HomeSecurityCheck Point: ransomware on DSLR cameras

Check Point: ransomware on DSLR cameras

Check Point Research, the research division of Check Point Software Technologies Ltd., has revealed that the Wi-Fi connectivity of modern cameras, as well as the use of their USB ports, makes them vulnerable to ransomware and malware attacks.

Check Point: ransomware on DSLR cameras

It is well known that modern cameras no longer use film to capture and play back images, the International Imaging Industry Association (I3A) developed a standardized protocol, known as the Picture Transfer Protocol (PTP), for transferring digital images from the camera to the computer. This protocol, originally focused on transferring images, has now evolved to include dozens of different commands that support everything from capturing live images to upgrading the camera's firmware.

Check Point Research decided to use a camera to exploit the protocol vulnerabilities in order to infect the camera. For the purposes of the research, Check Point used the Canon EOS 80D DSLR, which supports both USB and Wi-Fi, identifying critical vulnerabilities in PTP. Given that the protocol is standardized and is also integrated into other camera brands, Check Point believes that similar vulnerabilities can be found in cameras from other vendors.

“Any ‘smart’ device, including DSLR cameras, is vulnerable to attacks,” said Eyal Itkin, Security Researcher at Check Point Software Technologies.

Cameras no longer simply connect to USB, but to the Wi-Fi network and its surrounding environment. This makes them more vulnerable to threats, as attackers can inject ransomware into both the camera and the computer it is connected to. Photos could potentially be intercepted or “locked” until the user pays a ransom to “unlock” the footage.

The following are tips for users to protect their cameras from related threats:

  1. Make sure your camera is using the latest firmware version and install updates if available.
  2. Turn off the camera's Wi-Fi when you are not using it.
  3. When using Wi-Fi, consider using the camera as a Wi-Fi hotspot rather than connecting your camera to a public Wi-Fi network.

Check Point Research notified Canon of the vulnerabilities and the two companies worked together to address them and close the security gap. Canon released the “update” as part of an official security advisory released in both English and Japanese.

For more information on how the research was conducted, visit https://research.checkpoint.com/say-cheese-ransomware-ing-a-dslr-camera.

_________________

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS