Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A while ago there was a post on Reddit about something similar, and there wasn't even any "hacking" going on; the video feeds were just unsecured.

Using Google, someone search for a proprietary video protocol (IIRC) and found tons of video streams that weren't even password protected. Some in schools, some in warehouses, and some just on the street as part of neighborhood surveillance. I think I have the link saved, I'll look for it.



Finding unprotected streams via Google Dorking like this is easy. Here's an article that doesn't cover this particular use case, but rather the broader practice:

https://exposingtheinvisible.org/guides/google-dorking/

I've personally dabbled with it a bit in the past, and while I didn't find anything particularly interesting, it did make me a bit more cautious about enabling anyone with a link to access a Google Doc. With a good enough scraper or even just a lot of patience, there are a lot (potentially sensitive) data out there for people to harvest. That's not to say there aren't a number of benefits to having access to advanced search tools though, just that individual mindfulness when making something completely open for anyone to access is all the more important.


Its horrible how common this is. I used to do work on local business sites and the security was horrific. Pages that contain sensitive data or even CRM management pages exposed to the public internet with no password at all. On some of the less sensitive ones I had a look I found details of family members in these exposed sites.

Not only that, but it was all horribly outdated. Seen some things running on rails 1 pre release on a debian server about 6 years passed end of life.

Its a wonder the world works at all.



Wasn't there a website along the lines of "camroulette" that showed you random unsecured IP camera feeds?


Yes. There also used to be a subreddit where every post was an unsecured camera IP address.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: