VOGONS

Common searches


First post, by Miphee

User metadata
Rank Oldbie
Rank
Oldbie

I recently got this freebie chinese IP camera from a friend. He never used it because he claims it's not secure.
It shows up on the wireless network as a cloudcam and it has no security added at all, not even WEP. Anyone in range can connect to it.
I tried the YCC365 Plus app it came with, it's rather simple. First I have to connect to the cloudcam in my wifi list (no password), then use a local device account inside the app to access the camera. It uses the standard admin/password scheme and it cannot be changed.
It doesn't have an admin interface so can't add a password there.
Info would be appreciated.

Attachments

  • DSCN3015.JPG
    Filename
    DSCN3015.JPG
    File size
    106.17 KiB
    Views
    1382 views
    File license
    Fair use/fair dealing exception
  • DSC_0143.JPG
    Filename
    DSC_0143.JPG
    File size
    144.01 KiB
    Views
    1382 views
    File license
    Fair use/fair dealing exception
  • DSC_0142.JPG
    Filename
    DSC_0142.JPG
    File size
    324.16 KiB
    Views
    1382 views
    File license
    Fair use/fair dealing exception

Reply 1 of 8, by wiretap

User metadata
Rank Oldbie
Rank
Oldbie

Haven't seen this specific camera, but do a port scan on it to see what ports they left open. Usually they leave SSH (22) or telnet (23) open to remote manage/control it. If there's a password, you can usually use double blind injection attacks to leak it from the device. They don't secure these very well. My baby monitor was root/123456 for the telnet login. 🤣 After you gain access, you can harden it.

My Github
Circuit Board Repair Manuals

Reply 2 of 8, by Miphee

User metadata
Rank Oldbie
Rank
Oldbie
wiretap wrote on 2020-07-11, 12:00:

After you gain access, you can harden it.

Does this work with cameras without admin interface?
I have the camera IP and the necessary ports, I have the admin name/password but it won't connect.
Connection refused, empty response, file not found.
Nothing about changing SSID or adding WPA2 & password.

Reply 4 of 8, by will1384

User metadata
Rank Newbie
Rank
Newbie
Miphee wrote on 2020-07-11, 09:19:
I recently got this freebie chinese IP camera from a friend. He never used it because he claims it's not secure. It shows up on […]
Show full quote

I recently got this freebie chinese IP camera from a friend. He never used it because he claims it's not secure.
It shows up on the wireless network as a cloudcam and it has no security added at all, not even WEP. Anyone in range can connect to it.
I tried the YCC365 Plus app it came with, it's rather simple. First I have to connect to the cloudcam in my wifi list (no password), then use a local device account inside the app to access the camera. It uses the standard admin/password scheme and it cannot be changed.
It doesn't have an admin interface so can't add a password there.
Info would be appreciated.

I have had a lot of the cheap Chinese security cameras over the years, the first thing I do is disable the wireless even if I have to open them up and remove wires and parts to disable the camera's wireless, then I only use Ethernet after that, and if the cheap Chinese security camera don't have Ethernet I just don't use them, then I disable has much has I can on the camera using the camera's own web setup, and then I put the cameras behind there own router and have a computer record and serve up the camera's video to another router and my home network, even with the setup I have it's still possible for someone to spy on you, just a little harder, I just don't trust the cheap Chinese security cameras.

Reply 5 of 8, by Miphee

User metadata
Rank Oldbie
Rank
Oldbie
will1384 wrote on 2020-07-12, 01:11:

I have had a lot of the cheap Chinese security cameras over the years, the first thing I do is disable the wireless...

Fortunately the SSID broadcast is disabled when the ethernet cable is connected but the whole point of this camera is simple remote surveillance and wireless connectivity. Why the chinese thought it's a good idea to leave out wireless security is beyond me. It ruined this product completely.

Reply 6 of 8, by ShovelKnight

User metadata
Rank Oldbie
Rank
Oldbie
Miphee wrote on 2020-07-12, 09:30:

Fortunately the SSID broadcast is disabled when the ethernet cable is connected but the whole point of this camera is simple remote surveillance and wireless connectivity. Why the chinese thought it's a good idea to leave out wireless security is beyond me. It ruined this product completely.

There is no such thing as "privacy" in China.

Reply 7 of 8, by Miphee

User metadata
Rank Oldbie
Rank
Oldbie
ShovelKnight wrote on 2020-07-12, 09:33:

There is no such thing as "privacy" in China.

I draw a line between the government spying on citizens and criminals accessing a low security camera to map the estate before a heist.
The first happens in every country and the second is up to the developer of the product.