ESET vulnerability in cam allows tracking of the owner

According to ESET's latest survey on IoT, the D-Link DCS-2132L cloud camera has many security vulnerabilities that allow unauthorized persons to access. According to the manufacturer, some of the vulnerabilities have been repaired, but there are still problems.ESET

"The most serious problem with the D-Link DCS-2132L cloud camera is unencrypted video streaming. It runs without encryption on both connections - between the camera and the cloud and between the cloud and the application that the user uses. As a result, it provides ground for man-in-the-middle attacks (MitM) and allows attackers to spy on video footage of victims, "explains Milan Fránik, a researcher at the ESET Research Lab in Bratislava.

Discover more articles in search results.

Another serious problem that was detected in the camera was hidden in the myDlink services plug-in for a web browser. This is one of the alternative tracking applications available to the user. Mobile apps are available, but they were not part of ESET's research.

This particular plug-in manages the creation of TCP connection and live video playback in the user's browser but is also responsible for promoting requests for streaming video and audio data via a connection that listens to a port has been opened in localhost.

"The vulnerability of the plug-in could have serious security implications as it allowed attackers to replace legitimate firmware with their own counterfeit or back-door version," notes Fránik.

ESET has reported all the vulnerabilities found in the manufacturer. Since then, some of the vulnerabilities - mainly in the myDlink plug-in - have been fixed and patched, but there are still issues with the non-encrypted transmission.

For a more detailed description of vulnerabilities and possible attack scenarios, read the "D-Link camera vulnerability allows attackers to tap into the video stream"On ESET's site, WeLiveSecurity.com.

______________


Google preferences

Leave a Comment

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).