Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Security Analysis of a Cheap Chinese IoT WiFi Camera (eriknl.github.io)
12 points by milankragujevic on Nov 9, 2019 | hide | past | favorite | 5 comments


I had that camera, and got root access in 30 seconds (user: root, password: [blank] in my case, it was DOG-1WNEW)

https://i.imgur.com/jZYxETN.png

I returned it to the store for a refund. No way such a thing is going anywhere near my network or my home.

Also, it seems the manufacturer Cylan has not learnt anything, as new models also have gaping holes: https://github.com/offensive-security/exploitdb/blob/8cbfa5d...

Shenzhen Cylan Technology Co.,Ltd - https://www.crunchbase.com/organization/shenzhen-cylan-techn...

The offending camera: http://www.jfgou.com/camera/camera-wifi2/

A teardown: http://sirlagz.net/2017/11/20/reject-shop-special-home-secur...


I'd be interested to know if these type of cheap cameras are safe to use after fixing / replacing the default firmware or does the hardware itself have some kind of backdoors to allow easy exploits even if the firmware is updated.


Yup. There’s even a community helping.

Xiaomi DaFang Hacks / XiaoFang 1S / Wyzecam V2 / Wyzecam Pan / Other T20 Devices

https://github.com/EliasKotlyar/Xiaomi-Dafang-Hacks


It's common practise to put these devices on their own VLAN that is completely isolated from network access, except for the controller device (NVR, etc).

I'd consider these items completely and utterly unfit for purpose, even these from branded manufacturers.


Well, AFAIK, the so-called Cloud cameras that don't require (nor support) an NVR must be allowed to call-home, whether for setup or regular functioning. They don't do anything inside the LAN. That way they can be easily watched from anywhere, as they don't require open ports on the router, and can work even behind CGNAT. The obvious downside is the video is sent to the company's servers, and given how cheap the device is and how expensive storing and streaming video is, you can bet they're monetizing it somehow...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: