2017 m. kovo 11 d., šeštadienis

Multiple vulnerabilities found in Wireless IP Camera (P2P) WIFICAM cameras and vulnerabilities in GoAhead Part 2

 VCatch Other
    VCatch VC-MIC720HK
    Valtronics IP
    Valtronics Other
    Vandesc IP900
    Vantech Other
    Vantech PTZ
    Videosec+Security IPC-103
    Videosec+Security IPP-105
    Vimicro Other
    Vitek+CCTV Other
    Vstarcam 7823
    Vstarcam C-7824WIP
    Vstarcam C-7833WIP-X4
    Vstarcam C-7833wip
    Vstarcam C-7837WIP
    Vstarcam C-7838WIP
    Vstarcam C50S
    Vstarcam C7816W
    Vstarcam C7824WIP
    Vstarcam C782WIP
    Vstarcam C7842WIP
    Vstarcam C93
    Vstarcam C=7824WIP
    Vstarcam Cam360
    Vstarcam F-6836W
    Vstarcam H-6837WI
    Vstarcam H-6837WIP
    Vstarcam H-6850
    Vstarcam H-6850WIP
    Vstarcam H-6850wip
    Vstarcam ICAM-608
    Vstarcam Other
    Vstarcam T-6835WIP
    Vstarcam T-6836WTP
    Vstarcam T-6892wp
    Vstarcam T-7815WIP
    Vstarcam T-7833WIP
    Vstarcam T-7833wip
    Vstarcam T-7837WIP
    Vstarcam T-7838WIP
    Vstarcam T-7892WIP
    Vstarcam T6836WTP
    Vstarcam T7837WIP
    Vstarcam c7815wip
    Vstarcam c7833wip
    Vstarcam c7850wip
    Wanscam 00D6FB01980F
    Wanscam 106B
    Wanscam 118
    Wanscam 541-W
    Wanscam 543-W
    Wanscam 790
    Wanscam AJ-C0WA-198
    Wanscam AJ-C0WA-B106
    Wanscam AJ-C0WA-B116
    Wanscam AJ-C0WA-B168
    Wanscam AJ-C0WA-B1D8
    Wanscam AJ-C0WA-C0D8
    Wanscam AJ-C0WA-C116
    Wanscam AJ-C0WA-C126
    Wanscam AJ-C2WA-B118
    Wanscam AJ-C2WA-C116
    Wanscam AJ-C2WA-C118
    Wanscam AJ-C2WA-C198
    Wanscam AJ-COWA-B1D8
    Wanscam AJ-COWA-C116
    Wanscam AJ-COWA-C126
    Wanscam AJ-COWA-C128
    Wanscam AW00004J
    Wanscam B1D8-1
    Wanscam C-118
    Wanscam C-126
    Wanscam Colour
    Wanscam FI-18904w
    Wanscam FR-4020A2
    Wanscam FR4020A2
    Wanscam HD-100W
    Wanscam HW-0021
    Wanscam HW-0022
    Wanscam HW-0022HD
    Wanscam HW-0023
    Wanscam HW-0024
    Wanscam HW-0025
    Wanscam HW-0026
    Wanscam HW-0028
    Wanscam HW-0033
    Wanscam HW-0036
    Wanscam HW-0038
    Wanscam HW-0039
    Wanscam HW-22
    Wanscam HW0030
    Wanscam IP
    Wanscam JW-0001
    Wanscam JW-0003
    Wanscam JW-0004
    Wanscam JW-0004m
    Wanscam JW-0005
    Wanscam JW-0006
    Wanscam JW-0008
    Wanscam JW-0009
    Wanscam JW-0010
    Wanscam JW-0011
    Wanscam JW-0011l
    Wanscam JW-0012
    Wanscam JW-0018
    Wanscam JW-004
    Wanscam JW-009
    Wanscam JW-CD
    Wanscam JW000008
    Wanscam JW0009
    Wanscam JW001
    Wanscam JW0012
    Wanscam JW008
    Wanscam JWEV
    Wanscam JWEV-011777-NSRVV
    Wanscam JWEV-011921-RXSXT
    Wanscam JWEV-360171-BBEAC
    Wanscam JWEV-380096-CECDB
    Wanscam JWEV-PEPLOW
    Wanscam NBC-543W
    Wanscam NC-530
    Wanscam NC-541
    Wanscam NC-541/W
    Wanscam NC-541W
    Wanscam NC-541w
    Wanscam NC-543W
    Wanscam NCB-534W
    Wanscam NCB-540W
    Wanscam NCB-541W
    Wanscam NCB-541WB
    Wanscam NCB-543W
    Wanscam NCBL-618W
    Wanscam NCH-532MW
    Wanscam NCL-610W
