TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

This security camera was infected by malware 98 seconds after it was plugged in

49 点作者 brakmic超过 8 年前

15 条评论

maaaats超过 8 年前
Previous discussion on the original tweets: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12985974" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12985974</a>
kinkdr超过 8 年前
This brings back memories of Windows 95-98 era, where a fresh install would get infected in matter of seconds after connected to the internet.<p>I expect the IoT to go though a similar phase, but eventually get fixed and be secure enough.
评论 #13008870 未加载
ruddct超过 8 年前
Having flashbacks to the &#x27;bad old days&#x27; of similar things happening to Windows machines (PCs, ATMs, etc). Microsoft, the gigantic, near-monopoly company in the space with a jillion very smart people working for it, struggled with such issues for many years (though eventually reined it in).<p>This time, though, I don&#x27;t see a tenable path to actually fix this. The IoT industry is terribly, terribly fragmented. Few business models incentivize providing ongoing maintenance once they&#x27;ve sold you their gizmo. Few consumers have the ability to detect that this is happening.<p>I suspect that security and compatibility issues will cripple a large chunk of the IoT industry, with bigger players slowly picking off the profitable&#x2F;useful chunks with niche products customers will think of as &#x27;safe&#x27; (read: Amazon&#x2F;Google&#x27;s many IoT products).<p>In the mean time, I&#x27;ll continue avoiding smart&#x2F;IoT devices in my house. The risks seem to far, far, outweigh the rewards.
oxide超过 8 年前
I wonder how many of these cheap things are going to get plugged in this holiday season with default login&#x2F;passwords.
stamps超过 8 年前
What is a good security camera? Who makes good ones?<p>I haven&#x27;t been able to find a company who provides a quality POE device that allows me to control the feed into something like Zoneminder.<p>Do I have to use something more analog to be &quot;safer&quot; from something like this?
评论 #13008902 未加载
评论 #13008845 未加载
jbyers超过 8 年前
What is the expected time between port scan for an arbitrary IPv4 address? Is the level of scanning activity so high (or so well-targeted to &quot;promising&quot; address spaces) that one should expect to be scanned in minutes?
评论 #13010565 未加载
评论 #13008926 未加载
DanBC超过 8 年前
&gt; Better-quality devices will almost certainly be better protected against this kind of thing, and may for example block all incoming traffic until they’re paired with another device and set up manually. Still, this is a good reminder that it really is a jungle out there.<p>This seems like a bold claim, unless they define &quot;better quality&quot;.
fanzhang超过 8 年前
How would the malware even know that the camera was connected in? Especially if you&#x27;re on a home network (which is firewalled &#x2F; has NAT on).<p>I suspect that it must be the central server that this camera reports to that is infected, either directly, or indirectly with some program sitting at a nearby router listening for traffic.
评论 #13008803 未加载
评论 #13008822 未加载
t0mbstone超过 8 年前
News flash: If you expose a device web-accessible port to an internet IP with no firewall and leave the default user name and password intact, it will get hacked.<p>Put your shit behind firewalls and change the default user name and password to something secure. This is common sense stuff, people. Port scanners have existed for ages.
评论 #13008844 未加载
评论 #13008798 未加载
tonyplee超过 8 年前
From the tweet pics, it looks like the outside IP was able to connect to the camera via telnet.<p>Does the camera firmware open a UPNP tunnel in AP to its telnet port?<p>Does this guy&#x27;s Wifi router enable anyone one to open tunnels in his AP router?
评论 #13008818 未加载
shendu超过 8 年前
The article missed an important fact:<p>Question: interesting tweets Rob, is it used Dynamic DNS when it is initially setup? If no , how is it exposed to internet?<p>Answer: I had to map the external port 23 on the firewall to the device.
ryanstanton超过 8 年前
Eek, who knew the rise of cheap CMOS-based surveillance cameras would lead to DDOS attacks?
mmagin超过 8 年前
Are most of these things spread via random IPv4 address probes? Are we going to be a somewhat safer when networks are IPv6-only due to the size of the address space vs the used addresses?
batrat超过 8 年前
a tech industry veteran - Internet-scanning(his hobby) - cheap camera - no firewall - wannabe famous -&gt; make your pick. 100% he infected it himself.
funkyy超过 8 年前
It almost looks like the camera producer&#x2F;someone from an internal team was responsible for either giving out backdoor or actually infecting the camera...