[Full-Disclosure] Re: CORE-2003-0403: Axis Network Camera HTTP Authentication Bypass

From: Kee Hinckley (nazgulat_private)
Date: Tue May 27 2003 - 17:34:27 PDT

  • Next message: Auriemma Luigi: "Exploit: Quake 3 engine, con\con and heartbeats (just for fun)"

    While you are fixing the vulnerability in your Axis video camera. 
    Please also stop to check and make sure that you have turned off (or 
    properly configured) it's ability to send snapshots via email.  If 
    you turn on the function without configuring the addresses, older 
    cameras will default to sending email to mailat_private "from" 
    olgaat_private  We get on the order of ten to fifteen thousand 
    of these every day.  On occasions when we've bothered to look, we've 
    seen things ranging from computer rooms to jewelry store security 
    cameras.  Probably not the kind of thing you'd want to be sending to 
    strangers.
    
    -- 
    Kee Hinckley
    http://www.messagefire.com/          Anti-Spam Service for your POP Account
    http://commons.somewhere.com/buzz/   Writings on Technology and Society
    
    I'm not sure which upsets me more: that people are so unwilling to accept
    responsibility for their own actions, or that they are so eager to regulate
    everyone else's.
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    



    This archive was generated by hypermail 2b30 : Tue May 27 2003 - 19:19:50 PDT