Start a Conversation

Unsolved

10 Elder

 • 

44.3K Posts

3556

October 12th, 2018 17:00

Chinese webcams hackable

SEC Consult researchers warn about surveillance equipment (webcams) built by Chinese manufacturer, Hangzhou Xiongmai Technology.

  • Default password too easy to crack
  • May not have a default password at all and no requirement to set one
  • Multiple unencrypted communication channels
  • Failure to check integrity of unsigned firmware updates
  • P2P Cloud feature bypasses firewalls and allows remote connections into private networks

Long list of brands use this hardware, over 100 of brands worldwide. Here are some of them:


9Trading, Abowone, AHWVSE, ANRAN, ASECAM, Autoeye, AZISHN, A-ZONE, BESDER/BESDERSEC, BESSKY, Bestmo, BFMore, BOAVISION, BULWARK, CANAVIS, CWH, DAGRO, datocctv, DEFEWAY, digoo, DiySecurityCameraWorld, DONPHIA, ENKLOV, ESAMACT, ESCAM, EVTEVISION, Fayele, FLOUREON, Funi, GADINAN, GARUNK, HAMROL, HAMROLTE, Highfly, Hiseeu, HISVISION, HMQC, IHOMEGUARD, ISSEUSEE, iTooner, JENNOV, Jooan, Jshida, JUESENWDM, JUFENG, JZTEK, KERUI, KKMOON, KONLEN, Kopda, Lenyes, LESHP, LEVCOECAM, LINGSEE, LOOSAFE, MIEBUL, MISECU, Nextrend, OEM, OLOEY, OUERTECH, QNTSQ, SACAM, SANNCE, SANSCO, SecTec, Shell film, Sifvision / sifsecurityvision, smar, SMTSEC, SSICON, SUNBA, Sunivision, Susikum, TECBOX, Techage, Techege, TianAnXun, TMEZON, TVPSii, Unique Vision, unitoptek, USAFEQLO, VOLDRELI, Westmile, Westshine, Wistino, Witrue, WNK Security Technology, WOFEA, WOSHIJIA, WUSONLUSAN, XIAO MA, XinAnX, xloongx, YiiSPO, YUCHENG, YUNSYE, zclever, zilnk, ZJUXIN, zmodo, ZRHUNTER

I never heard of these brands and don't know which ones might be sold here, but if you own one of them, be warned. The only things you can fix yourself are to change the default password to something stronger, or to set a strong password if none is already set. Manufacturer hasn't offered fixes for the other issues...

 

1 Message

October 19th, 2018 04:00

Aren't most webcams hackable? I read somewhere that the only safe way to not have someone spy on you is disconnect the webcam when not using it and taping over uilt-in webcams.

10 Elder

 • 

44.3K Posts

October 19th, 2018 11:00


@Herman LT wrote:

Aren't most webcams hackable? I read somewhere that the only safe way to not have someone spy on you is disconnect the webcam when not using it and taping over uilt-in webcams.


Except those webcams are mainly used as outdoor security cams, nanny cams, and/or activated inside when leaving the house/building. And the real issue is they could allow access to other devices your network, not just because they might see you.

Disconnecting them would certainly protect from a hacker trying to gain access to your network that way, but that makes the cams useless, and covering them with tape won't stop a hacker from accessing your network via the cam's hardware/software, even if they can't see you.

No Events found!

Top