November 2017
Intermediate to advanced
452 pages
11h 46m
English
|
Threat description |
Attacker could remotely take over the DVR system |
|
Threat target |
DVR customers, DVR network processes, DVR applications. |
|
Attack techniques |
Attacker intercept wireless communication, API communication, and/or network protocol communications for credentials or session cookies. Attackers can social engineer users into accessing their DVR via spoofed user interfaces or exploiting application vulnerabilities to add user accounts using cross-site request forgery (CSRF). |
|
Countermeasures |
DVR locks out users for 30 mins if failed logins are attempted or too many requests are sent at one time. |
Read now
Unlock full access