Author Topic: Helping me testing my Cams  (Read 2194 times)

0 Members and 4 Guests are viewing this topic.

Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
Re: Helping me testing my Cams
« Reply #15 on: April 22, 2014, 09:19:08 am »
Are the camera's connected wireless or over ethernet ?
If they are connected wireless you are fucked basically, there is nothing more stupid than this.

They can run to a router that's not connected to the internet, and then either run the router as the VPN or a dedicated machine for more flexability.
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Helping me testing my Cams
« Reply #16 on: April 22, 2014, 09:25:43 am »
They can run to a router that's not connected to the internet, and then either run the router as the VPN or a dedicated machine for more flexability.
Wireless also means a deauth attack, flatlining it right at the bottom of the chain.
IP camera's + wireless == fail
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: Helping me testing my Cams
« Reply #17 on: April 22, 2014, 10:37:29 am »
That's the gist of it.

Offline ande

  • Owner
  • Titan
  • *
  • Posts: 2664
  • Cookies: 256
    • View Profile
Re: Helping me testing my Cams
« Reply #18 on: April 22, 2014, 05:14:21 pm »
Are the camera's connected wireless or over ethernet ?
If they are connected wireless you are fucked basically, there is nothing more stupid than this.

I concur, optimally camera's should be wired to avoid jamming and hijacking. But a secure wifi setup should not have hijacking issues, only jamming.
« Last Edit: April 22, 2014, 05:15:36 pm by ande »
if($statement) { unless(!$statement) { // Very sure } }
https://evilzone.org/?hack=true

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Helping me testing my Cams
« Reply #19 on: April 22, 2014, 05:37:39 pm »
I concur, optimally camera's should be wired to avoid jamming and hijacking. But a secure wifi setup should not have hijacking issues, only jamming.
Exactly and jamming is completely fatal.
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
Re: Helping me testing my Cams
« Reply #20 on: April 22, 2014, 06:27:21 pm »
As I stated, cameras should never be online. CCTV is a tried and true method on a DVR with not network. Physical attack is going to be the only method



The problem is companies like Lorex, QSee, Comcast, ADT, wtc. Tell you, hey you can view your cameras wherever you are never mentioning the security risk of your privacy. So everyone wants to be able to view their cameras from their ipad. I had a pharmacy get their cameras hacked because they wanted to view them at home. I warned them that camera systems should be PCI complient and treated just like their internal network that handles customer and payment information, but they didn't want to listen. They didn't even want to get the hardware to run a hardware firewall because they didn't want to pay for the hardware. They changed their tune when they got hacked. The hackers replaced their webview URL with a driveby, it was great!
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline khofo

  • EZ's Swashbuckler
  • Knight
  • **
  • Posts: 350
  • Cookies: 25
  • My humor is so black, it could go cotton picking.
    • View Profile
Re: Helping me testing my Cams
« Reply #21 on: April 26, 2014, 03:36:14 am »
The cams are connected via a kind of coax.
I'll try to be clear "my house" okay so imagine this and help me hack.
A place where there is lots of computers all centralized via a hub and a dozen cameras all also centralized on the hub via CCTV. So basically i connected my cams to the hub and from there I have coax to a TV where I can view the cams and also via the wifi I can access my cams with an http login.
HOW TO HACK THIS 
Quote from: #Evilzone
<Spacecow18> priests are bad ppl
<Insanity> Holy crap
Of course God isnt dead. He's out there partying with the Easter Bunny, Santa Clause, Tooth Fairy, and the Man on the moon...
Some of my work: Introduction to Physical Security

Offline lucid

  • #Underground
  • Titan
  • **
  • Posts: 2683
  • Cookies: 243
  • psychonaut
    • View Profile
Re: Helping me testing my Cams
« Reply #22 on: April 26, 2014, 03:38:22 am »
HOW TO HACK THIS
Caps lock won't help you in this neighborhood..
"Hacking is at least as much about ideas as about computers and technology. We use our skills to open doors that should never have been shut. We open these doors not only for our own benefit but for the benefit of others, too." - Brian the Hacker

Quote
15:04  @Phage : I'm bored of Python

Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
Re: Helping me testing my Cams
« Reply #23 on: April 26, 2014, 03:55:32 am »
The cams are connected via a kind of coax.
I'll try to be clear "my house" okay so imagine this and help me hack.
A place where there is lots of computers all centralized via a hub and a dozen cameras all also centralized on the hub via CCTV. So basically i connected my cams to the hub and from there I have coax to a TV where I can view the cams and also via the wifi I can access my cams with an http login.
HOW TO HACK THIS 

Wow as stated a basic HTTP auth can be bruteforced via hydra or medusa, jtr, c&a, etc. Those "coax" things are called "BNC" and your system should not be online. A bruteforce or dictionary attack could lead to your system being compromised.
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline khofo

  • EZ's Swashbuckler
  • Knight
  • **
  • Posts: 350
  • Cookies: 25
  • My humor is so black, it could go cotton picking.
    • View Profile
Re: Helping me testing my Cams
« Reply #24 on: April 28, 2014, 02:07:41 am »
It's not online but I don't know how a hacker cam make his way to find the cam. I mean can the cams be easily found via Nmap or some scanning software?
Quote from: #Evilzone
<Spacecow18> priests are bad ppl
<Insanity> Holy crap
Of course God isnt dead. He's out there partying with the Easter Bunny, Santa Clause, Tooth Fairy, and the Man on the moon...
Some of my work: Introduction to Physical Security

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: Helping me testing my Cams
« Reply #25 on: April 28, 2014, 05:03:37 am »
Many cameras (webcam, security CCTVs etc.) are easily found by vulnerability scans and yes NMAP has modules for this as well, and a lot of cameras and CCTV setups are also easily exploitable services. This is why you should eliminate the possibility of an outside threat by never connecting to the internet, or at least having them secured on the internal network via firewall or iptables rules to only allow certain hosts (but NEVER by other internal services/hosts which could be vulnerable to other things and thus easily privilege escalated).

Offline khofo

  • EZ's Swashbuckler
  • Knight
  • **
  • Posts: 350
  • Cookies: 25
  • My humor is so black, it could go cotton picking.
    • View Profile
Re: Helping me testing my Cams
« Reply #26 on: April 29, 2014, 06:17:26 pm »
Ok thanks guys :)
Quote from: #Evilzone
<Spacecow18> priests are bad ppl
<Insanity> Holy crap
Of course God isnt dead. He's out there partying with the Easter Bunny, Santa Clause, Tooth Fairy, and the Man on the moon...
Some of my work: Introduction to Physical Security

Offline ThePH30N1X

  • Peasant
  • *
  • Posts: 50
  • Cookies: 18
  • Java Programmer
    • View Profile
Re: Helping me testing my Cams
« Reply #27 on: April 29, 2014, 08:25:08 pm »
The cams are connected via a kind of coax.
I'll try to be clear "my house" okay so imagine this and help me hack.
A place where there is lots of computers all centralized via a hub and a dozen cameras all also centralized on the hub via CCTV. So basically i connected my cams to the hub and from there I have coax to a TV where I can view the cams and also via the wifi I can access my cams with an http login.
HOW TO HACK THIS
Don't use a hub. Use a switch.
« Last Edit: April 29, 2014, 08:26:24 pm by ThePH30N1X »