Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

7/30/2019
02:15 PM
50%
50%

Insecure Real-Time Video Protocols Allow Hollywood-Style Hacking

Lack of security in the default settings of Internet-enabled video cameras make co-opting video feeds not just a movie-hacker technique, but a reality for millions of cameras.

More than 4.6 million video cameras may be open to an attack that could co-opt the video feeds of network-connected video cameras if the owners relied on the device's default settings, according to research by Internet of Things (IoT) security firm Forescout Technologies. 

In a report published on July 30, the company's researchers found that an attacker who already has some level of access to a smart building's or corporation's network could completely replace the video feeds from many types and configurations of IP video cameras because they rarely use encryption or authentication. A simple attack to reroute the video and restart the device can easily replace a video stream with attacker-provided data, the company states

"Our main point is not to demonstrate that you take over a system, but that you can conduct a cyber-physical attack — you are disrupting functions in the physical world using cyber means," says Elisa Costante, senior director of research for Forescout. "If you encrypt the protocols, none of this would be possible."

Hackers co-opting video feeds to stymie corporate defenses is a staple of Hollywood movies. Unlike many attack techniques, which Hollywood studios often treat as some sort of techno-wizardry, hacking IP video cameras is often straightforward because most devices continue to be poorly secured.

Forescout's attack, for example, relies on an common technique known as ARP poisoning, where the attacker misdirects network traffic by sending an address resolution protocol (ARP) packet to link an IP address with an attacker-controlled system. The effectiveness of the attack highlights how manufacturers continue to fail to secure the network-connected devices — such as IP cameras — to prevent the easiest attacks.

While some manufacturers have secured their devices, tens of millions of IP-connected video cameras have been installed by businesses and consumers, many without thought to security, Forescout says.

Secure versions of the real-time streaming protocol (RTSP) exist but are often not implemented, the company's report states.

"Unfortunately, these secure alternatives are not always available in IoT devices, are almost never configured by default, and are many times not enabled by the end users, who generally do not have all the knowledge required to secure RTP sessions in the first place," the company says.

A scan for the unsecured RTSP port uncovered more than 4.6 million devices that exposed the real-time streaming protocol to the Internet, suggesting that those devices are likely to be misconfigured and have unencrypted streams. Such devices often pose a higher security risk because they are rarely managed in the same ways as computer systems, with little on-board security and very infrequent patching.

The worries come the same week that security firm Armis revealed that more than a dozen flaws exist in a variety of versions of the real-time operating system (RTOS) created by VxWorks, a provider of embedded software. The vulnerabilities could leave as many as 200 million devices vulnerable to attack, many of which are unlikely to be patched.

In Forescout's report on its research, the company includes a video demonstrating how an attacker could sabotage an IP video stream to make security guards, for example, not see an intruder. Current security solutions are unlikely to be able to detect such attacks, the company says.

"The security challenges presented by these devices are forcing organizations to rethink their cybersecurity strategies," the company states in the report. "Legacy security solutions are not enough to secure today’s networks because either they are unsupported by embedded devices or they are incapable of understanding the network traffic generated by these devices."

Instead, companies need to focus on easily managed devices and configure them to use encryption, the report stated.

Related Content:

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

 

 

 

 

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
GitHub Named in Capital One Breach Lawsuit
Dark Reading Staff 8/14/2019
The Mainframe Is Seeing a Resurgence. Is Security Keeping Pace?
Ray Overby, Co-Founder & President at Key Resources, Inc.,  8/15/2019
The Flaw in Vulnerability Management: It's Time to Get Real
Jim Souders, Chief Executive Officer at Adaptiva,  8/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5034
PUBLISHED: 2019-08-20
An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indoor version 4620002. A set of specially crafted weave packets can cause an out of bounds read, resulting in information disclosure. An attacker can send packets to trigger this vuln...
CVE-2019-5035
PUBLISHED: 2019-08-20
An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater Weave access and potentially full device control. An attacker c...
CVE-2019-5036
PUBLISHED: 2019-08-20
An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resulting in a denial of service. An attacker can send a specially cr...
CVE-2019-8103
PUBLISHED: 2019-08-20
Adobe Acrobat and Reader versions, 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation ...
CVE-2019-8104
PUBLISHED: 2019-08-20
Adobe Acrobat and Reader versions, 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation ...