DEF CON 33 - Turning Camera Surveillance on its Axis - Noam Moshe

DEF CON 33 - Turning Camera Surveillance on its Axis - Noam Moshe

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 21:30

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Here's the revised summary based on the feedback, incorporating accurate technical details and narrative flow from the transcript:

Summary: Noah Mushe from Clarity presents his research uncovering critical pre-authentication remote code execution vulnerabilities in Axis camera surveillance systems. By exploiting a proprietary protocol and fallback mechanisms, he gained access to thousands of exposed servers globally, including those in government, medical, and educational institutions, before responsibly disclosing the flaws to Axis for patching.

Key Takeaways:
Research Objective: Noah aimed to hack into internal networks of major companies by targeting internet-exposed services, leading him to discover Axis' proprietary "Axis remoting" protocol 1:15.
Protocol Vulnerability: Axis remoting, a JSON-based RPC protocol wrapped in mTLS, used insecure .NET deserialization (TypeNameHandling.Auto) in its service contracts. This allowed attackers to inject malicious objects and achieve RCE—but only after authentication 9:55.
Authentication Bypass: Noah exploited a fallback HTTP-based protocol (port 80) with a custom encryption handshake. He discovered a secret endpoint (//) supporting anonymous authentication, bypassing NTLM/Kerberos requirements entirely 14:14, 18:13.
Pre-Auth RCE: Combining the deserialization flaw with the anonymous endpoint enabled unauthenticated remote code execution on Axis device management servers (Axis Device Manager) 18:13.
Lateral Movement: Compromised servers could deploy malicious signed packages (via Axis Camera Station) to hack connected cameras, granting full surveillance access and network visibilit

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Let's get to it. Uh, no emotion from clarity team turning camera surveillance on this ax. >> Yeah, good job winning. Yeah, we kicked the asses. So, before I start, let me introduce myself. My name is Noah Mushe and I am the team lead and lead vulnerability researcher at Clarity 2. Now, my day job, and I believe it's one of the coolest there is, is to essentially find vulnerabilities and all sorts of devices and responsibly disclose them to the vendor. Here you can see one of I think six, seven racks in our lab where essentially this is my playground. I gets to connect and play and find vulnerabilities in all sorts of devices including OT like PLC's, HMIs, medical devices like DNA sequencers, patient monitors, all of that sort of fun. and of course my personal favorite and today's topic IoT…