The Security of Video Surveillance Systems Questioned

The same useful features that enable security administrators to monitor surveillance cameras from any Web browser are also fraught with security vulnerabilities, according to a security services company. Gotham Digital Science recently posted a blog write-up that described how an unauthorized person could gain remote access to a closed circuit television video system. Doing so would allow that user to view video being captured with the camera, gain access to archived video footage, and, if supported by the particular model of camera, control the direction of the camera. Also, the company reported, many of the organizations running video surveillance may never know that an attacker has gained access to the system.

According to Justin Cacak, who penned the blog entry, the vulnerability can be tested with the use of a new tool added to the Metasploit Framework, a part of the Metasploit open source security project that allows testers to develop and execute exploit code against a specified target. So far the tool has been run against surveillance gear from MicroDigital, Hivision, and CTRing, as well as a "substantial number of other rebranded devices," the blog entry stated. Many of these systems are rebranded by other vendors and sold under different names in the United States

A common problem is that often the password that provides remote access to the device is never changed. "Typically, in over 70 percent of cases the device is still configured with the default vendor password which allows trivial access to real time video, the ability to control PTZ (pan-tilt-zoom) cameras, and access to any archived footage," Cacak wrote.

During its testing, in cases where the default password had been changed, the company used a network proxy to intercept and modify network data for non-proxy-aware applications, allowing researchers to determine valid and invalid users and authentication responses. That in turn allowed them to develop software that could validate user accounts, exclude non-valid ones, and use "brute force logins" to gain entry to the video systems.

"It is likely that other manufacturers and CCTV devices are similarly vulnerable," Cacak noted. Gotham recommended that organizations protect themselves against unauthorized breaches by changing default passwords, using strong passwords, filtering access to trusted hosts, and exposing the video system to the Internet only "if absolutely necessary."

The company also suggested that security professionals try out the new Metasploit module, available in the Metasploit Framework, to scan their networks for vulnerable systems.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • ClassVR headsets

    Avantis Education Launches New Headsets for ClassVR Solution

    Avantis Education recently introduced two new headsets for its flagship educational VR/AR solution, ClassVR. According to a news release, the Xcelerate and Xplorer headsets expand the company’s offerings into higher education while continuing to meet the evolving needs of K–12 users.

  • Abstract AI circuit board pattern

    Nonprofit LawZero to Work Toward Safer, Truthful AI

    Turing Award-winning AI researcher Yoshua Bengio has launched LawZero, a nonprofit aimed at developing AI systems that prioritize safety and truthfulness over autonomy.

  • blue AI cloud connected to circuit lines, a server stack, and a shield with a padlock icon

    Report: AI Security Controls Lag Behind Adoption of AI Cloud Services

    According to a recent report from cybersecurity firm Wiz, nearly nine out of 10 organizations are already using AI services in the cloud — but fewer than one in seven have implemented AI-specific security controls.

  • magnifying glass highlighting a human profile silhouette, set over a collage of framed icons including landscapes, charts, and education symbols

    New AI Detector Identifies AI-Generated Multimedia Content

    Amazon Web Services and DeepBrain AI have launched AI Detector, an enterprise-grade solution designed to identify and manage AI-generated content across multiple media types. The collaboration targets organizations in government, finance, media, law, and education sectors that need to validate content authenticity at scale.