    Wanscam NCL-612W
    Wanscam NCL-616W
    Wanscam NCL-S616W
    Wanscam Other
    Wanscam TG-002
    Wanscam WJ-0004
    Wanscam WX-617
    Wanscam Works
    Wanscam XHA-120903181
    Wanscam XHA-4020a2
    Wanscam __PTZ
    Wanscam chiOthernese
    Wanscam ip
    Wanscam jw0005
    Wanscam jw0010
    Wansview 541
    Wansview 625W
    Wansview MCM-627
    Wansview N540w
    Wansview NCB-534W
    Wansview NCB-541W
    Wansview NCB-541w
    Wansview NCB-543W
    Wansview NCB541W
    Wansview NCB545W
    Wansview NCL-610W
    Wansview NCL610D04
    Wansview NCL614W
    Wansview Other
    Wansview dcs543w
    Wansview nc543w
    Wardmay+CCTV WDM-6702AL
    Watch+bot+Camera resup
    WebcamXP Other
    WinBook Other
    WinBook T-6835
    WinBook T-6835WIP
    WinBook T-7838
    Winic NVT-530004
    Wise+Group Other
    X-Price Other
    X10 39A
    X10 AIRSIGHT
    X10 AirSight
    X10 Airsight
    X10 Jake
    X10 Other
    X10 XC-38A
    X10 XX-36A
    X10 XX-39A
    X10 XX-56A
    X10 XX-59A
    X10 XX-60
    X10 XX-69A
    X10 XX41Ahome
    XVision Other
    XXCamera 53100
    XXCamera 5330-E
    XXCamera Other
    XXCamera XXC-000723-NJFJD
    XXCamera XXC-092411-DCAFC
    XXCamera XXC-50100-H
    XXCamera XXC-50100-T
    XXCamera XXC-5030-E
    XXCamera XXC-53100-T
    XXCamera XXC52130
    Xin+Ling Other
    Yawcam Other
    Zilink Other
    Zmodo CMI-11123BK
    Zmodo IP-900
    Zmodo Other
    Zodiac+Security 909
    Zodiac+Security Other
    Zoneway NC638MW-P
    ZyXEL Other
    alexim Other
    alexim cam22822
    alias Other
    all+in+one+ Other
    all+in+one+ b1
    all-in-one Other
    allecto DVC-150IP
    apc Other
    asw-006 Other
    boh l
    bravo Other
    bush+plus BU-300WF
    ccam p2p
    china 8904W
    china HDIPCAM
    china IPCAM
    china Other
    china PTZCAM
    china np-02
    ciana+exports antani
    cina Other
    coolead L
    coolead L610WS
    dax Other
    denver IPC-320
    denver IPO-320
    e-landing 720p
    eScam QF100
    ebw Other
    epexis PIPCAMHD82
    epexis pipcam5
    esecure nvp
    geeya C602
    geeya P2P
    geeya c801
    hdcam Other
    homeguard 720P
    homeguard Other
    homeguard Wireless
    homeguard wifi
    iView ID002A
    iView Other
    insteon 75790
    insteon 75790wh
    insteon High
    insteon Other
    insteon Wireless
    iuk 5A1
    ivision hdwificam
    iwitness bullet
    jwt Other
    jyacam JYA8010
    kadymay KDM-6800
    kadymay KDM6702
    kadymay KMD-6800
    kadymay Other
    kang+xun xxc5030-t
    kines Other
    kiocong 1601
    kiocong 1602
    kiocong 1609
    kiocong Other
    kodak 201pl
    koicong 1601
    l+series CAM0758
    l+series CAM0760
    l+series Other
    l+series V100
    logan n8504hh
    meyetech 095475-caeca
    meyetech 188091-EFBAE
    meyetech Other
    meyetech WirelessCam
    micasaverde VistaCamSD
    pipcam HD17
    pni 941w
    pni IP451W
    pni IP541W
    pni IP941W
    pni IP951W
    pni Other
    pnp IP
    pnp Other
    semac Other
    skylink WC-300PS
    storex D-10H

