Unsecured IP Cameras Accessible To Everyone 146
Orome1 writes "In the last couple of decades, we have become so accustomed to the idea that the public portion of our everyday life is watched and recorded — in stores, on the street, in institutions — that we often don't even notice the cameras anymore. Analog surveillance systems were difficult to hack into by people who lacked the adequate knowledge, but IP cameras — having their own IPs — can be quite easily physically located and their stream watched in real-time by anyone who has a modicum of computer knowledge and knows what to search for on Google."
Nice one (Score:5, Informative)
Good find 2002.
Re: (Score:2)
Re:Nice one (Score:5, Informative)
from 2005... but whatever. it's old news
http://it.slashdot.org/article.pl?sid=05/01/09/1411242 [slashdot.org]
Re:Nice one (Score:5, Informative)
Re: (Score:1)
You're doing it wrong. If you want to karma whore, you go through there and start posting the +5s. There's fuckin' room to move as a fry cook. I could be manager in two years. King. God.
Re: (Score:2)
Re: (Score:2)
You are touchy.
Touché
Re:Nice one (Score:5, Informative)
Here's the deal though: if it's been six years and nobody's bothered to close these security holes --- and the searches still work, I just tried --- then *THAT* is news.
Finding a security exploit is not big news. Leaving a security hole unfixed for six years *is* big news, especially if it's done by companies for whom "security" is literally their middle name.
Re:Nice one (Score:4, Insightful)
Here's the deal though: if it's been six years and nobody's bothered to close these security holes --- and the searches still work, I just tried --- then *THAT* is news.
Finding a security exploit is not big news. Leaving a security hole unfixed for six years *is* big news, especially if it's done by companies for whom "security" is literally their middle name.
Who says its a security hole?
Do I care if the entire world can look thru my camera? Does it in any way effect the operation of the camera or of the security system attached to it? No.
Now if the camera is pointed at something I don't want the rest of the world to see... maybe I should have sprung for a system that at least requires a password...
Re:Nice one (Score:5, Interesting)
Actually it does. Most cameras have a limit of how many simultaneous connections are allowed. Exceed that limit and the owner might have to reboot the camera in order to access their own video feed. Bad news if that camera's looking at the door of your emergency room or your unmanned warehouse half a continent away.
Re: (Score:3)
Re: (Score:2)
Re: (Score:2)
You have a five digit /. ID and you ask a stupid question like that?
Presumably you were on the plonk, tired and emotional when you posted it.
Surely you see that your comment implies you have a nearly infinitely fast internet connection ...
Cheers
Jon
Re: (Score:2)
Build a man a fire and you warm him for a day. Set a man on fire and you warm him for the rest of his life.
Way to mangle a classic there, Captain Shakespeare. It actually goes like this:
Light a man a fire and he will be warm for a day, light a man afire and he will be warm for the rest of his life
It's about subtlety
Old news is old. (Score:2)
NPR had a story on using an iPhone app to surf surveillance cameras around the world.
Re: (Score:2)
9/11/2001: I was working for a newspaper and since most of the usual communication lines were jammed, etc. I was put on the mission to find an open webcam in NYC. I found one on top of Empire State Building that gave us a fairly clear shot that we used for our piece on the subject. That was 2001 so this is ooooooold news..
Re: (Score:3)
We found one on a passenger jet over NYC but that didn't turn out so well.
Re:Nice one (Score:4, Funny)
Me too, mine was even aimable with a little javascript control. Got a really good close up of the second tower.
Re: (Score:2)
No kidding.
And now, the search is so full of SEO poisoning spam results, you can't actually find any cameras on the first few pages of results.
Also on Ars Technica (Score:5, Informative)
Ars Technica did a nice piece on this too:
http://arstechnica.com/gadgets/guides/2011/01/one-mans-journey-through-the-world-of-unsecured-ip-surveillance-cams.ars [arstechnica.com]
Worth a read.
Re: (Score:1)
Worth a read.
Except for this inflammatory part:
Because he accessed the feed through the back door, he probably didn't see the welcome mat on the front door. Many jurisdictions put traffic cameras (which are not the same as 'security cameras') online intentionally so people can pla
Re: (Score:1)
This is so old. (Score:5, Informative)
And toast always drops butter side down (Score:1)
"Unsecured IP Cameras Accessible To Everyone"
Well, doh, enable a good password and run them over SSH .. !!!
