<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hacking Linksys IP Cameras (pt 1)</title>
	<atom:link href="http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Thu, 11 Mar 2010 22:49:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Hacking Linksys IP Cameras (pt 6) &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-128170</link>
		<dc:creator>Hacking Linksys IP Cameras (pt 6) &#124; GNUCITIZEN</dc:creator>
		<pubDate>Wed, 24 Feb 2010 07:18:35 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-128170</guid>
		<description>[...] published: February 24th, 2010 This article is a continuation of the following GNUCITIZEN articles: Hacking Linksys IP Cameras (pt 1), Hacking Linksys IP Cameras (pt 2), Hacking Linksys IP Cameras (pt 3), Hacking Linksys IP Cameras [...]</description>
		<content:encoded><![CDATA[<p>[...] published: February 24th, 2010 This article is a continuation of the following GNUCITIZEN articles: Hacking Linksys IP Cameras (pt 1), Hacking Linksys IP Cameras (pt 2), Hacking Linksys IP Cameras (pt 3), Hacking Linksys IP Cameras [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WVC54GCA Firmware v1.1 &#171; Brian Klug: Internet Adventures</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-128108</link>
		<dc:creator>WVC54GCA Firmware v1.1 &#171; Brian Klug: Internet Adventures</dc:creator>
		<pubDate>Wed, 20 Jan 2010 07:57:22 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-128108</guid>
		<description>[...] about the security issues (which are supposedly fixed in 1.1), I upgraded both cameras from my previous trusty (but somewhat [...]</description>
		<content:encoded><![CDATA[<p>[...] about the security issues (which are supposedly fixed in 1.1), I upgraded both cameras from my previous trusty (but somewhat [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Linksys IP cam hacking &#124; Hack a Day Thailand</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-128051</link>
		<dc:creator>Linksys IP cam hacking &#124; Hack a Day Thailand</dc:creator>
		<pubDate>Wed, 16 Dec 2009 16:21:59 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-128051</guid>
		<description>[...] has posted information on linksys wireless IP camera hacking. It turns out that some models send the administrator user name and password to the computer when [...]</description>
		<content:encoded><![CDATA[<p>[...] has posted information on linksys wireless IP camera hacking. It turns out that some models send the administrator user name and password to the computer when [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rmadeat</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-127487</link>
		<dc:creator>rmadeat</dc:creator>
		<pubDate>Sat, 13 Jun 2009 10:25:40 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-127487</guid>
		<description>Very nice. 

Thank you</description>
		<content:encoded><![CDATA[<p>Very nice. </p>
<p>Thank you</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wayland</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-127426</link>
		<dc:creator>Wayland</dc:creator>
		<pubDate>Fri, 05 Jun 2009 20:09:44 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-127426</guid>
		<description>I can confirm that the camera does lock up on occasion but clears itself and it&#039;s light sensitivity is not as good as a Sitecom Wifi camera. However it&#039;s an excellent price and works very well with Go1984. 

It would be interesting to turn a router or a print server into a mini USB camera server.</description>
		<content:encoded><![CDATA[<p>I can confirm that the camera does lock up on occasion but clears itself and it&#8217;s light sensitivity is not as good as a Sitecom Wifi camera. However it&#8217;s an excellent price and works very well with Go1984. </p>
<p>It would be interesting to turn a router or a print server into a mini USB camera server.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacking Linksys IP Cameras (pt 5) &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-127423</link>
		<dc:creator>Hacking Linksys IP Cameras (pt 5) &#124; GNUCITIZEN</dc:creator>
		<pubDate>Fri, 05 Jun 2009 08:05:32 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-127423</guid>
		<description>[...] 5) published: June 5th, 2009 This article is a continuation of the following GNUCITIZEN articles: Hacking Linksys IP Cameras (pt 1), Hacking Linksys IP Cameras (pt 2), Hacking Linksys IP Cameras (pt 3), Hacking Linksys IP Cameras [...]</description>
		<content:encoded><![CDATA[<p>[...] 5) published: June 5th, 2009 This article is a continuation of the following GNUCITIZEN articles: Hacking Linksys IP Cameras (pt 1), Hacking Linksys IP Cameras (pt 2), Hacking Linksys IP Cameras (pt 3), Hacking Linksys IP Cameras [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ---</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126974</link>
		<dc:creator>---</dc:creator>
		<pubDate>Sun, 10 May 2009 15:50:50 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126974</guid>
		<description>Has anyone tried to sniff and playback the video stream (probably mpeg4) of these IP cameras?</description>
		<content:encoded><![CDATA[<p>Has anyone tried to sniff and playback the video stream (probably mpeg4) of these IP cameras?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126908</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Thu, 07 May 2009 17:38:25 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126908</guid>
		<description>@shawnmer: Linksys updated the wizard URL. The new link is http://downloads.linksysbycisco.com/downloads/WVC54GCA-CD-Content-10-25-2007_SetupWiz,0.zip

