Telecom Tidbits
Jared's Network and Security Blog
  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links

Foscam: A Chinese Disaster

June 8, 2017 Jared Hall General

Foscam, a Chinese manufacturer of IP Cameras, is a good example of what’s bad with the Internet of Things.   They also demonstrate that low-cost *is* low-security.  If you have a Foscam product, you might as well put a sign up saying, “Hack Me.  I don’t care.”

F-Secure released a report earlier this week detailing critical flaws in the Opticam i5 HD and the Foscam C2 series of products.  Despite being notified several months ago of the problems (18 vulnerabilities total), Foscam has not fixed the problems.

  1. Non-random default credentials for web user interface account
  2. FTP server account uses empty password
  3. FTP server account has a hard-coded password
  4. Configuration back-up file is protected by hard-coded credentials
  5. Hidden hard-coded credentials for web user interface
  6. Hidden Telnet functionality
  7. Remote command injection in User Add
  8. Remote command injection in /mnt/mtd/boot.sh via ProductConfig.xml
  9. Unauthenticated Remote Command Injection via Anonymous ONVIF SetDNS
  10.  Incorrect permission assignment for startup script: /mnt/mtd/boot.sh
  11.  Incorrect permission assignment for directory: /mnt/mtd/app
  12.  Administrator Credential Disclosure via Anonymous ONVIF GetStreamUri
  13.  Unauthenticated Reboot via Anonymous ONVIF SystemReboot
  14.  Firewall only protects ports 88 and 443
  15.  Missing restriction of multiple login attempts
  16.  Denial of service of the RTSP video feed
  17.  Unauthenticated Persistent XSS via Anonymous ONVIF SetHostname
  18.  Buffer overflow in ONVIF SetDNS

Foscam cameras are re-branded by other companies under the names:

ScreenShot266

Foscam camera deployment density:

ScreenShot267

As F-Secure surmises, it is likely that many of these bugs exist in most of Foscam‘s product lines.

F-Secure’s detailed write-up can be found here.  A locally cached copy is here.

Caveat emptor

« Google Chrome 59 Released » Top Attacking Countries: May 2017

Tools & Downloads

Download Center

Categories

Good Reads (PDF)

Recent Posts

  • PayPal Woes and Degenerative AI
  • A Pathetic Defense of Julian Assange
  • Damned if you do. Damned if you don’t.
  • ProtonMail? Not Worth an Electron!
  • Give it a REST: Serious WordPress Bugs
$
Select Payment Method
Personal Info

Donation Total: $20.00

↑

  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links
Temporal Based Intelligence © 2017