Re: (Score:2)
It's like those idiots that use wireless cameras. They're easi
tons of cams are available. (Score:5, Informative)
heres a long list copied from various parts of the web for searches you can try :
allintitle: "Network Camera NetworkCamera" Network cameras
intitle:Axis 2400 video server Mostly security cameras, car parks, colleges, clubs, bars, etc.
intitle:axis intitle:"video server" Mostly security cameras, car parks, colleges, bars, ski slopes etc.
intitle:"EvoCam" inurl:"webcam.html" Mostly European security cameras
intitle:"Live NetSnap Cam-Server feed" Network cameras, private and non private web cameras
intitle:"Live View / - AXIS" Mostly security cameras, car parks, colleges etc.
intitle:"LiveView / - AXIS" | inurl:view/view.shtml Mostly security cameras, car parks, colleges etc.
intitle:liveapplet Mostly security cameras, car parks, colleges, clubs, bars etc.
intitle:snc-cs3 inurl:home/ Mostly security cameras, swimming pools and more etc.
intitle:"snc-rz30 home" Mostly security cameras, shops, car parks
intitle:snc-z20 inurl:home/ Mostly security cameras, swimming pools and more etc.
intitle:"WJ-NT104 Main" Mostly security cameras, shops, car parks
inurl:LvAppl intitle:liveapplet Mostly security cameras, car parks, colleges etc.
inurl:indexFrame.shtml "Axis Video Server" Mostly security cameras, car parks, colleges etc.
inurl:lvappl A huge list of webcams around the world, mostly security cameras, car parks, colleges etc.
inurl:axis-cgi/jpg Mostly security cameras
inurl:indexFrame.shtml Axis Mostly security cameras, car parks, colleges etc.
inurl:"MultiCameraFrame?Mode=Motion" Mostly security cameras, pet shops, colleges etc.
inurl:/view.shtml Mostly security cameras, car parks, colleges etc.
inurl:/view/index.shtml Mostly security cameras, airports, car parks, back gardens, traffic cams etc.
inurl:viewerframe?mode= Network cameras, mostly private webcams etc.
inurl:"viewerframe?mode=motion" Network cameras
inurl:ViewerFrame?Mode=Refresh Mostly security cameras, parks, bird tables etc.
Other searches: /view/index.shtml
control/userimage.html liveapplet inurl:indexframe.shtml inurl:"view/index.shtml" inurl:"view/indexFrame.shtml" inurl:view/view.shtml
inurl:/view/view.shtml?videos= inurl:ViewerFrame?Mode= inurl:ViewerFrame?Mode=Motion inurl:ViewerFrame?Mode=Refresh site:.viewnetcam.com -www.viewnetcam.com
In Title:
intitle:"live view" intitle:axis
intitle:"EvoCam" inurl:"webcam.html"
intitle:"i-Catcher Console - Web Monitor"
intitle:"Live NetSnap Cam-Server feed"
allintitle:liveapplet
intitle:liveapplet
intitle:"netcam live image"
intitle:"snc-rz30 home"
intitle:"WJ-NT104 Main"
In URL:
inurl:axis-cgi/jpg
inurl:indexFrame.shtml Axis
inurl:indexFrame.shtml "Axis Video Server"
inurl:lvappl live webcams
inurl:LvAppl intitle:liveapplet
inurl:"MultiCameraFrame?Mode=Motion"
inurl:/view:shtml
inurl:/view/index.shtml
inurl:view/indexframe.shtml
inurl:view/view.shtml
viewerframe?mode=
inurl:"viewerframe?mode=motion"
inurl:ViewerFrame?Mode=Refresh
Two searches in one order:
intitle:"live view" intitle:axis (two searches in one order)
intitle:axis intitle:"video server"
intitle:liveapplet inurl:LvAppl
intitle:"Live View / - AXIS" | inurl:view/view.shtml
intitle:start inurl:cgistart
Combination:
camera linksys inurl:main.cgi
Display Cameras intitle:"Express6 Live Image"
intitle:"active webcam page"
intitle:"EvoCam" inurl:"webcam.html"
inurl:LvAppl intitle:liveapplet
intitle:"Live View / - AXIS"
intitle:liveapplet inurl:LvAppl
intitle:"my webcamXP server!" inurl:":8080"
intitle:"Network Camera" inurl:ViewerFrame
intitle:snc-z20 inurl:home/
intitle:snc-rz30 inurl:home/
intitle:"toshiba network camera - User Login"
intitle:"Live View / - AXIS" | inurl:view/view.shtml
tilt intitle:"Live View / - AXIS" | inurl:view/view.shtml
intitle:"WJ-NT104 Main Page"
Sometimes your order gives hundreds of URLs. You can restrict your search by adding a country, a specialized URL or another mes
Re: (Score:1)
So which ones are the open live porn chat cams?
