Flock cameras are riddled with security vulnerabilities and hard-coded credentials (micahflee.com)
from greenbelt@lemy.lol to privacy@lemmy.ml on 17 Sep 00:37
https://lemy.lol/post/71556457

Despite being a relatively recent build, the Flock camera was running Android 8.1. This version of Android was released in 2017, and officially stopped getting support from Google in 2021 (see the Android end-of-life page for more info). And despite Google publishing security fixes for Android 8.1 until 2021, the Android patch level is 2018-06-05. This camera is missing Android security updates for the last eight years.

#privacy

threaded - newest

Semi_Hemi_Demigod@lemmy.world on 17 Sep 01:08 next collapse

Oh, so you could work up a war driving rig to fry them. Neat.

panda_abyss@lemmy.ca on 17 Sep 01:29 next collapse

Good.

Don’t tell them where they are.

toiletobserver@lemmy.world on 17 Sep 01:53 next collapse

I’d like to see a practical guide to leveraging this information

anarchaos@lemmy.ml on 17 Sep 02:41 collapse

kali Linux with metasploit will do a lot of the heavy lifting. I imagine you could turn your local installations into a free wifi access point, for starters.

toiletobserver@lemmy.world on 17 Sep 04:24 collapse

Are you able to provide greater detail?

Valarie@lemmygrad.ml on 17 Sep 07:10 collapse

download kali onto a computer and it should have an application called metasploit.

open your terminal and type in “man metasploit” and it should have enough info on the actual application to get you started but if you need more info go on youtube or kali docs

refalo@programming.dev on 17 Sep 03:23 next collapse

This camera is missing Android security updates for the last eight years.

Any RCEs though? Or do they all require local privileges?

nixfreak@sopuli.xyz on 17 Sep 05:12 collapse

Hmm, thinking bootloader sploits

refalo@programming.dev on 17 Sep 07:04 collapse

I mean if you have physical access, then yea all bets are off. I was more thinking about remote exploits since most people (who aren’t actually stealing/hacking on them directly) wouldn’t be able to gain access otherwise.

nixfreak@sopuli.xyz on 17 Sep 13:20 collapse

Well if it’s android good bet that OTA is probably working

OhVenus_Baby@lemmy.ml on 17 Sep 05:32 next collapse

Deflock app. Me everyone should have it

Lucidlethargy@sh.itjust.works on 18 Sep 01:29 next collapse

I hope people hack/compromise them and use them against the police and the people in charge to embarrass and expose them. That’s likely the only way they will finally get removed.

captain_aggravated@sh.itjust.works on 18 Sep 03:16 next collapse

That doesn’t surprise me.

Buddahriffic@lemmy.world on 18 Sep 17:56 collapse

Guessing this is deliberate to enable warrantless use of the resource by people who wouldn’t have been authorized to use it in the first place.