple Vulnerabilities
  • Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
    Security IP Camera Star Vision DVR - Authentication Bypass
  • IPUX Cube Type CS303C IP Camera - 'UltraMJCamX.ocx' ActiveX Stack Buffer Overflow
    IPUX CL5452/CL5132 IP Camera - 'UltraSVCamX.ocx' ActiveX Stack Buffer Overflow
  • IPUX CS7522/CS2330/CS2030 IP Camera - 'UltraHVCamX.ocx' ActiveX Stack Buffer Overflow
    TRENDnet SecurView Wireless Network Camera TV-IP422WN - 'UltraCamX.ocx' Stack Buffer Overflow
  • Foscam IP Camera - Predictable Credentials Security Bypass
    Vivotek IP Cameras - RTSP Authentication Bypass
  • Loftek Nexus 543 IP Cameras - Multiple Vulnerabilities
    Hikvision IP Cameras 4.1.0 b130111 - Multiple Vulnerabilities
  • TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
    FOSCAM IP-Cameras - Improper Access Restrictions
  • Airlive IP Cameras - Multiple Vulnerabilities
    TP-Link IP Cameras Firmware 1.6.18P12 - Multiple Vulnerabilities
  • D-Link IP Cameras - Multiple Vulnerabilities
    StarVedia IPCamera IC502w IC502w+ v020313 - 'Username'/Password Disclosure
  • D-Link DCS Cameras - Multiple Vulnerabilities
    Vivotek Cameras - Sensitive Information Disclosure
  • TRENDnet SecurView Internet Camera - UltraMJCam OpenFileDlg Buffer Overflow (Metasploit)
    TRENDnet SecurView TV-IP121WN Wireless Internet Camera - UltraMJCam ActiveX Control OpenFileDlg WideCharToMultiByte Remote Stack Buffer Overflow
  • Cisco Linksys WVC200 Wireless-G PTZ Internet Video Camera PlayerPT - ActiveX Control PlayerPT.ocx sprintf Buffer Overflow
    Multiple Trendnet Camera Products - Remote Security Bypass
  • RXS-3211 IP Camera - UDP Packet Password Information Disclosure
    Camtron CMNC-200 IP Camera - Authentication Bypass
  • Camtron CMNC-200 IP Camera - Undocumented Default Accounts
    Camtron CMNC-200 IP Camera - ActiveX Buffer Overflow
  • Camtron CMNC-200 IP Camera - Directory Traversal
    Intellinet IP Camera MNC-L10 - Authentication Bypass
  • ARD-9808 DVR Card Security Camera - Arbitrary Config Disclosure
    Camera Life 2.6.2b4 - Arbitrary File Upload
  • Camera Life 2.6.2 - 'id' Parameter SQL Injection
    AXIS Camera Control (AxisCamControl.ocx 1.0.2.15) - Buffer Overflow
  • Sony Network Camera SNC-P5 1.0 - ActiveX viewer Heap Overflow (PoC)
    D-Link DCS-900 Camera - Remote IP Address Changer Exploit
  • Axis Network Camera 2.x And Video Server 1-3 - virtualinput.cgi Arbitrary Command Execution
    Axis Network Camera 2.x And Video Server 1-3 - Directory Traversal
  • Axis Network Camera 2.x And Video Server 1-3 - HTTP Authentication Bypass
    Linksys Web Camera Software 2.10 - Next_file Parameter File Disclosure
  • Axis Network Camera 2.x - HTTP Authentication Bypass


If you're more technically inclined https://jumpespjump.blogspot.com/201...and-found.html:

That kind of thinking really holds people back.

Anything tied to the internet can be hacked just change the default passwords and move on.

We have cameras, security systems, phones, tablets, computers, nest, refrigerators, the list goes on and on and our life is fine and very accessible now with technology!