Re:tons of cams are available. (Score:5, Interesting)
Glad I work for one of the few security companies that doesn't have its head up its collective ass. I'd really hate working for one of the Big Three.
Re: (Score:1)
Re: (Score:1)
Horrible practice, however I would imagine that many of these jobs are contract installs. If no one is around to create and keep the password I can understand how some installers would not change it as it then becomes their obligation to store the password. More of a headache, but as a security business this is laughable!
Re: (Score:2)
But still, it sounds completely insane. I knew the IT security industry was full of crazy, but this is just surreal. Insi
Re: (Score:2, Offtopic)
Re: (Score:3)
How do you guys handle situations like that? Ever had any problems when actually telling the management/client? Or is it all cool and professional?
Re: (Score:3)
Not always though. We have one customer where I just plain can't talk to the network admins directly because I inadvertantly showed them up as a clot of incompetent
Re: (Score:1)
These are cameras. Not installed or maintained by IT staff.
Few places have physical security as a function of their IT dept, although that trend is changing.
Re: (Score:2)
Accounting isn't a function of the IT department, but those systems are maintained by the IT staff. The physical security systems are just one more thing that's being added to the mix.
Re: (Score:3)
Re: (Score:2)
Re: (Score:2, Insightful)
For the most part these cameras are looking at parking lots and other boring crap, why secure it at all?
Oh Noes the bad guys can look at our empty parking lot at night!
Re:tons of cams are available. (Score:4, Interesting)
Re: (Score:2)
Offhand I would say the primary concern would be that if the criminals know where the security cameras are looking then they would know where they aren't looking as well.
Re: (Score:2)
You can figure that out by looking at the camera too.
Re: (Score:2)
You can tell how wide the field of view of a camera mounted 30 feet up is just by looking at it? I think it would be rather helpful when planning a robbery/murder/whatever to know exactly where the cameras are looking instead of having just a general idea. Plus getting this information online reduces your risk of being recognized from having cased the location in person.
Re: (Score:2)
Ahh see, now looking in on an open webcam is one thing - with a good lawyer you probably wouldn't make it to court. Trying to break into one that is secured by a password (even a shitty password) is criminal pretty much everywhere.
Where did you say you worked again? Failing that, who was the "competition"? I know that you know these are rhetorical questions, but if you DID get caught one day I'm sure you wouldn't be able to hide behind the "security researcher" excuse for long.
Re: (Score:2)
But if you knew the username and password, couldn't you claim you were an authorized user - after all, you have a valid username and password.
Re: (Score:2)
Re: (Score:2)
But far be it from me to complain and not offer a better solution, so I give you:
inurl:"/jpg/" | "/mjpg/" | "/axis-cgi/" ?inurl:"image.cgi" | "video.cgi" | "video.mjpg" filetype:mjpg | filetype:cgi
Not perfect, but almost all the results returned are working cams, though it is limited to Axis cams.
Re: (Score:2)
A friend of mine said that one of those cameras was in the bathroom of a super-model.
I guess she must be an athlete because he said he saw her box.
Re: (Score:1)
you will find a huge torrent of bullshit if you search for "Index of" "mp3"
To be fair, that's pretty much what the kiddies are wanting when they do that search.
Cameras Everywhere (Score:5, Interesting)
At the University where I work, there are cameras in all of the lobby areas and in many of the labs. They are publicly accessible, for the most part - non-port 22 but otherwise unsecured. However, because the University wants to be able to use the pictures in legal proceedings, all the camera areas are clearly marked with "Video Surveillance" stickers.
I can't speak for anyone else, but it's not that hard to just not do funky things in these areas.
Yes, it intrudes on my sphere, but I have no expectation of privacy at work, or on the street. If I want to do something private, I go somewhere private. It's not that much of a burden, at least to me.
Re: (Score:2)
What are you, some sort of Religious prude? Come on, really get with the times. Not only are you supposed to do it public, you are supposed to use video cams and upload your exploits to PornTube or other video sharing sites. No judging going on there, as whatever you're into, you're not alone!
Go on, be proud of who you are.
Re: (Score:3)
Yes, it intrudes on my sphere, but I have no expectation of privacy at work, or on the street. If I want to do something private, I go somewhere private. It's not that much of a burden, at least to me.
What happens when cameras - and the databases behind them - become so pervasive that you can't go anywhere without a permanent record being made?
Its one thing for some people on the street to see you walk to the corner drug store and buy a pack of condoms.
Its an entirely different thing for that to be recorded and cross-indexed with everything else you've done outside of your home.
If I remember correctly... (Score:2)
There was an article a while back about the US Army drones transmitting over an unsecure protocol and needing 50 dollar equipment to find out what they were scouting out.
MIT Carpark (Score:2)
This was available on the MBone as an IP camera before Google even existed.
Aggregator (Score:5, Informative)
Re: (Score:2)
Re: (Score:2)
The one labeled Argonne National Laboratory raises a security eyebrow.
My local red light cameras (Score:5, Funny)
Now all I need is to have the IP address of my local red light and speed cameras.
Of course, I would never have any fun and do something like, changing the time, moving the camera, replacing drivers' faces with pictures of say, maybe Osama Bin Laden, Benjamin Franklin, or the president.
Re: (Score:2)
You would be charged with a felony and would spend 10+ years in prison for it.
Re: (Score:3)
Not if he hacked into it from your house. :p
Re: (Score:2)
Um...how is this different then anything else? (Score:2)
This is how it should be (Score:1)
If the streams were secured, there'd be a monopoly or oligopoly of the information thereof, paving way for police states. As long as it's publicly accessible (though it should be properly accounted and publicly listed) it's common knowledge to be leveraged by all. Want to check whether your friends are hanging at their usual place? Check it out from the live stream. Want to see how it's like to live on the other side of the world? Want to follow an uprising in Tunisia? Likewise.
Re: (Score:2)
Yes. The inequality of information access is usually why we worry about privacy. We are quite comfortable operating in public places. It's the selective and unaccountable use of information about us that freaks people out.
Information that is truly public isn't nearly as scary as information which is selectively used by people working in secret. Most corporations, of course, prefer that the data you turn over remains entirely private. And we have no corresponding view into the corporation's inner workings (F
Transparent Society & The Light of Other Days (Score:2)
http://en.wikipedia.org/wiki/Transparent_society [wikipedia.org]
http://en.wikipedia.org/wiki/The_Light_of_Other_Days [wikipedia.org]
Re: (Score:2)
Re: (Score:2)
Red-light cameras? (Score:2)
>>He also managed to access three red-light cameras in a town in Texas, and while he didn't change any settings, he could have.
Oh, that kind of red-light, shame....
where is the google mashup? (Score:2, Interesting)
In 2011 I would expect to see a mashup showing a map with all the locations of the IP addresses that allows you to click and view
OH CRAP!!! (Score:2)
Apparently spammers have caught on to this (Score:2)
I found many online cameras 3-4 years ago, but things seem to have changed. For example, the Ars Technica article, referenced earlier, says "Change the search to “intitle: ‘Live View / - AXIS 206M,’” though, and Google returns 3 pages of links to 206Ms that are online and viewable." But when I try this, I only get spam websites and articles telling you "how to use Google to find online cameras".
Like anyone cares (Score:2)
Why would the camera owners care? Mostly they are just there for surveillance. They don't care who is watching or they would not have a camera.
Re: (Score:2)
I'd like to pass a law (Score:2)
Re: (Score:2)
Re: (Score:2)
ChumbySpy has been around for years (Score:2)
This is news?
ChumbySpy and SurveillanceSaver have been around for years.
http://www.chumby.com/guide/widget/ChumbySpy [chumby.com]
Re: (Score:2)
I had the OSX version of surveillancesaver installed on my mac, but when I upgraded to Snow Leopard it quit working. Found out it was written in Quartz, so I re-compiled it with the new version, and got it working again.
Then I found out that the guys who wrote the original went on to found the Public Viewpoint Project, which searches for publicly available webcams and creates an RSS feed. I can't find their web site anymore, but the RSS feed is still up. I added to the screen saver the ability to connect to
Too simple to avoid this problem (Score:1)
Why would anyone do this when it's so simple not to?
Besides the obvious issue of choosing good passwords, why would anyone use public IP addresses or for that matter even the "common" private IP address for security devices?
Ideally, you'd have them on an isolated network which MIGHT be joined to the corporate WAN by a dual-homed control/recording station but that might not be possible for a variety of reasons.
Less than ideal is running them on a separate IP address space so they weren't "visible" to other c
Re: (Score:1)
At the very least firewall the puppies (Score:1)
Tell him he can have what he wants if he antes up for a dedicated VPN or equivalent "front end login" that doesn't expose the cameras or the control computer directly to the Interweb.
You might also gain some traction if your state or country's employment laws would put the company or its officers at risk for violating employee privacy if they put the cameras on the web without adequate security. Heck, if the lawyer says doing this puts YOU at risk then that's the ultimate trump card.
Re: (Score:2)
Re: (Score:2)
Our preference is a completely private network, or
useless (Score:1)
So what if they are on google, most are empty until action happens, and the timing needed to be on at the same time action happens, is too small to even bother...unless it was inside a shower, then you pay per view....however, a camera set up outside someones home to log each entry into a house is pretty wasteful to watch...who cares if you can see what they see....as long as you cant reconfigure it,...
SurveillanceSaverOSX (Score:2)
A while back I ran across the SurveillanceSaver project - a simple screen saver which contained a small list of webcams it would cycle through. I had the OSX version installed on my mac, but when I upgraded to Snow Leopard it quit working. Found out it was written in Quartz, so I re-compiled it with the new version, and got it working again.
Then I found out that the guys who wrote it went on to found the Public Viewpoint Project, which searches for publicly available webcams and creates an RSS feed. I ca
There's an app for that! (Score:2)
http://livecams-iphone.com/ [livecams-iphone.com]
There are others, but I have found this one to be the best
Old news (Score:2)
Since I first arrived in La Jolla, CA (92037) and noticed the little black domes darn near everywhere I theorized that, whether or not different subcontractors manage the security contract for any individual location, there is some overseer--either official or sitting on a network intersection--who has access to all of them. They probably have a FPS/MMORPG type interface which they are able to use to follow any particular person around should any particular person happen to catch their special interest. G
Re: (Score:3)
Senior Seminar Project (Score:2)
My senior seminar project as a CS undergrad (2005) was the creation of a motion sensing surveillance system. Part of the demonstration I did during the presentation was to show how my software could monitor cameras from around the world for motion. In many cases I had no idea where the cameras were physically located. Later as part of my Masters thesis (2010), I extended the software to include face recognition... now it can identify "John Doe" and you can have it tell you when it see's specific people in a
City Denies Citizen Access Over Webcam Use (Score:3)
My city has several cameras around the city available for access at the city's taxpayer-funded website. I decided to use them once to create some time-lapse video of the wax and wane of winter weather. One day, suddenly I couldn't access the cams anymore. Or the entire website. They unilaterally decided that I was using too much of their bandwidth and dropped my IP into a configuration file to disable my access, expecting me to go to them to get my access reinstated. Of course, all information on how to contact them was on their now-restricted website.
The amount of data transferred was less than 1 DVD a month. It wasn't that the usage was excessive; it was that my usage was an identifiable spike. But instead of limiting how often you can pull frames from the cameras (I used 1 every 30 seconds, sub-SD resolution, in greyscale, but from every camera), they instead decided to lock me out. (They also say they don't retain the video they record.)
Unfortunately, since I was grabbing these still images using my machine at work, and others at work were just monitoring the cameras in preparation for travel home, they saw it as coming from multiple IPs in the same subnet and blocked the company's entire IP range, which became a problem when the head of HR was needing to do background checks on some potential new hires on the city website.
Now if I want to do time-lapse videos of traffic cams again, I'm going to have to do it from home and through Tor so they can't identify one IP block. Even though there's some nice snowfall patterns recently, it just isn't worth the effort/hassle to satisfy my creative curiosity now.
Re: (Score:2)
Neat idea!
We do a similar thing with a few remotely located cameras. In this case, it's a webcam aimed at a river with a proposed hydroelectric development. The purpose of the camera is for ice monitoring. It takes photos hourly and is connected via satellite modem.
http://www.env.gov.nl.ca/wrmd/ADRS/v6/Template_Grizzle_Rapids.asp?station=03OE013 [gov.nl.ca]
Located at: 52.97583, -61.46858
Re: (Score:3)
so you like to hack into gay bar to watch penises, as they says : each to is own !
Re:I've hacked into... (Score:4, Funny)
so you like to hack into gay bar to watch penises, as they says : each to is own !
What a dick. If they find out, he's screwed.
Re: (Score:1)
so you like to hack into gay bar to watch penises, as they says : each to is own !
What a dick. If they find out, he's screwed.
Once you got the hang of it, you'll be a happy cork soaker!
Re: (Score:2)
so you like to hack into gay bar to watch penises, as they says : each to is own !
Has grandparent looked into a job with TSA? I heard it's an all-you-can-eat smorgasbord for the eyes of penus, all day just PENUS PENUS PENUS PENUS PENUS PENUS and they actually pay you for it!
Re: (Score:2)
Don't be such a cheapskate. Pay the bathhouse admission fee like everyone else if you want to make use of the... er.... facilities.
Re: (Score:2)
Re: (Score:2)
Re: (Score:1)
Weird how even not reading names I can tell it's one of your sock puppets. You need to develop a better trolling technique. You're not as amusing as the GNAA or trying to hide goatse into everything and that's saying something.
you're completely pathetic.
you're an ignorant hypocrite.
you're an idiot.
MichaelKristopeit402 = stagnated.
Re: (Score:2)