
DEF CON 32 - The edges of Surveilance System and its supply chain - Chanin Kim, Myounghun Pak
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 43:46
The video exposes critical vulnerabilities in MVR (Network Video Recorder) devices from major vendors like Hikvision, Dahua, and vendor A, enabling remote code execution, privilege escalation, and full device control through flaws in command injection, buffer overflows, and authorization logic. 0:47
Key Takeaways:
• Command injection and buffer overflows allow remote code execution and privilege escalation in Hikvision, Dahua, and vendor A devices 3:15-3:50.
• A "glitching attack" bypasses password protection in vendor A devices by disrupting the boot process to enable unauthorized SSH access 9:35-10:38.
• Guest users can access full device controls—including reboot, shutdown, and package installation—due to flawed authorization in the Chology surveillance station 18:10-19:23.
• Dahua’s AO Air background service allows remote denial-of-service and arbitrary command execution via unbounded data size 27:40-29:58.
• Local Windows plugins with admin privileges enable remote access and lateral movement via crafted messages 35:11-37:03.
These vulnerabilities highlight the risks in surveillance systems, especially when devices are rebranded by third parties, extending supply chain exposure beyond original vendors. 41:45-43:42
Sources:
- 0:47 Overview of MVR vulnerabilities and research motivation
- 3:15-3:50 Remote code execution via command injection and buffer overflows
- 9:35-10:38 Glitching attack to bypass
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
okay hello defon um thank you for coming to our presentation we are excited to share our talk titled Watchers being watch it exploiting the surveillance system and its supply chain we'll talk about our vulnerability search on surveillance system devices please enjoy first let us introduce our research group I'm chanik Kim and I'm currently working as an offensive researcher at s2w and he is m p and he's a student attending a university in Korea enjoying offensive research and this is what we'll show you in this talk we'll be talking about a $30,000 Bounty and a four month journey to become a defon speaker in our talk we'll cover how we exct the fare then the steps we took to analyze the vulnerabilities and after that the various vulnerabilities that could be exploited in the world and thei…