follow

help me to improve quality

donate

Pages

Thursday 8 June 2017

Hard-coded Passwords Make Hacking Foscam ‘IP Cameras’ Much Easier






  • Insecure default credentials
  • Hard-coded credentials
  • Hidden and undocumented Telnet functionality
  • Remote Command Injections
  • Incorrect permissions assigned to programming scripts
  • Firewall leaking details about the validity of credentials
  • Persistent cross-site scripting
  • Stack-based Buffer overflow attack










"The empty password on the FTP user account can be used to log in. The hidden Telnet functionality can then be activated. After this, the attacker can access the world-writable (non-restricted) file that controls which programs run on boot, and the attacker may add his own to the list," F-Secure researchers says. 
"This allows the attacker persistent access, even if the device is rebooted. In fact, the attack requires the device to be rebooted, but there is a way to force a reboot as well."





 

1 comments: