exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Swann Security CCTV DVR Disclosure

Swann Security CCTV DVR Disclosure
Posted Feb 10, 2009
Authored by Terry Froy

The CCTV DVR being marketed by Swann Security suffers from a remote file disclosure vulnerability that leaks credential information.

tags | exploit, remote, info disclosure
SHA-256 | 07c459e6ef6c1a89c83decc11beeb4d60d7ef946657d75f71b08df8c9cccecb0

Swann Security CCTV DVR Disclosure

Change Mirror Download
Dear BugTraq Readers,

It is possible to download the configuration containing usernames/passwords to this CCTV DVR which is being marketed by Swann Security (suspect that it is a rebranded AVTech unit)

[tez@tetris ~]$ curl http://192.168.2.100/../../var/run/vy_netman.cfg
<snip>Padmin111111

(the above are the default username/password on the unit; which I have yet to change - access to other units found via Google have demonstrated that this technique does work)

Once you have the username/password from this file, you can log in to the unit via http://[IP Address]/ and authenticate with those details.

It is strongly suggested that owners of these units secure them by configuring an IP-based ACL on their firewall/router in order to ensure that unwanted parties cannot view the cameras attached to this unit.

This vulnerability has been reported to Swann Security and as of yet, they have not published a firmware update for this nor responded to my request for access to firmware source under the terms of the GPL.

As per standard disclosure practices, the vendor was given 30 days to publish a patch/fix or announce this themselves - so far, they have not done so hence my own disclosure.

Regards,
Terry Froy
Spilsby Internet Solutions
http://www.spilsby.net/
Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    20 Files
  • 11
    Oct 11th
    21 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    14 Files
  • 15
    Oct 15th
    49 Files
  • 16
    Oct 16th
    28 Files
  • 17
    Oct 17th
    23 Files
  • 18
    Oct 18th
    10 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    5 Files
  • 22
    Oct 22nd
    12 Files
  • 23
    Oct 23rd
    23 Files
  • 24
    Oct 24th
    9 Files
  • 25
    Oct 25th
    10 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close