It’s now anno domini 2017 and the number of Internet-connected devices surpass the living population by an order of magnitude. And while most of these devices help us reinvent the way we interact with our homes, our offices or with our own bodies, some “smart things” can lend hackers a helping hand in digital burglary.
This is the case with over 120,000 internet-connected security cameras manufactured by Shenzhen Neo Electronics, whose firmware contains a massive security flaw that renders them remotely exploitable. A bug in the authentication mechanism allows a remote attacker to completely take control and run commands on the vulnerable devices and turn them into a zombie army ready to trigger the next Mirai or to become tools of mass surveillance in users’ homes.
Our own Chief Security Researcher Alex “Jay” Balan got on the Defcon IoT stage with a live demo of the exploitation. And while we’re eagerly waiting for the video, his presentation () and the technical whitepaper documenting the findings are ready for download.