The Security of Video Surveillance Systems Questioned

The same useful features that enable security administrators to monitor surveillance cameras from any Web browser are also fraught with security vulnerabilities, according to a security services company. Gotham Digital Science recently posted a blog write-up that described how an unauthorized person could gain remote access to a closed circuit television video system. Doing so would allow that user to view video being captured with the camera, gain access to archived video footage, and, if supported by the particular model of camera, control the direction of the camera. Also, the company reported, many of the organizations running video surveillance may never know that an attacker has gained access to the system.

According to Justin Cacak, who penned the blog entry, the vulnerability can be tested with the use of a new tool added to the Metasploit Framework, a part of the Metasploit open source security project that allows testers to develop and execute exploit code against a specified target. So far the tool has been run against surveillance gear from MicroDigital, Hivision, and CTRing, as well as a "substantial number of other rebranded devices," the blog entry stated. Many of these systems are rebranded by other vendors and sold under different names in the United States

A common problem is that often the password that provides remote access to the device is never changed. "Typically, in over 70 percent of cases the device is still configured with the default vendor password which allows trivial access to real time video, the ability to control PTZ (pan-tilt-zoom) cameras, and access to any archived footage," Cacak wrote.

During its testing, in cases where the default password had been changed, the company used a network proxy to intercept and modify network data for non-proxy-aware applications, allowing researchers to determine valid and invalid users and authentication responses. That in turn allowed them to develop software that could validate user accounts, exclude non-valid ones, and use "brute force logins" to gain entry to the video systems.

"It is likely that other manufacturers and CCTV devices are similarly vulnerable," Cacak noted. Gotham recommended that organizations protect themselves against unauthorized breaches by changing default passwords, using strong passwords, filtering access to trusted hosts, and exposing the video system to the Internet only "if absolutely necessary."

The company also suggested that security professionals try out the new Metasploit module, available in the Metasploit Framework, to scan their networks for vulnerable systems.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • blue and green network lines

    HPE Intros Agentic AI Enhancements to Mist Platform

    HPE recently introduced new capabilities for its Juniper Mist platform that leverage agentic AI to enable more autonomous, intelligent, and proactive network operations.

  • Schoolchildren Work on Personal Computers

    Code.org Reinvents Hour of Code as Hour of AI

    Education nonprofit Code.org has partnered with CSforALL to launch the Hour of AI, a global initiative providing learning activities for AI education.

  • abstract generative AI technology

    Apple and Google Announce AI Deal to Bring Gemini Models to Siri

    Apple and Google have embarked on a multiyear partnership that will put Google's Gemini models and cloud technology at the core of the next generation of Apple Foundation Models, a move that could help Apple accelerate long-promised upgrades to Siri while handing Google a high-profile distribution win on the iPhone.

  • pattern featuring various scientific instruments and space icons, including beakers, atoms, and planets on a dark background

    Mark Rober's CrunchLabs Unveils Free Science Curriculum for Grades 6-8

    CrunchLabs, the maker of STEM activity kits for kids founded by NASA engineer turned YouTube science communicator Mark Rober, has launched Class CrunchLabs, a collection of free standards-aligned science curriculum resources that combine video storytelling with hands-on classroom challenges.