Malware security cameras are sold to Amazon

An independent security researcher, Mike Olsen, discovered last week that Amazon CCTV cameras with pre-installed malware were sold to Amazon.

malware-cameras Amazon

The discovery was made when he visited a friend of his to help him install and customize a kit with external security cameras he had just bought. His friend's overall purchase was six CCTV PoE cameras (Sony's Power Over Ethernet), a DVR, and a PoE switch. Everyone bought it from a reputable store Amazon, which had good customer reviews.

While trying to gain access to the admin panel of the cameras, Mr Olsen discovered that the settings table was empty.

His first thought was that there is one με τα CSS αρχεία που εμποδίζει να εμφανίζονται οι ρυθμίσεις, οπότε άνοιξε τον κώδικα της σελίδας του browser για να δει την ανάπτυξη του προγράμματος και έκπληκτος διαπίστωσε ότι υπήρχε ένα iframe that loaded at the bottom of the page, and retrieved content from the Brenz.pl website

Doing a quick search on Google revealed one blog post from 2011 which described how the domain Brenz.pl was used in .

Obviously, the domain is still active and is used to host dangerous trojans that will come down to the computers of infected users.

That meant that purchased kit with surveillance cameras could be at any time infected with malware, if the operator Brenz.pl decided to send the malicious code to his DVR through the hidden iframe.

But if the Breza.pl domain was already in the kit firmware, then there might be other more malicious malware in its code.

So we recommend paying special attention if you want to buy this product

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).