Slashdot Mirror


Unsecured IP Cameras Accessible To Everyone

Orome1 writes "In the last couple of decades, we have become so accustomed to the idea that the public portion of our everyday life is watched and recorded — in stores, on the street, in institutions — that we often don't even notice the cameras anymore. Analog surveillance systems were difficult to hack into by people who lacked the adequate knowledge, but IP cameras — having their own IPs — can be quite easily physically located and their stream watched in real-time by anyone who has a modicum of computer knowledge and knows what to search for on Google."

16 of 146 comments (clear)

  1. Nice one by Peach+Rings · · Score: 5, Informative

    Good find 2002.

    1. Re:Nice one by Solid+StaTe_1 · · Score: 5, Informative

      from 2005... but whatever. it's old news

      http://it.slashdot.org/article.pl?sid=05/01/09/1411242

      --
      Build a man a fire and you warm him for a day. Set a man on fire and you warm him for the rest of his life.
    2. Re:Nice one by PatPending · · Score: 5, Informative
      --
      What one fool can do, another can. (Ancient Simian Proverb)
    3. Re:Nice one by goodmanj · · Score: 5, Informative

      Here's the deal though: if it's been six years and nobody's bothered to close these security holes --- and the searches still work, I just tried --- then *THAT* is news.

      Finding a security exploit is not big news. Leaving a security hole unfixed for six years *is* big news, especially if it's done by companies for whom "security" is literally their middle name.

    4. Re:Nice one by Local+ID10T · · Score: 3, Insightful

      Here's the deal though: if it's been six years and nobody's bothered to close these security holes --- and the searches still work, I just tried --- then *THAT* is news.

      Finding a security exploit is not big news. Leaving a security hole unfixed for six years *is* big news, especially if it's done by companies for whom "security" is literally their middle name.

      Who says its a security hole?

      Do I care if the entire world can look thru my camera? Does it in any way effect the operation of the camera or of the security system attached to it? No.

      Now if the camera is pointed at something I don't want the rest of the world to see... maybe I should have sprung for a system that at least requires a password...

      --
      "You want to know how to help your kids? Leave them the fuck alone." -George Carlin
    5. Re:Nice one by cusco · · Score: 5, Interesting

      Does it in any way effect the operation of the camera or of the security system attached to it?

      Actually it does. Most cameras have a limit of how many simultaneous connections are allowed. Exceed that limit and the owner might have to reboot the camera in order to access their own video feed. Bad news if that camera's looking at the door of your emergency room or your unmanned warehouse half a continent away.

      --
      "Think about how stupid the average person is. Now, realise that half of them are dumber than that." - George Carlin
    6. Re:Nice one by Peach+Rings · · Score: 3, Funny

      Me too, mine was even aimable with a little javascript control. Got a really good close up of the second tower.

  2. Also on Ars Technica by Max+Romantschuk · · Score: 4, Informative
    --
    .: Max Romantschuk :: http://max.romantschuk.fi/
  3. This is so old. by Securityemo · · Score: 4, Informative

    And there's lots of other things you can find. Here are some lists: http://www.hackersforcharity.org/ghdb/

    --
    Emotions! In your brain!
  4. tons of cams are available. by Zurk · · Score: 5, Informative

    heres a long list copied from various parts of the web for searches you can try :

    allintitle: "Network Camera NetworkCamera" Network cameras
    intitle:Axis 2400 video server Mostly security cameras, car parks, colleges, clubs, bars, etc.
    intitle:axis intitle:"video server" Mostly security cameras, car parks, colleges, bars, ski slopes etc.
    intitle:"EvoCam" inurl:"webcam.html" Mostly European security cameras
    intitle:"Live NetSnap Cam-Server feed" Network cameras, private and non private web cameras
    intitle:"Live View / - AXIS" Mostly security cameras, car parks, colleges etc.
    intitle:"LiveView / - AXIS" | inurl:view/view.shtml Mostly security cameras, car parks, colleges etc.
    intitle:liveapplet Mostly security cameras, car parks, colleges, clubs, bars etc.
    intitle:snc-cs3 inurl:home/ Mostly security cameras, swimming pools and more etc.
    intitle:"snc-rz30 home" Mostly security cameras, shops, car parks
    intitle:snc-z20 inurl:home/ Mostly security cameras, swimming pools and more etc.
    intitle:"WJ-NT104 Main" Mostly security cameras, shops, car parks
    inurl:LvAppl intitle:liveapplet Mostly security cameras, car parks, colleges etc.
    inurl:indexFrame.shtml "Axis Video Server" Mostly security cameras, car parks, colleges etc.
    inurl:lvappl A huge list of webcams around the world, mostly security cameras, car parks, colleges etc.
    inurl:axis-cgi/jpg Mostly security cameras
    inurl:indexFrame.shtml Axis Mostly security cameras, car parks, colleges etc.
    inurl:"MultiCameraFrame?Mode=Motion" Mostly security cameras, pet shops, colleges etc.
    inurl:/view.shtml Mostly security cameras, car parks, colleges etc.
    inurl:/view/index.shtml Mostly security cameras, airports, car parks, back gardens, traffic cams etc.
    inurl:viewerframe?mode= Network cameras, mostly private webcams etc.
    inurl:"viewerframe?mode=motion" Network cameras
    inurl:ViewerFrame?Mode=Refresh Mostly security cameras, parks, bird tables etc.

