By Lynn Palec, | January 19, 2017
Samsung is yet to comment on the recently revealed vulnerability of SmartCam. (YouTube)
The current proliferation of Internet of Things devices have made them a prime target for hackers. Meanwhile, IoT device makers do not appear to be very concerned about securing their products. The latest victim is Samsung's SmartCam.
Shortly after Samsung launched the SmartCam, hackers and security researchers have found out several vulnerabilities that could put users' data in danger. Samsung was quick to acknowledge the issue and immediately released a fix.
Like Us on Facebook
However, recent assessments revealed that instead of fixing the vulnerabilities, Samsung only provided a sort of workaround that might have rendered the device more vulnerable to hackers. Samsung did this by removing the SmartCam's entire Web admin interface which allows users to configure the smart camera, according to Hot Hardware. Samsung now redirects users to a cloud-based service to use the same operations.
In a post shared on the Exploitee website, it revealed that a script which was formerly used for firmware updates was not removed even after Samsung halted the Web interface service. This very script has a command injection bug which can allow malicious hackers to escalate remote user permissions to admin or even root privileges.
An Exploitee researcher said, "The iWatch Install.php vulnerability can be exploited by crafting a special filename which is then stored within a tar command passed to a php system()call."
In a hacking video shared on YouTube, the user was able to successfully carry out the exploit from start to finish. Using a special command, the hacker was able to trick the SmartCam into triggering the bug and making the device accessible through a telnet login. Using the same exploit, hackers can also re-enable the Web admin interface that Samsung originally disabled.
Samsung is yet to comment on the recently revealed vulnerability of SmartCam.
-
Use of Coronavirus Pandemic Drones Raises Privacy Concerns: Drones Spread Fear, Local Officials Say
-
Coronavirus Hampers The Delivery Of Lockheed Martin F-35 Stealth Fighters For 2020
-
Instagram Speeds Up Plans to Add Account Memorialization Feature Due to COVID-19 Deaths
-
NASA: Perseverance Plans to Bring 'Mars Rock' to Earth in 2031
-
600 Dead And 3,000 In The Hospital as Iranians Believed Drinking High-Concentrations of Alcohol Can Cure The Coronavirus
-
600 Dead And 3,000 In The Hospital as Iranians Believed Drinking High-Concentrations of Alcohol Can Cure The Coronavirus
-
COVID-19: Doctors, Nurses Use Virtual Reality to Learn New Skills in Treating Coronavirus Patients