Latest news

But, those individuals and organizations who actually use and control them should be aware that most of them come with default settings that make them vulnerable to outside attacks.
According to Gotham Digital Science researcher Justin Cacak, standalone CCTV video surveillance systems by MicroDigital, HIVISION, CTRing, and many other rebranded devices are not only shipped with remote access enabled by default, but also with preconfigured default accounts and passwords that are banal and easy to guess.
"Many owners of CCTV video surveillance systems may not even be fully aware of the device’s remote access capabilities as monitoring may be conducted exclusively via the local video console," he pointed out in a blog post.
Add to this the fact that these same owners often fail to change default password for the admin account, or change it to one equally easy to guess, and you have a recipe for disaster.
"Interacting with the standalone CCTV system can be achieved via a Win32 thick client, a mobile device, or an IE ActiveX control in which a user name and password are required," he explains. "Typically, in over 70% of cases the device is still configured with the default vendor password which allows trivial access to real time video, the ability to control PTZ (pan-tilt-zoom) cameras, and access to any archived footage."
Cacak says that video surveillance devices are often overlooked during security audits and vulnerability/penetration tests, but this is likely to change, as the company's researchers have collaborated with Rapid7 developers and have created a new Metasploit module that tests the most popular CCTV systems - including the aforementioned ones.
He also gave good advice to CCTV deployers: change the default vendor passwords to strong ones, filter access to only trusted hosts, and disable the system's remote access if it's not needed.


Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





