HomeSecurityNow Hacking on Canon EOS-1DX Camera

Now Hacking on Canon EOS-1DX Camera

Imagine you're a journalist after a press conference. You're trying to remotely upload the photos you just took with your high-end camera from your hotel or a coffee shop with a Wi-Fi connection.

So far so good, but hackers could be lurking. They could steal your photos, upload their own to the camera, or maybe they could use the device to spy on someone.

It's not a James Bond movie, nor a science fiction script. According to Daniel Mende, this is a very likely scenario.

In a presentation at Hack in the Box 2013, a security conference held in Amsterdam, an expert demonstrated that there are design flaws in Canon EOS-1DX, and possibly other models or from other vendors, that can be exploited for a wide range of attacks.

canon-eos-1dx

High-end cameras, such as the Canon EOS-1DX, allow users to easily transfer photos they take to the Web via a built-in Ethernet port or via the Wireless File Transmitter (WFT).

According to Mende, most journalists from major media outlets such as Reuters currently use the Canon EOS-1DX, which means there are many potential targets.

How do attacks work?

The Canon EOS-1DX has four ways to connect to the Web: you can upload files using FTP, or DLNA (Digital Living Network Alliance), it has a built-in webserver, and the EOS utility. Mende managed to identify a way to hack into each of these.

For example, the FTP Upload function can be used to upload photos to a server configured on the camera.

However, since the data is not encrypted, it can be easily detected. This includes uploaded photos or even FTP credentials since they are transmitted in plain text.

For DLNA functionality, UPnP is used to find HTTP and XML to use for accessing media. The problem is that there is no authentication system and there are no restrictions, so any user with a DLNA client can download the photos.

The WFT server function, or built-in webserver, allows users to view and download photos remotely via their browser. The issue is that security is again lacking and credentials can be easily extracted.

The session cookies used in WFT operate 20 minutes after the session ends.

EOS Utility, on the other hand, can be exploited for even more interesting things. Mende discovered that EOS Utility – which users install on their computers to control all the non-manual functions of their camera remotely – can allow an attacker to access the camera and use it for live streaming!!

When EOS Utility is running, the camera will need to connect to the software via multicast Domain Name System (mDNS).

For this attack method, the attacker attempts to “listen” to the mDNS, and deobfuscate the device to obtain credentials. The attacker would then have to log out the already logged in user, as the camera only allows one login.

The final step is to connect to the camera via PTP/IP (Picture Transfer Protocol). Once this is done, the device is at the mercy of the attacker.

The full presentation by Daniel Mende, with additional technical details, is available here. (PDF)

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS