The Security of Video Surveillance Systems Questioned

The same useful features that enable security administrators to monitor surveillance cameras from any Web browser are also fraught with security vulnerabilities, according to a security services company. Gotham Digital Science recently posted a blog write-up that described how an unauthorized person could gain remote access to a closed circuit television video system. Doing so would allow that user to view video being captured with the camera, gain access to archived video footage, and, if supported by the particular model of camera, control the direction of the camera. Also, the company reported, many of the organizations running video surveillance may never know that an attacker has gained access to the system.

According to Justin Cacak, who penned the blog entry, the vulnerability can be tested with the use of a new tool added to the Metasploit Framework, a part of the Metasploit open source security project that allows testers to develop and execute exploit code against a specified target. So far the tool has been run against surveillance gear from MicroDigital, Hivision, and CTRing, as well as a "substantial number of other rebranded devices," the blog entry stated. Many of these systems are rebranded by other vendors and sold under different names in the United States

A common problem is that often the password that provides remote access to the device is never changed. "Typically, in over 70 percent of cases the device is still configured with the default vendor password which allows trivial access to real time video, the ability to control PTZ (pan-tilt-zoom) cameras, and access to any archived footage," Cacak wrote.

During its testing, in cases where the default password had been changed, the company used a network proxy to intercept and modify network data for non-proxy-aware applications, allowing researchers to determine valid and invalid users and authentication responses. That in turn allowed them to develop software that could validate user accounts, exclude non-valid ones, and use "brute force logins" to gain entry to the video systems.

"It is likely that other manufacturers and CCTV devices are similarly vulnerable," Cacak noted. Gotham recommended that organizations protect themselves against unauthorized breaches by changing default passwords, using strong passwords, filtering access to trusted hosts, and exposing the video system to the Internet only "if absolutely necessary."

The company also suggested that security professionals try out the new Metasploit module, available in the Metasploit Framework, to scan their networks for vulnerable systems.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • abstract smartphone translucent screen displaying AI interface

    Apple Unveils Redesigned Siri AI

    At its recent Worldwide Developers Conference, Apple announced Siri AI, a redesigned version of its voice assistant that Apple describes in its own announcement as "a profoundly more capable and personal assistant." The update is intended to make Siri more conversational, more context-aware, and more useful across iPhone, iPad, Mac, Apple Watch, and Vision Pro.

  • Man offers stem word sign on virtual screen

    Immersive Workforce Development Initiative Connects Students with Real-World STEM Careers

    The Center of Science and Industry, a science museum and research center in Central Ohio, has launched The HIVE, a workforce development initiative designed to help students across the country explore real-world career pathways in aerospace, advanced manufacturing, engineering, and emerging technologies.

  • abstract glowing circuit patterns

    Microsoft Scales Back Copilot Integrations in Windows 11

    Microsoft is dialing back its Copilot push in Windows 11, promising a sweeping quality overhaul that puts performance and reliability ahead of AI feature expansion .

  • Abstract futuristic background with blurry glowing wave and neon lines

    Microsoft Unveils 'Cowork' Feature for Copilot, AI Updates

    Microsoft recently announced a trio of AI updates, spanning Microsoft 365 Copilot, Security Copilot and Microsoft Foundry.