FYI:

&lt;pre&gt;&lt;code&gt;$ md5sum SetupWizard.exe 
1c7cb77e906152376102b88604650577  SetupWizard.exe&lt;/code&gt;&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p>@shawnmer: Linksys updated the wizard URL. The new link is <a href="http://downloads.linksysbycisco.com/downloads/WVC54GCA-CD-Content-10-25-2007_SetupWiz,0.zip" rel="nofollow">http://downloads.linksysbycisc.....pWiz,0.zip</a></p>
<p>FYI:</p>
<pre><code>$ md5sum SetupWizard.exe
1c7cb77e906152376102b88604650577  SetupWizard.exe</code></pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: shawnmer</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126685</link>
		<dc:creator>shawnmer</dc:creator>
		<pubDate>Tue, 28 Apr 2009 02:42:36 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126685</guid>
		<description>Looks like the Linksys Setup utility has been pullled from the link you provided above: WVC54GCA-CD-Content-10-25-2007_SetupWiz.zip</description>
		<content:encoded><![CDATA[<p>Looks like the Linksys Setup utility has been pullled from the link you provided above: WVC54GCA-CD-Content-10-25-2007_SetupWiz.zip</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacking Linksys IP Cameras (pt 4) &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126651</link>
		<dc:creator>Hacking Linksys IP Cameras (pt 4) &#124; GNUCITIZEN</dc:creator>
		<pubDate>Sat, 25 Apr 2009 03:29:19 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126651</guid>
		<description>[...] GNUCITIZEN articles, which include an introduction to the topic and also some initial observations: Hacking Linksys IP Cameras (pt 1), Hacking Linksys IP Cameras (pt 2), Hacking Linksys IP Cameras (pt [...]</description>
		<content:encoded><![CDATA[<p>[...] GNUCITIZEN articles, which include an introduction to the topic and also some initial observations: Hacking Linksys IP Cameras (pt 1), Hacking Linksys IP Cameras (pt 2), Hacking Linksys IP Cameras (pt [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nederland doelwit spionage en IP camera's hack je zo</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126642</link>
		<dc:creator>Nederland doelwit spionage en IP camera's hack je zo</dc:creator>
		<pubDate>Fri, 24 Apr 2009 10:08:05 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126642</guid>
		<description>[...] Meer informatie over de IP camera hack vind je hier: Hacking Linksys IP Cameras [...]</description>
		<content:encoded><![CDATA[<p>[...] Meer informatie over de IP camera hack vind je hier: Hacking Linksys IP Cameras [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacking Linksys IP Cameras (pt 3) &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126630</link>
		<dc:creator>Hacking Linksys IP Cameras (pt 3) &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 23 Apr 2009 00:53:08 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126630</guid>
		<description>[...] GNUCITIZEN articles, which include an introduction to the topic and also some initial observations: Hacking Linksys IP Cameras (pt 1), Hacking Linksys IP Cameras (pt [...]</description>
		<content:encoded><![CDATA[<p>[...] GNUCITIZEN articles, which include an introduction to the topic and also some initial observations: Hacking Linksys IP Cameras (pt 1), Hacking Linksys IP Cameras (pt [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126621</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Wed, 22 Apr 2009 06:34:43 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126621</guid>
		<description>@CERT: the US-CERT note you mentioned (VU#528993) is the same as CVE-2008-4390 which I *did* talk about in this post. It might not be the same exact issue but it&#039;s hard to tell as there is very little info provided by CVE-2008-4390/VU#528993.

