Hackers could serve up fake video by injecting it into the popular home surveillance kit Dropcam. They could then use the system to attack networks or carry out a robbery, researchers Patrick Wardle and Colby Moore report.
The attacks require attackers to have physical access to the devices, and the exploits use the Heartbleed vulnerability.
Dropcam is a video surveillance platform that was acquired by Google's Nest Labs last month for $555 million.
Wardle (@patrickwardle) and Moore (@colbymoore) of California-based security firm Synack have reverse-engineered Dropcam hardware and software to implant malware into the devices, allowing them to attack home and corporate networks.
"If someone has physical access, it's game over," Wardle told DarkReading.
"The camera is vulnerable to Heartbleed client-side attacks. You could spoof Dropcam's DNS server."
The duo will describe the Dropcam vulnerability during their talk " Optical surgery? Implanting a Dropcam" at the upcoming DEF CON 22 conference in Las Vegas next month.
Source: secnews.gr

