Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Super-Creepy Reason Why You’ll Want to Secure Your Surveillance Camera

b2ap3_thumbnail_dvr_iot_issues_400.jpgWith approximately 5.5 million new devices being connected to the Internet everyday, the Internet of Things presents the biggest security challenge to date for IT professionals. Essentially, an IoT device that’s not secured can easily fall prey to hackers, and with so many different devices being connected, it’s easy to overlook a device or two, like your security cameras.

The creepy risk associated with not securing an Internet-connected security camera was recently reported on by Lisa Vaas of Naked Security. In her article, “DVR snaps stills from CCTV surveillance and sends them to China,” she presents findings from researchers at UK-based Pen Test Partners about the security holes found in the Internet of Things.

For the study, Pen Test Partners researchers analyzed data from Shodan, which is essentially a search engine for Internet-connected devices, like buildings, smart appliances, webcams, and much more. In particular, the researchers used Shodan to look at Internet-connected surveillance cameras.

Before we go into the technicalities of what they found, let’s take a step back and warn everybody who uses a webcam or Internet-connected surveillance camera that even a novice PC user can create a free account with Shodan and use it to search for, access, view, and even control unsecured cameras. We were skeptical of this claim when we first heard about it, but the proof is in the pudding. Check out these stills from random surveillance cameras we came across on Shodan:

ib spy1

ib spy2

ib spy3

ib spy4

These cameras are just random ones that we stumbled upon. However, Shodan has been criticized for giving its users easy access to cameras that are sensitive in nature. Vocativ cites findings by Ars Technica:

These webcams show feeds from sensitive locations like schools, banks, marijuana plantations, labs and babies’ rooms. Shodan members who pay the $49 monthly fee can search the full feed at images.shodan.io. A Vocativ search of some of the most recently added images shows offices, school, porches and the interior of people’s homes. Accompanying each of these grabs is a pinned map that shows the location of the device capturing that footage.

If that doesn’t creep you out, then lets go back and take a look at the even-more-in-depth findings of the first study we mentioned by Pen Test Partners. Vass reports:

The device also has no Cross-Site Request Forgery (CSRF) protection, so attackers can trick users into clicking on links to carry out malicious actions; it has no lock-out, so attackers can guess as many passwords as they like; it sends communications without HTTPS that can be intercepted and tampered with; and there’s no firmware updates, so “you’re stuck with these issues,” Pen Test Partners said. But weirdest of all, the thing is capturing still images from video feeds and emailing them to an address that appears to be hosted in China.

As far as why surveillance images were being sent to China, that’s a mystery that Pen Test Partners was unable to get to the bottom of. We could speculate as to what’s going on here, but at the risk of letting our imaginations run wild and sounding like conspiracy nuts, we won’t. Instead of making wild speculations, we want to communicate that we’re here to help your company secure all of its Internet-connected devices from the prying eyes of everyone on the web.

Are you confident that all of your IOT devices are secure enough to keep hackers out of your network? Do you even know if you have IoT devices on your network transmitting data across the web? Or at the very least, are you sure that random Shodan users aren’t making a highlight reel from your surveillance camera footage? To get a grip on the security of every Internet-connected device on your company’s network, give Total Tech Care a call at 866-348-2602.

 

Comments 1

brenda williamson on Sunday, 08 July 2018 16:29

IoT devices are enhancing the level of security with surveillance camera in home and office.The amcrest 1080p reviews will let the users know about how to install the security camera and how to take the safety measures for the future.

IoT devices are enhancing the level of security with surveillance camera in home and office.The [url=https://homebuyingchecklist.co/reviews/amcrest-prohd-1080p-wifi-ip-security-camera-review/]amcrest 1080p reviews[/url] will let the users know about how to install the security camera and how to take the safety measures for the future.
Already Registered? Login Here
Guest
Friday, 24 January 2025
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Network Security Business Google Microsoft Internet Email Malware Workplace Tips Backup Innovation Data User Tips Computer Mobile Devices Hardware IT Services Android VoIP Disaster Recovery communications IT Support Smartphones Communication Business Continuity Miscellaneous Smartphone Mobile Device Browser Small Business Network Collaboration Productivity Quick Tips Cybersecurity Users Business Management Upgrade Managed IT Services Windows Phishing Outsourced IT Ransomware Data Backup Windows 10 Data Recovery Cloud Computing Server Save Money Office Passwords Windows 10 Chrome Tech Term Virtualization Social Media Saving Money Gadgets Holiday Managed Service Microsoft Office Automation Managed IT Services Operating System Facebook Computers Cybercrime Artificial Intelligence IT Support Hacking Internet of Things BYOD Health Mobile Device Management Wi-Fi Networking Spam Managed Service Provider Covid-19 Information Office 365 Telephone Systems Information Technology Remote Alert Social Engineering Mobility Router BDR Recovery Employer-Employee Relationship Bandwidth Password Remote Monitoring Money Big Data Encryption Applications App History Data Breach Mobile Computing Law Enforcement Human Resources Application Blockchain Mobile Office Apps Paperless Office Data Storage Patch Management Office Tips Training Government VPN Private Cloud How To Managed IT Remote Computing HaaS Work/Life Balance Vulnerability Windows 7 Word Infrastructure Google Drive Voice over Internet Protocol Wireless Flexibility Servers Marketing WiFi Gmail Avoiding Downtime IT solutions Settings Entertainment Data Security Website Budget Two-factor Authentication Bring Your Own Device Mouse Data Management Vendor Cleaning User Error Managed Services Telephone System Staff Software as a Service Display Meetings Conferencing Machine Learning End of Support Connectivity Remote Work Education Physical Security Scam Employee/Employer Relationship Safety Risk Management RMM Hacker Sports HIPAA Redundancy Vendor Management Keyboard The Internet of Things Lithium-ion battery Data Protection Firewall USB Save Time Virtual Reality Apple Social Virtual Assistant Computing Infrastructure Hiring/Firing Going Green Authentication Database Remote Workers Processor Wearable Technology Battery Update Retail Hard Drives Shadow IT Instant Messaging Legal Business Intelligence Hard Drive Robot Excel Google Docs Audit Internet Exlporer Worker IT Management Biometrics Identity Theft Virus Virtual Desktop Computing Botnet PDF IT Plan Unified Threat Management DDoS Computer Accessories Proactive IT Augmented Reality Unsupported Software Fraud SharePoint Best Practice YouTube Charger Remote Worker Digital Signage Black Market Printer Customer Service Compliance Cryptocurrency Computer Care Bluetooth OneNote Environment Current Events Procurement Document Management Telephony Fax Server Wireless Technology Samsung Workplace Strategy Comparison Net Neutrality Solid State Drive How to Downtime CES SaaS Help Desk Value IT Consultant Printing Data storage Business Technology Content Management Automobile Spam Blocking Electronic Medical Records Access Control Humor Network Congestion Managed Services Provider eWaste Monitoring Batteries Mobile Windows 10s Tablets Entrepreneur Virtual Private Network Windows 8.1 Digitize Workforce Cast Cables Windows Server 2008 R2 Tip of the week Reputation webinar Streaming Media Emergency Consultant Customer relationships Content Professional Services Analytics Shortcut Public Cloud Tech Support Employer Employee Relationship Cost Management Laptop Assessment Project Management Email Best Practices Nanotechnology IT Assessment Telecommuting Manufacturing Techology Best Available Cortana Windows Server 2008 Social Networking Customers Computer Tips WIndows 7 Digital Signature Managed IT Service Audiobook Tools Security Cameras Touchpad Television Warranty Virtual CIO OneDrive Biometric Security Google Apps Running Cable HVAC Peripheral Digital Security Cameras Analysis Using Data Politics Advertising Memory Public Computer Administrator Devices Copiers 5G Regulations Notifications Transportation Enterprise Content Management Quick Tip Rootkit MSP Ergonomics User Accountants PowerPoint Smartwatch Computer Fan Windows Media Player Microchip Thought Leadership Development Credit Cards OLED Password Manager Virtual Machine Relocation Workers Science Benefits Password Management PCI DSS 2FA Managing Stress Fiber Optics Multi-Factor Security Employee FENG Video Games IBM Search Engine Twitter Messaging Cabling Business Mangement Hypervisor Distributed Denial of Service Worker Commute Flash Cameras Customer Relationship Management Smart Technology NIST Policy Dark mode Smart Tech Trend Micro Experience Trending Analyitcs Scalability Software Tips Programming Supercomputer Addiction SMS Amazon Default App Recycling Saving Time Business Owner Sync Emails Procedure NarrowBand Wiring dark theme Practices Shopping Google Search Antivirus Search Cache AI Amazon Web Services IT Infrastructure Criminal Printer Server Bing iPhone Netflix Windows 8 Two Factor Authentication Safe Mode FinTech GDPR Hosted Computing Social Network IT service Root Cause Analysis HBO Knowledge Music Wireless Internet Online Shopping Investment Employee/Employer Relationships Skype Files Tablet File Sharing Employees Chromecast Camera Windows 365 Inventory Specifications ISP Domains Data loss Outlook Leadership Troubleshooting Wire Video Conferencing Evernote ROI Sales Bitcoin IaaS Start Menu Travel Shortcuts Maintenance Colocation Uninterrupted Power Supply Bloatware Loyalty Printers Point of Sale Personal Millennials Cryptomining Screen Mirroring Wireless Charging Frequently Asked Questions Monitor Books Smart Office Supply Chain Management

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code