ISC StormCast for Tuesday, April 30th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 April 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, April 30th, 2019 edition of the Sandtonet Storm Center's Stormcast. |
| 0:08.3 | My name is Johannes Ulrich and I'm quoting from Augusta, Georgia. |
| 0:14.8 | One feature in modern consumer-crate firewalls that probably made the biggest difference when it comes to |
| 0:22.9 | protecting the various devices that users are connecting to the network is NAT. Now, Nat never really |
| 0:30.2 | meant to be a security feature. That's a reasonable good job in preventing so of these random, |
| 0:36.3 | unsolicited, inbound connections. |
| 0:38.7 | But it doesn't help at all, of course, is outbound connections. |
| 0:43.2 | And apparently this is a problem again with security cameras in particular, those that |
| 0:49.9 | support the iLink p2p protocol. |
| 0:53.2 | I link p2p essentially instructs the camera to connect outbound to a specific server that is |
| 1:00.8 | associated with that cameras manufacture. |
| 1:04.8 | And if you are owning one of these cameras, the only thing you need to know in order to connect |
| 1:09.9 | back to your camera is a unique |
| 1:12.3 | UID, which is essentially a serial number. |
| 1:16.4 | Problem of course is these UIDs are predictable, so an attacker could easily scan for security |
| 1:23.7 | cameras by connecting to a particular manufacturer's server and just essentially |
| 1:28.5 | prude for us different serial numbers. Security researcher Paul Mara Pise took a quick look at |
| 1:36.1 | some of these servers and he discovered about 2 million connected devices and he was able to connect |
| 1:42.6 | to devices just knowing their serial number. |
| 1:46.0 | Now, you still need the username and password to actually log into the camera, |
| 1:50.0 | but of course if users aren't aware that the cameras are actually exposed in this manner, |
| 1:56.0 | they may not bother setting a strong password or changing defaults passwords at all. Also, the communication |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

