US security expert says surveillance cameras can be hacked

Published June 18, 2013
A security camera sits on a building in New York City March 6, 2008. — Reuters Photo
A security camera sits on a building in New York City March 6, 2008. — Reuters Photo

BOSTON, Mon Jun 17, 2013 - A US security expert says he has identified ways to remotely attack high-end surveillance cameras used by industrial plants, prisons, banks and the military, something that potentially would allow hackers to spy on facilities or gain access to sensitive computer networks.

Craig Heffner, a former software developer with the National Security Administration who now works for a private security firm, said he discovered the previously unreported bugs in digital video surveillance equipment from firms including Cisco Systems Inc, D-Link Corp and TRENDnet.

"It's a significant threat," he said in an interview.

"Somebody could potentially access a camera and view it. Or they could also use it as a pivot point, an initial foothold, to get into the network and start attacking internal systems."

He plans to demonstrate techniques for exploiting these bugs at the Black Hat hacking conference, which starts July 31 in Las Vegas. (here)

Heffner, who now works as a vulnerability researcher with a firm known as Tactical Network Solutions in Columbia, Maryland, said that he has discovered hundreds of thousands of surveillance cameras that can be accessed via the public Internet.

He said he has figured out a real-life version of the familiar "Hollywood-style" attack that has become a fixture in action films. He can freeze a picture on a surveillance camera to help thieves break into facilities without detection.

Heffner said that he has not discussed his research with the camera makers and does not plan to do so ahead of his presentation at the hacking conference.

Cisco, D-Link and TRENDnet said they would take any appropriate action that might be needed to secure their equipment after the Black Hat presentation.

Heffner's presentation is one of more than 100 talks at the annual gathering, which is expected to attract some 6,500 security professionals who will learn about the growing threat that hackers pose to businesses, consumers and national security.

Other talks will explore threats to Microsoft Windows and Apple systems, mobile phone networks, medical devices and systems that control industrial plants.

All research presented at the conference is vetted by a review board of 22 security experts.

Opinion

Enter the deputy PM

Enter the deputy PM

Clearly, something has changed since for this step to have been taken and there are shifts in the balance of power within.

Editorial

All this talk
Updated 30 Apr, 2024

All this talk

The other parties are equally legitimate stakeholders in the country’s political future, and it must give them due consideration.
Monetary policy
30 Apr, 2024

Monetary policy

ALIGNING its decision with the trend in developed economies, the State Bank has acted wisely by holding its key...
Meaningless appointment
30 Apr, 2024

Meaningless appointment

THE PML-N’s policy of ‘family first’ has once again triggered criticism. The party’s latest move in this...
Weathering the storm
Updated 29 Apr, 2024

Weathering the storm

Let 2024 be the year when we all proactively ensure that our communities are safeguarded and that the future is secure against the inevitable next storm.
Afghan repatriation
29 Apr, 2024

Afghan repatriation

COMPARED to the roughshod manner in which the caretaker set-up dealt with the issue, the elected government seems a...
Trying harder
29 Apr, 2024

Trying harder

IT is a relief that Pakistan managed to salvage some pride. Pakistan had taken the lead, then fell behind before...