Who is responsible? You are!

July 2016 News & Events

Gone are the days of installing IP cameras without a care about security; and by that I mean information security or cyber security, or whatever you want to call it. A security company, Sucuri, was recently asked to help a small jewellery business suffering a distributed denial of service (DDOS) attack. The business’s website was receiving around 35 000 requests per second, which basically made the website useless for everyone.

Sucuri dealt with the attack, only to find the number of requests increasing to almost 50 000 after the site came back online. This is where the IoT (Internet of Things) comes into the picture. IoT devices have been used in attacks before, but this time the IoT devices were surveillance cameras that were connected to the Internet. To be more specific, Sucuri was able to identify over 25 000 IP addresses from cameras located around the world.

The cameras were located in 105 different countries. What is nice is that for once South Africa wasn’t in the top 10, although it was one of the 105.

The key issue here was the vulnerability the attackers took advantage of dates back to 2014. The software was developed in China and affects over 70 vendors who use it in their DVRs – which means the cameras attached to the DVRs can be compromised. You can read a technical investigation into the vulnerability at www.securitysa.com/*ksrce1, as well as a list of the affected vendors.

Fortunately, most of the vendors are small companies you probably haven’t heard of, but there are enough recognisable names to make one nervous. Of course, one doesn’t know who may have bought from these vendors and put their own branding on the product.

We also don’t know which vendors may have patched their products since the article was published, but we do know there are over 25 000 cameras out there that are still vulnerable. But these are only the ones discovered in this incident, how many more may be out there?

You can read the story at www.securitysa.com/*subot1, but the moral of the story is simply that you can not expect security when you are on the Internet for any reason. It would be nice if we could expect our vendors and service providers to do their jobs and ensure security, but at the end of the day it’s you who must take responsibility for your own kit.

This means buying trusted brands from suppliers and service providers who know what they are doing and won’t vanish into thin air after the account is paid. It also means taking responsibility for your own upgrades and security patches – even on cameras, NVRs and DVRs, as well as computers, laptops and servers. At the very least, include it in your SLA and check that it’s done.

This won’t solve all the malware and similar problems, but it will make it harder for malware deviants to ply their trade. Also, maybe it’s time for physical security vendors to upgrade their patch release schedules?

Andrew Seldon

Editor



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
From the editor's desk: Interesting times
Technews Publishing News & Events
We certainly live in interesting times. From delaying the budget speech because the ANC doesn’t see any reason why VAT shouldn’t be increased by 2%, to crime fighters being set up and prosecuted in ...

Read more...
World-first safe K9 training for drug detection
Technews Publishing SMART Security Solutions Editor's Choice News & Events Security Services & Risk Management Government and Parastatal (Industry)
The Braveheart Bio-Dog Academy recently announced the results of its scientific research into training dogs to accurately detect drugs and explosives without harming either the dogs or their handlers.

Read more...
Bosch sells product business to Triton
Bosch Building Technologies News & Events Products & Solutions Facilities & Building Management
Bosch is selling its Building Technologies division’s product business for security and communications technology to the European investment firm Triton. The division is set to focus on systems integration business in the future.

Read more...
Nice launches DC Blue Astute garage door motor
Nice Group South Africa Technews Publishing News & Events Access Control & Identity Management Perimeter Security, Alarms & Intruder Detection
Nice Systems SA has launched the Nice DC Blue Astute, a garage door motor for the South African market featuring a pre-installed lithium-ion battery instead of traditional lead-acid batteries.

Read more...
The human element remains the cornerstone of success
News & Events
Gallagher Security, has unveiled its Security Industry Trends Report 2025, offering insights into the rapid evolution of security systems and the broader role they play in business operations worldwide.

Read more...
New firearms training modules from ITA
News & Events Security Services & Risk Management
The International Firearm Training Academy has launched two new firearms training modules to support career development in the firearms industry: the Maintenance Fitter and the Firearms Custodian modules.

Read more...
The IoT trends shaping a smarter, more connected future
IoT & Automation News & Events
The Internet of Things (IoT) is revolutionising sectors across Africa. In 2025, IoT is expected to continue driving digital innovation, enhancing operational efficiencies, and enabling the creation of smarter, more sustainable ecosystems.

Read more...
New AI advisor for robot selection
News & Events Industrial (Industry) AI & Data Analytics
Igus’ new AI chatbot has been added to its online platform to enable companies with little previous experience and technological expertise to quickly and reliably put together Low-Cost Automation (LCA) solutions to become more competitive.

Read more...
On the ball or unaware
Technews Publishing Information Security Security Services & Risk Management
Whether an organisation is operating at a high level of information security maturity or has dangerous vulnerabilities that could put an entire business at risk, advanced, strategic penetration testing can uncover its true state of IT security.

Read more...