Shodan lists 185 000 vulnerable cameras (
https://www.shodan.io/search?query=GoAhead+5ccc069c403ebaf9f0171e9517f40e41
).



## Details - Backdoor account

By default, telnetd is running on the camera.

    user@kali$ telnet 192.168.1.107
    Trying 192.168.1.107...
    Connected to 192.168.1.107.
    Escape character is '^]'.

    apk-link login: admin
    Password:

    telnet> q
    Connection closed.
    user@kali$


One backdoor account exists in the camera:

    root:$1$ybdHbPDn$ii9aEIFNiolBbM9QxW9mr0:0:0::/
root:/bin/sh



## Details - RSA key and certificates

The `/system/www/pem/ck.pem` contains an Apple certificate with a
private RSA key:


    / # cat /system/www/pem/ck.pem
    Bag Attributes
        friendlyName: Apple Production IOS Push Services: com.app.camera
        localKeyID: 74 9E 29 D0 6A 47 1B 35 AD D4 68 6D 46 D8 E2 37 C8 DA A1 9D
    subject=/UID=com.app.camera/CN=Apple Production IOS Push Services:
com.app.camera/OU=SQ6NNPBE2K/C=US
    issuer=/C=US/O=Apple Inc./OU=Apple Worldwide Developer
Relations/CN=Apple Worldwide Developer Relations Certification
Authority
    -----BEGIN CERTIFICATE-----
    [...]
    -----END CERTIFICATE-----
    Bag Attributes
        friendlyName: andrew
        localKeyID: 74 9E 29 D0 6A 47 1B 35 AD D4 68 6D 46 D8 E2 37 C8 DA A1 9D
    Key Attributes: <No Attributes>
    -----BEGIN RSA PRIVATE KEY-----
    [...]
    -----END RSA PRIVATE KEY-----



## Details - Pre-Auth Info Leak (credentials) within the GoAhead http server

The HTTP interface is provided by GoAhead. It allows 2 kinds of authentication:

- - htdigest authentication OR
- - authentication using credentials in URI (`?loginuse=LOGIN&?loginpas=PASS`).


By default, the web directory contains symbolic links to configuration
files (`system.ini` and `system-b.ini` contain credentials):

    /tmp/web # ls -la *ini
    lrwxrwxrwx    1 root     0               25 Oct 27 02:11
factory.ini -> /system/param/factory.ini
    lrwxrwxrwx    1 root     0               30 Oct 27 02:11
factoryparam.ini -> /system/param/factoryparam.ini
    lrwxrwxrwx    1 root     0               23 Oct 27 02:11
network-b.ini -> /system/www/network.ini
    lrwxrwxrwx    1 root     0               23 Oct 27 02:11
network.ini -> /system/www/network.ini
    lrwxrwxrwx    1 root     0               22 Oct 27 02:11
system-b.ini -> /system/www/system.ini
    lrwxrwxrwx    1 root     0               22 Oct 27 02:11
system.ini -> /system/www/system.ini
    /tmp/web #

1 komentaras:

  1. Very good post, thank you. I am surprised to find your website. I love to read more and more about home security appliances. I am looking for wireless burglar alarm with latest technology and features. Please gives your suggestions.

    AtsakytiPanaikinti