HomeSecurityHackers turn Google's Dropcam into a Spycam

Hackers turn Google's Dropcam into a Spycam

Hackers could serve up fake video by injecting  into the popular home surveillance kit Dropcam. They could then use the system to attack networks or carry out a robbery, researchers Patrick Wardle and Colby Moore report.

dropcam

The attacks require attackers to have physical access to the devices, and the exploits use the Heartbleed vulnerability.

Dropcam is a video surveillance platform that was acquired by Google's Nest Labs last month for $555 million.

Wardle (@patrickwardle) and Moore (@colbymoore) of California-based security firm Synack have reverse-engineered Dropcam hardware and software to implant malware into the devices, allowing them to attack home and corporate networks.

“If someone has physical access, it’s game over,” Wardle told DarkReading.

“The camera is vulnerable to client-side Heartbleed attacks. You could spoof the Dropcam DNS server.”

The duo will describe the Dropcam vulnerability during their talk, " Optical surgery; Implanting a Dropcam," at the upcoming DEF CON 22 conference in Las Vegas next month.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS