November 2017
Intermediate to advanced
452 pages
11h 46m
English
|
Threat description |
Attacker could remotely view camera feeds without authorization |
|
Threat target |
DVR customers, protocols, and applications. |
|
Attack techniques |
Acquire credentials or API calls to view cameras without authenticated access. Attacker can harvest session identifiers to hijack sessions to enable remote viewing of camera feeds. Attackers can socially engineer users into accessing their DVR feed. Attackers can exploit vulnerable clear text RTSP streams to access video feeds with tools such as Cameradar (https://hub.docker.com/r/ullaakut/cameradar/). |
|
Countermeasures |
Enforce multifactor authentication and make use of encrypted RTSP or SRTP streams. |
Read now
Unlock full access