An independent security researcher, Mike Olsen, discovered last week that CCTV cameras were being sold on Amazon with pre-installed malware.
The discovery was made when he visited a friend to help him install and configure a kit of outdoor security cameras he had just purchased. His friend’s total purchase was six Sony PoE (Power Over Ethernet) CCTV cameras to be placed around the perimeter of the premises, a DVR, and a PoE switch. He bought all of them from a reputable Amazon store thathad good customer reviews.
While trying to access the cameras' admin panel, Mr. Olsen discovered that the settings panel was empty.
His first thought was that there was some problem with the CSS files that was preventing the settings from appearing, so he opened the browser page source to see the program's development and was surprised to find that there was a hidden iframe that was loading at the bottom of the page, retrieving content from the Brenz.pl website
A quick Google search revealed a blog post from 2011 that described how the Brenz.pl domain was used in malware distributions.
Apparently, the domain is still active and is used to host dangerous trojans, which will be downloaded to infected users' computers.
This meant that the newly purchased kit with surveillance cameras could be infected with malware at any time if the Brenz.pl operator decided to send the malicious code to his DVR via the hidden iframe.
But if the Breza.pl domain was already in the kit's firmware, then there is probably also other more dangerous malware in its code.
So we recommend that you pay special attention if you want to buy this product.

