{"id":6939,"date":"2017-03-10T13:17:31","date_gmt":"2017-03-10T21:17:31","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/03\/10\/news-730\/"},"modified":"2017-03-10T13:17:31","modified_gmt":"2017-03-10T21:17:31","slug":"news-730","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/03\/10\/news-730\/","title":{"rendered":"Dahua, Hikvision IoT Devices Under Siege"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Fri, 10 Mar 2017 20:07:51 +0000<\/strong><\/p>\n<p><strong>Dahua<\/strong>, the world&#8217;s second-largest maker of &#8220;Internet of Things&#8221; devices like security cameras and digital video recorders (DVRs), has shipped a software update that closes a gaping security hole in a broad swath of its products. The vulnerability allows anyone to bypass the login process for these devices and gain remote, direct control over vulnerable systems. Adding urgency to the situation, there is now code available online that allows anyone to exploit this bug and commandeer a large number of\u00a0IoT devices.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-38431\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/03\/dahua.png\" alt=\"dahua\" width=\"254\" height=\"219\" \/>On March 5, a security researcher named <strong>Bashis<\/strong> posted to <a href=\"http:\/\/seclists.org\/fulldisclosure\/2017\/Mar\/7\" target=\"_blank\">the Full Disclosure security mailing list<\/a> exploit code for an embarrassingly simple flaw in the way many Dahua security cameras and DVRs handle authentication. These devices are designed to be controlled by a local Web server that\u00a0is accessible via a Web browser.<\/p>\n<p>That server requires the user to enter a username and password, but Bashis found he could force all affected devices to cough up their usernames and a simple hashed value of the password. Armed with this information, he could effectively &#8220;pass the hash&#8221; and the corresponding username right back to the Web server and be admitted access to the device settings page. From there, he could add users and install or modify the device&#8217;s software. From Full Disclosure:<\/p>\n<blockquote>\n<p>&#8220;This is so simple as:<br \/> 1. Remotely download the full user database with all credentials and permissions<br \/> 2. Choose whatever admin user, copy the login names and password hashes<br \/> 3. Use them as source to remotely login to the Dahua devices<\/p>\n<p>&#8220;This is like a damn Hollywood hack, click on one button and you are in&#8230;&#8221;<\/p>\n<\/blockquote>\n<p>Bashis said he was so appalled at the discovery that he labeled it an\u00a0apparent &#8220;backdoor&#8221; &#8212; an undocumented means of accessing an electronic device that often only the vendor\u00a0knows about. Enraged, Bashis decided to publish his exploit code without first notifying Dahua. Later, Bashis said he changed his mind after being contacted by the company and agreed\u00a0to remove his code from the online posting.<\/p>\n<p>Unfortunately, that ship may have already sailed. Bashis&#8217;s exploit code already has been copied in several other places online as of this publication.<\/p>\n<p>Asked why he took down his exploit code, Bashis said in an interview with KrebsOnSecurity that &#8220;The hack is too simple, way too simple, and now I want Dahua&#8217;s users to get patched firmware\u2019s before they will be victims to some botnet.&#8221;<\/p>\n<p>In an advisory published March 6, Dahua said it has identified nearly a dozen of its products that are vulnerable, and that further review may reveal additional models also have this flaw. The company is urging users to <a href=\"http:\/\/us.dahuasecurity.com\/en\/us\/Security-Bulletin_030617.php\" target=\"_blank\">download and install the newest firmware updates<\/a> as soon as possible. Here are the models known to be affected so far:<\/p>\n<p>DH-IPC-HDW23A0RN-ZS<br \/> DH-IPC-HDBW23A0RN-ZS<br \/> DH-IPC-HDBW13A0SN<br \/> DH-IPC-HDW13A0SN<br \/> DH-IPC-HFW13A0SN-W<br \/> DH-IPC-HDBW13A0SN<br \/> DH-IPC-HDW13A0SN<br \/> DH-IPC-HFW13A0SN-W<br \/> DHI-HCVR51A04HE-S3<br \/> DHI-HCVR51A08HE-S3<br \/> DHI-HCVR58A32S-S2<\/p>\n<p>It&#8217;s not clear exactly how many devices worldwide may be vulnerable. Bashis says that&#8217;s a difficult question to answer, but that he &#8220;wouldn&#8217;t be surprised if 95 percent of Dahua&#8217;s product line has the same problem,&#8221; he said. &#8220;And also possible their OEM clones.&#8221;<\/p>\n<p>Dahua has not yet responded to my questions or request for comment. I&#8217;ll update that here if things change on that front.<\/p>\n<p>This is the second time in a week that a major Chinese IoT firm has urgently warned its\u00a0customers to update the firmware on their devices. For weeks, experts have been warning that there are signs of attackers exploiting an unknown backdoor or equally serious vulnerability in cameras and DVR devices made by IoT giant <strong>Hikvision<\/strong>.<span id=\"more-38363\"><\/span><\/p>\n<p>Writing for video surveillance publication <strong>IPVM<\/strong>, <strong>Brian Karas<\/strong> <a href=\"https:\/\/ipvm.com\/reports\/hik-default-hack\" target=\"_blank\">reported on March 2<\/a> that he was hearing from multiple Hikvision security camera and DVR users who suddenly were locked out of their devices and had new &#8220;system&#8221; user accounts added without their permission.<\/p>\n<p>Karas said the devices in question all were set up to be remotely accessible over the Internet, and were running with the default credentials (12345). Karas noted that there don&#8217;t appear to be any Hikvision devices sought out by the <a href=\"https:\/\/krebsonsecurity.com\/?s=mirai&amp;x=0&amp;y=0\" target=\"_blank\">Mirai worm<\/a> &#8212; the <a href=\"https:\/\/krebsonsecurity.com\/2016\/10\/source-code-for-iot-botnet-mirai-released\/\" target=\"_blank\">now open-source malware<\/a>\u00a0that is being used to enslave IoT devices in a botnet for launching crippling online attacks (in contrast, Dahua&#8217;s products are <a href=\"https:\/\/krebsonsecurity.com\/2016\/10\/who-makes-the-iot-things-under-attack\/\" target=\"_blank\">hugely represented in the list of systems being sought out by the Mirai worm<\/a>.)<\/p>\n<p>In addition, a\u00a0programmer who has long written and distributed custom firmware for Hikvision devices claims he&#8217;s found a backdoor\u00a0in &#8220;many popular Hikvision products that makes it possible to gain full admin access to the device,&#8221; <a href=\"https:\/\/ipcamtalk.com\/threads\/backdoor-found-in-hikvision-cameras.17523\/\" target=\"_blank\">wrote<\/a> the user &#8220;Montecrypto&#8221; on the IoT forum <strong>IPcamtalk<\/strong> on Mar. 5. &#8220;Hikvision gets two weeks to come forward, acknowledge, and explain why the backdoor is there and when it is going to be removed. I sent them an email. If nothing changes, I will publish all details on March 20th, along with the firmware that disables the backdoor.&#8221;<\/p>\n<p>According to IPVM&#8217;s Karas, Hikvision has not acknowledged an unpatched backdoor or any other equivalent weakness in its product. But on Mar. 2, the company issued a reminder to its integrator partners about the need to be updated to the latest firmware.<\/p>\n<div id=\"attachment_38430\" style=\"width: 573px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-38430\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/03\/hikvisionstatement.png\" alt=\"A special bulletin issued Mar. 2, 2017 by Hikvision. Image: IPVM\" width=\"563\" height=\"484\" \/><\/p>\n<p class=\"wp-caption-text\">A special bulletin issued Mar. 2, 2017 by Hikvision. Image: IPVM<\/p>\n<\/div>\n<p>&#8220;Hikvision has determined that there is a scripted application specifically targeting Hikvision NVRs and DVRs that meet the following conditions: they have not been updated to the latest firmware; they are set to the default port, default user name, and default password,&#8221; the company&#8217;s statement reads. &#8220;Hikvision has required secure activation since May of 2015, making it impossible for our integrator partners to install equipment with default settings. However, it was possible, before that date, for integrators to install NVRs and DVRs with default settings. Hikvision strongly recommends that our dealer base review the security levels of equipment installed prior to June 2015 to ensure the use of complex passwords and upgraded firmware to best protect their customers.&#8221;<\/p>\n<h4>ANALYSIS<\/h4>\n<p>I don&#8217;t agree with Bashis&#8217;s conclusion that the Dahua flaw was intentional; It appears that the makers of these products simply did not invest much energy, time or money in building security into the software. Rather, security is clearly an afterthought that is bolted on afterwards with these devices, which is why nobody should trust them.<\/p>\n<p>The truth is that the software that runs on a whole mess of these security cameras and DVRs is very poorly written, and probably full of more security holes just like the flaw Dahua users are dealing with right now. To hope or wish otherwise given what we know about the history of these cheap electronic devices seems sheer folly.<\/p>\n<p>In December, KrebsOnSecurity <a href=\"https:\/\/krebsonsecurity.com\/2016\/12\/researchers-find-fresh-fodder-for-iot-attack-cannons\/\" target=\"_blank\">warned<\/a> that many Sony security cameras contained a backdoor that can only be erased by updating the firmware on the devices.<\/p>\n<p>Some security experts maintain that these types of flaws can&#8217;t be easily exploited when the IoT device in question is behind a firewall. But that advice just doesn&#8217;t hold water for today&#8217;s IoT cameras and DVRs. For one thing, a great many security cameras and other IoT devices will punch a hole in your firewall straight away without your permission, using a technology called <a href=\"https:\/\/en.wikipedia.org\/wiki\/Universal_Plug_and_Play\" target=\"_blank\">Universal Plug-and-Play<\/a> (UPnP).<\/p>\n<p>In other cases, IoT products are incorporating <a href=\"https:\/\/krebsonsecurity.com\/2016\/02\/this-is-why-people-fear-the-internet-of-things\/\" target=\"_blank\">peer-to-peer (P2P) technology that cannot be turned off<\/a> and exposes users to even greater threats. \u00a0In that same December 2016 story referenced above, I cited research from security firm <strong>Cybereason<\/strong>, which found at least two previously unknown security flaws in dozens of IP camera families that are white-labeled under a number of different brands (and some without brands at all).<\/p>\n<p>&#8220;Cybereason\u2019s team found that they could easily exploit these devices even if they <em>were<\/em> set up behind a firewall,&#8221; that story noted. &#8220;That\u2019s because all of these cameras ship with a factory-default peer-to-peer (P2P) communications capability that enables remote &#8216;cloud&#8217; access to the devices via the manufacturer\u2019s Web site \u2014 provided a customer visits the site and provides the unique camera ID stamped on the bottom of the devices.&#8221;<\/p>\n<p>The story continued:<\/p>\n<p>&#8220;Although it may seem that attackers would need physical access to the vulnerable devices in order to derive those unique camera IDs, Cybereason\u2019s principal security researcher <strong>Amit Serper<\/strong> said the company figured out a simple way to enumerate all possible camera IDs using the manufacturer\u2019s Web site.&#8221;<\/p>\n<p>My advice? Avoid the P2P models like the plague. If you have security cameras or DVR devices that are connected to the Internet, make sure they are up to date with the latest firmware. Beyond that, consider completely blocking external network access to the devices and enabling a VPN if you truly need remote access to them.<\/p>\n<p><a href=\"https:\/\/www.howtogeek.com\/221001\/how-to-set-up-your-own-home-vpn-server\/\" target=\"_blank\">Howtogeek.com<\/a> has a decent tutorial on setting up your own VPN to enable remote access to your home or business network; on picking a decent router that supports VPNs; and installing custom firmware like DD-WRT on the router if available (because, as we can see, stock firmware usually is some horribly insecure and shoddy stuff).<\/p>\n<p>If you\u2019re curious about an IoT device you purchased and what it might do after you\u00a0connect it to a network,\u00a0the information is there if you know how and where to look. <a href=\"http:\/\/lifehacker.com\/how-to-tap-your-network-and-see-everything-that-happens-1649292940\" target=\"_blank\">This Lifehacker post<\/a> walks through some of the basic software tools and steps that even a novice can follow to learn more about what\u2019s going on across a local network.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2017\/03\/dahua-hikvision-iot-devices-under-siege\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/03\/dahua.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Fri, 10 Mar 2017 20:07:51 +0000<\/strong><\/p>\n<p>Dahua, the world&#8217;s second-largest maker of &#8220;Internet of Things&#8221; devices like security cameras and digital video recorders (DVRs), has shipped a software update that closes a gaping security hole in a broad swath of its products. The vulnerability allows anyone to bypass the login process for these devices and gain remote, direct control over vulnerable systems. Adding urgency to the situation, there is now code available online that allows anyone to exploit this bug and commandeer a large number of IoT devices.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[11601,11602,11603,11604,11605,11606,11607,11608,11609,11610,10644,11611,11612],"class_list":["post-6939","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-amit-serper","tag-bashis","tag-cybereason","tag-dahua-backdoor","tag-dh-ipc-hdbw13a0sn","tag-dh-ipc-hdbw23a0rn-zs","tag-dh-ipc-hdw13a0sn","tag-dh-ipc-hdw23a0rn-zs","tag-dh-ipc-hfw13a0sn-w","tag-hikvision","tag-other","tag-p2p","tag-upnp"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6939","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6939"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6939\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6939"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6939"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6939"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}