    Other searches:
    control/userimage.html liveapplet inurl:indexframe.shtml inurl:"view/index.shtml" inurl:"view/indexFrame.shtml" inurl:view/view.shtml
    inurl:/view/view.shtml?videos= inurl:ViewerFrame?Mode= inurl:ViewerFrame?Mode=Motion inurl:ViewerFrame?Mode=Refresh site:.viewnetcam.com -www.viewnetcam.com /view/index.shtml

    In Title:
    intitle:"live view" intitle:axis
    intitle:"EvoCam" inurl:"webcam.html"
    intitle:"i-Catcher Console - Web Monitor"
    intitle:"Live NetSnap Cam-Server feed"
    allintitle:liveapplet
    intitle:liveapplet
    intitle:"netcam live image"
    intitle:"snc-rz30 home"
    intitle:"WJ-NT104 Main"

    In URL:
    inurl:axis-cgi/jpg
    inurl:indexFrame.shtml Axis
    inurl:indexFrame.shtml "Axis Video Server"
    inurl:lvappl live webcams
    inurl:LvAppl intitle:liveapplet
    inurl:"MultiCameraFrame?Mode=Motion"
    inurl:/view:shtml
    inurl:/view/index.shtml
    inurl:view/indexframe.shtml
    inurl:view/view.shtml
    viewerframe?mode=
    inurl:"viewerframe?mode=motion"
    inurl:ViewerFrame?Mode=Refresh

    Two searches in one order:
    intitle:"live view" intitle:axis (two searches in one order)
    intitle:axis intitle:"video server"
    intitle:liveapplet inurl:LvAppl
    intitle:"Live View / - AXIS" | inurl:view/view.shtml
    intitle:start inurl:cgistart

    Combination:
    camera linksys inurl:main.cgi
    Display Cameras intitle:"Express6 Live Image"
    intitle:"active webcam page"
    intitle:"EvoCam" inurl:"webcam.html"
    inurl:LvAppl intitle:liveapplet
    intitle:"Live View / - AXIS"
    intitle:liveapplet inurl:LvAppl
    intitle:"my webcamXP server!" inurl:":8080"
    intitle:"Network Camera" inurl:ViewerFrame
    intitle:snc-z20 inurl:home/
    intitle:snc-rz30 inurl:home/
    intitle:"toshiba network camera - User Login"
    intitle:"Live View / - AXIS" | inurl:view/view.shtml
    tilt intitle:"Live View / - AXIS" | inurl:view/view.shtml
    intitle:"WJ-NT104 Main Page"

    Sometimes your order gives hundreds of URLs. You can restrict your search by adding a country, a specialized URL or another mes

    1. Re:tons of cams are available. by cusco · · Score: 4, Interesting

      Just an FYI, as someone who does this for a living, most of our competition leaves their cameras at the factory default usernames and passwords. Try root, admin or Admin as usernames, and root, admin, pass, 1234, 12345 or just plain blank as passwords. Some of the manufacturers are getting a clue and requiring a password be created on first login in the newer firmware, but most of these bozos are just putting in the old factory default again.

      Glad I work for one of the few security companies that doesn't have its head up its collective ass. I'd really hate working for one of the Big Three.

      --
      "Think about how stupid the average person is. Now, realise that half of them are dumber than that." - George Carlin
    2. Re:tons of cams are available. by hedwards · · Score: 3, Interesting

      Because then they can figure out ways of obscuring themselves more effectively. Which is the problem, additionally you frequently run into dome cameras where you're not sure where exactly they're pointed. With practice you can see very quickly, but it's a bit of a risk.

  5. Cameras Everywhere by NReitzel · · Score: 4, Interesting

    At the University where I work, there are cameras in all of the lobby areas and in many of the labs. They are publicly accessible, for the most part - non-port 22 but otherwise unsecured. However, because the University wants to be able to use the pictures in legal proceedings, all the camera areas are clearly marked with "Video Surveillance" stickers.

    I can't speak for anyone else, but it's not that hard to just not do funky things in these areas.

    Yes, it intrudes on my sphere, but I have no expectation of privacy at work, or on the street. If I want to do something private, I go somewhere private. It's not that much of a burden, at least to me.

    --

    Don't take life too seriously; it isn't permanent.

  6. Re:I've hacked into... by fridaynightsmoke · · Score: 3, Funny

    so you like to hack into gay bar to watch penises, as they says : each to is own !

    What a dick. If they find out, he's screwed.

    --
    This is a substitute for a clever sig that fits within the maximum number of characters.
  7. Aggregator by symes · · Score: 5, Informative

    Someone has a whole list of open webcams: http://www.opentopia.com/hiddencam.php

  8. My local red light cameras by www.sorehands.com · · Score: 4, Funny

    Now all I need is to have the IP address of my local red light and speed cameras.

    Of course, I would never have any fun and do something like, changing the time, moving the camera, replacing drivers' faces with pictures of say, maybe Osama Bin Laden, Benjamin Franklin, or the president.