<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>IP-Camera on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/ip-camera/</link>
    <description>Recent content in IP-Camera on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 30 Nov 2016 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/ip-camera/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Research Diary: IP-Cameras Part 2</title>
      <link>https://insinuator.net/2016/11/research-diary-ip-cameras-part-2/</link>
      <pubDate>Wed, 30 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/research-diary-ip-cameras-part-2/</guid>
      <description>&lt;p&gt;Hi everybody,&lt;br&gt;&#xA;This is the second entry in our research diary on IP cameras. If you haven’t done so yet, you should read the first entry in advance. This time we focused more on analysis and exploitation.&lt;/p&gt;&#xA;&lt;h2 id=&#34;another-entry-vector&#34;&gt;&lt;a href=&#34;#another-entry-vector&#34;&gt;&lt;/a&gt;Another entry vector&lt;/h2&gt;&#xA;&lt;p&gt;After running a vulnerability scan on both devices, it was revealed that the M1033 has multiple buffer overflow vulnerabilities (CVE-2012-5958 to CVE-2012-5965), which are readily exploitable via Metasploit. This gave us another shell (in addition to the root shell mentioned in the last post), though this time it was not a root shell. By using the &lt;em&gt;find&lt;/em&gt; command, we searched for executables having the &lt;em&gt;setuid&lt;/em&gt; or &lt;em&gt;setgid&lt;/em&gt; bit set. We hoped to use one of those to escalate privileges. To do so yourself add the parameter &lt;em&gt;-perm -4000&lt;/em&gt; to &lt;em&gt;find&lt;/em&gt; and it will search for files having the setuid bit set. If you try that on your own unix-like device, for example it should yield &lt;em&gt;/bin/passwd&lt;/em&gt; which is perfectly reasonable as you’re able to change your password without being root.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research Diary: IP-Cameras</title>
      <link>https://insinuator.net/2016/11/research-diary-ip-cameras/</link>
      <pubDate>Tue, 22 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/research-diary-ip-cameras/</guid>
      <description>&lt;p&gt;As you probably know we perform research on a regular basis at ERNW. This post is the first entry on our – Benjamin’s and Pascal’s – research diary. You might already have seen &lt;a href=&#34;https://insinuator.net/2016/10/setting-up-a-research-environment-for-ip-cameras/&#34;&gt;Oliver’s post on setting up an research environment&lt;/a&gt; or Brian’s posts on IoT botnets (&lt;a href=&#34;https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/&#34;&gt;here&lt;/a&gt;). With that in mind we want to take a look at one of the market leaders for network camera equipment: AXIS.&lt;/p&gt;&#xA;&lt;p&gt;At first we’d like to give a quick overview of our research objects. We bought two cameras, an AXIS M1033-W and an AXIS M3005-V. The M1033’s description states that it is for “small business, hotels, residences and more”. The M3005 has a typical dome design and was actually seen in some customer environments during projects this year.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
