A webcam app that has been downloaded and installed by thousands of users has left a database full of user data exposed online, without a password . The Elasticsearch database belonged to Adorcam , an app for viewing and controlling several webcam models, including the Zeeporte and Umino cameras. Security researcher Justin Paine discovered the data leak and contacted Adorcam, which secured the database.
Paine said in a blog post shared with TechCrunch that the database contained about 124 million rows of data from thousands of users, as well as “live” information about the webcam — such as its location, whether the microphone was active, and the name of the Wi-Fi network the camera was connected to . More importantly, it could also access information about the webcam’s owner, such as email addresses .

Additionally, Paine found evidence of photos taken by the camera being uploaded to the cloud , but he was unable to verify them since the links had expired.
He also discovered hardcoded credentials in the database for the app’s MQTT server, a “lightweight” messaging protocol often used on devices connected to the Internet. Paine did not “check” the credentials, as doing so would be illegal in the U.S.However, he alerted the app’s developer to the vulnerability, who then changed the password.

As TechCrunch reports, Paine verified that the database was updated, live, by signing up for a new account and searching for his information in the database. While the data was limited in terms of “sensitivity,” Paine warned that a malicious hacker could create convincing phishing emails or use the information to blackmail users.
Η Adorcam δεν έχει κάνει μέχρι στιγμής κάποια επίσημη δήλωση σχετικά με το θέμα.
