Approximately 780 webcams were identified by the SecNews and iGuru research, in Greek cyberspace, in which anyone can monitor the daily lives of thousands of Greek citizens!
Many of us have wondered how secure the cameras we have at work or in our personal space are, or how easy it would be for someone to gain access without their owners knowing.
Without wanting to scare our readers, the short answer to the question is:
It's extremely easy for anyone to access and control or monitor your cameras!
Cases have occasionally come to light where unauthorized access to webcams exposed the private moments of innocent citizens, while the way Facebook founder Mark Zuckerberg protected the camera and microphone of his personal computer was impressive!
THE RESEARCH

The question that arose in mid-summer in the SecNews technological and journalistic team was “How exposed are we in Greece regarding the security webcams we have?”
SecNews, in collaboration with iGuru, in the context of informing the general public, conducted a 2-month in-depth journalistic investigation that documented the entire Greek cyberspace in an effort to identify weaknesses. In the first part of our investigation (and which we are publishing today) we focused on publicly exposed cameras.
The method of collecting the relevant information and its evaluation was carried out with:
- initial scan of Greek cyberspace (all published public IP addresses)
- import the entire data set into a database (MongoDB)
- optimized scanning of only active addresses of exposed webcam services [specific ports, specific URLs – specific users with full permissions]
- Create automated python code to use default passwords and test access to the found IP addresses
- Creation/configuration of a relevant webapp to search for active cameras+ports depending on the IP address of the exposed user.

[Editors' Note: The database we created is updated 3 times a week automatically and is already being used for additional investigations of exposed servers and terminals, data that we will make public in the future]
It is worth mentioning that the process followed (beyond the programming part of the configuration) was particularly easy and can be carried out by ANY internet user with basic knowledge of networks and minimal programming.
This in itself makes the findings even more important and dangerous for society as a whole, since no specialized knowledge or hacking skills are needed to gain access to the webcams we mention and therefore anyone with minimal knowledge can monitor exposed cameras!!
We are particularly pleased that SecNews, in collaboration with the team of the friendly technology website iGuru, has conducted for the first time a nationwide independent survey to identify insecure devices (the first and only one that has been conducted in Greece en masse, with such precision and at such a level).
The findings

The findings raised particular concern among the SecNews researchers who conducted the study. The most alarming finding is that the vast majority (96%) of camera owners are unaware that they are exposed or that their businesses or businesses may be being monitored. Specifically:
- All of the findings concern incorrectly configured webcams.
- A large part of the investigation identified incorrectly configured AVTECH cameras. This is not due to a weakness of the camera itself, but to the installers who did not change the default access codes.
- The installers or companies that have installed the closed circuits and bear FULL RESPONSIBILITY, have left internet access enabled AND with a default password (administrator) admin/admin. The owners of these devices should certainly be held accountable.
- Therefore, anyone who knows the IP address and port with admin/admin credentials has full access to the CCTV cameras with the ability to change settings, even changing the camera's view to another direction (PTZ)!
- Additionally, as we have found, in many cases the cameras are placed above store, hotel or employee cash registers in such a position that it allows eavesdroppers to REMOTELY record the PIN entry code of customers' cards and even access codes to business e-mails or
The Greek Webcam Exposed app
It would be risky to publish the full list of webcams with the IP addresses we have at our disposal. In case we chose to publish the IP addresses, there was a fear that they would be used by malicious users, without the knowledge of the camera owners, for various purposes and even for monitoring citizens. After meetings with the SecNews technology team, we chose to publish them via a custom made application.

In practice, this means that anyone who wishes can enter the IP address (which appears at the top of the web application) or another IP address and determine whether they are exposed in order to proceed with immediate repair or update accordingly.
It would certainly be best practice for those who have AVTECH cameras to IMMEDIATELY contact their installers and locate their IP address in our application so that they can proceed with the relevant correct configuration.
You can find our application [here].
We would advise you to share the link https://www.secnews.gr/check-camera/ with your acquaintances and friends IMMEDIATELY so that they can check their own exposure to the relevant risk.
Corresponding mass investigations by SecNews, not only for webcams but also for other weaknesses involving servers and network devices that may lead to interceptions or leaks, will continue with the aim of informing and protecting society as a whole and Greek citizens.
We thank the iGuru.gr team for their technical participation and support during the research.
https://www.secnews.gr/107235/webcam/
