BSides Cymru has ended
Back To Schedule
Saturday, September 28 • 12:00pm - 12:30pm
I Spy With My Little Eye

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
How would you feel if you knew it was possible to view every single camera feed of several major DVR Smart camera platforms. You know, the camera you use in your house.

Sometimes it feels we are going backwards in IoT security, we are moving to the age of the "central platform" to avoid opening ports and handling all the connection stuff for ease and extra security. But this approach can and will backfire majorly, if a vulnerability is found on the platform itself. And exploitatopm of that kind of vulnerability means gaining access to a large number of devices.

In this talk we will look at connected smart cameras and show example of multiple simple logic flaws that are found on multiple portals. We will show how manufacturers and developers fall short in different places and how they are practically are giving access to all their cameras to an attacker.

avatar for Mike Polydorou

Mike Polydorou

Security Consultant, Pen Test Partners
Mike holds an BSc and M.Eng in Network Management & Security. He is a CHECK Team Leader (infra) and a holds a hand full of Cisco certs. He now works on various hardware engagements and research projects for Pen Test Partners. his hobbies include entering beard contests and hoping... Read More →
avatar for Vangelis Stykas

Vangelis Stykas

Security Consultant, Pen Test Partners
Vangelis Stykas is a backend engineer turned into a pentester. Playing around with bits and bytes for the past 30 years , he has hacked ships,cars and locks. He has a weak spot for breaking APIs and web stuff but hates building them.

Saturday September 28, 2019 12:00pm - 12:30pm BST
Track 2 - Tramshed Tech Workspace

Attendees (4)