4 ms·
Exactly. The best-selling home IP camera on Amazon [1], from a Chinese company, has the following "features": - Default Wifi setup is done through their phone
by sittonOK 10y ago
Exactly. The best-selling home IP camera on Amazon [1], from a Chinese company, has the following "features":
- Default Wifi setup is done through their phone app through the "cloud" (let me tell you how much I trust that one)
- Has a webserver listening on port 80 with default u:p admin:admin (to be fair, their instructions are clear that you should change it, but it's not a mandatory part of the setup process)
- Has an RTSP server listening on port 554
- All of this a disaster waiting to happen because of UPnP (ugh, how many home routers have this enabled...)
- Sends outbound TCP traffic to amcrestcloud.com and amcrestview.com every few seconds (cannot be disabled on the device) [2]
- Sends a continuous stream of UDP data to 52.91.189.219:8800 (cannot be disabled on the device) [2]
The only way to prevent this device from a calling a CNC server is with a hardware firewall or an isolated LAN segment (I suppose this idea isn't at all specific to this camera). I bet fewer than 0.01% of their customers do that.
[1] https://www.amazon.com/Amcrest-IP2M-841-1920TVL-Wireless-Camera/dp/B0145OQTPG/ https://www.amazon.com/Amcrest-IP2M-841-1920TVL-Wireless-Cam...
[2]
01:41:17 firewall: [CamVLAN-WAN-20-Reject] SRC=CAM-IP DST=54.87.129.131 LEN=60 PROTO=TCP DPT=12366
01:41:20 firewall: [CamVLAN-WAN-20-Reject] SRC=CAM-IP DST=54.158.250.32 LEN=60 PROTO=TCP DPT=443
01:41:27 firewall: [CamVLAN-WAN-20-Reject] SRC=CAM-IP DST=52.91.189.219 LEN=295 PROTO=UDP DPT=8800
01:41:27 firewall: [CamVLAN-WAN-20-Reject] SRC=CAM-IP DST=52.91.189.219 LEN=295 PROTO=UDP DPT=8800
01:41:27 firewall: [CamVLAN-WAN-20-Reject] SRC=CAM-IP DST=52.91.189.219 LEN=295 PROTO=UDP DPT=8800
01:41:28 firewall: [CamVLAN-WAN-20-Reject] SRC=CAM-IP DST=52.91.189.219 LEN=295 PROTO=UDP DPT=8800
01:41:28 firewall: [CamVLAN-WAN-20-Reject] SRC=CAM-IP DST=52.91.189.219 LEN=295 PROTO=UDP DPT=8800
01:41:29 firewall: [CamVLAN-WAN-20-Reject] SRC=CAM-IP DST=52.91.189.219 LEN=295 PROTO=UDP DPT=8800
- mixedCase 10y ago> All of this a disaster waiting to happen because of UPnP (ugh, how many home routers have this enabled...) The problem is shitty UPnP implementations rather than UPnP itself. If you're pwned you are fucked one way or another, if an online device is vulnerable it's going to be vulnerable wether it exposes itself through UPnP or if it's manually forwarded. And in the end if you don't like it and want to do your own manual forwarding in a home router, you're free to disable it.