Please note that:

1) a different model (WVC54GC) was reported to be vulnerable on CVE-2008-4390/VU#528993

2) the data didn&#039;t seem to travel unencrypted in the case of the WVC54GCA during communications with the setup wizard (maybe just encoded/obfuscated?). VU#528993 mentions: &quot;This packet is sent over the network unencrypted&quot;, which doesn&#039;t appear to be true for the WVC54GCA (at least at first sight, further digging might reveal otherwise)

3) there is no fix available for the WVC54GCA at time of writing, while Linksys did release a fix for the WVC54GC

I tried contacting Andre Protas and Greg Linares who found the issue you mentioned (CVE-2008-4390/VU#528993) in order to gather more details, but I received no response.

It might be possible that Linksys did fix the issue of sensitive data traveling in the clear when the wizard communicates with the camera, but might have still left unfixed a fundamental flaw: the camera sends the admin password to the wizard before the user even enters them on the wizard. I guess the developer(s) didn&#039;t think of someone examining the memory of the wizard process?</description>
		<content:encoded><![CDATA[<p>@CERT: the US-CERT note you mentioned (VU#528993) is the same as CVE-2008-4390 which I *did* talk about in this post. It might not be the same exact issue but it&#8217;s hard to tell as there is very little info provided by CVE-2008-4390/VU#528993.</p>
<p>Please note that:</p>
<p>1) a different model (WVC54GC) was reported to be vulnerable on CVE-2008-4390/VU#528993</p>
<p>2) the data didn&#8217;t seem to travel unencrypted in the case of the WVC54GCA during communications with the setup wizard (maybe just encoded/obfuscated?). VU#528993 mentions: &#8220;This packet is sent over the network unencrypted&#8221;, which doesn&#8217;t appear to be true for the WVC54GCA (at least at first sight, further digging might reveal otherwise)</p>
<p>3) there is no fix available for the WVC54GCA at time of writing, while Linksys did release a fix for the WVC54GC</p>
<p>I tried contacting Andre Protas and Greg Linares who found the issue you mentioned (CVE-2008-4390/VU#528993) in order to gather more details, but I received no response.</p>
<p>It might be possible that Linksys did fix the issue of sensitive data traveling in the clear when the wizard communicates with the camera, but might have still left unfixed a fundamental flaw: the camera sends the admin password to the wizard before the user even enters them on the wizard. I guess the developer(s) didn&#8217;t think of someone examining the memory of the wizard process?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126618</link>
		<dc:creator>Justin</dc:creator>
		<pubDate>Wed, 22 Apr 2009 02:07:25 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126618</guid>
		<description>Ok I just ordered one to try this myself. justin@wastate.net</description>
		<content:encoded><![CDATA[<p>Ok I just ordered one to try this myself. <a href="mailto:justin@wastate.net">justin@wastate.net</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126614</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 21 Apr 2009 20:28:44 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126614</guid>
		<description>ahhhhhhh, r u sure this is the same vuln?</description>
		<content:encoded><![CDATA[<p>ahhhhhhh, r u sure this is the same vuln?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CERT</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126610</link>
		<dc:creator>CERT</dc:creator>
		<pubDate>Tue, 21 Apr 2009 14:46:42 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126610</guid>
		<description>http://www.kb.cert.org/vuls/id/528993

Old news</description>
		<content:encoded><![CDATA[<p><a href="http://www.kb.cert.org/vuls/id/528993" rel="nofollow">http://www.kb.cert.org/vuls/id/528993</a></p>
<p>Old news</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Linksys IP Cam Hacking &#124; the2600.com</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126606</link>
		<dc:creator>Linksys IP Cam Hacking &#124; the2600.com</dc:creator>
		<pubDate>Tue, 21 Apr 2009 08:12:23 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126606</guid>
		<description>[...] So go ahead and check out how to protect yourself against this VIA Hack a Day &amp; Gnucitizen Part 1 and Part 2   Hacks Hack, Linksys, Web Cam, [...]</description>
		<content:encoded><![CDATA[<p>[...] So go ahead and check out how to protect yourself against this VIA Hack a Day &amp; Gnucitizen Part 1 and Part 2   Hacks Hack, Linksys, Web Cam, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: j-zero</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126605</link>
		<dc:creator>j-zero</dc:creator>
		<pubDate>Tue, 21 Apr 2009 08:06:45 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126605</guid>
		<description>yeah linksys. epic fail.</description>
		<content:encoded><![CDATA[<p>yeah linksys. epic fail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Linksys IP cam hacking &#124; News for Geek</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126602</link>
		<dc:creator>Linksys IP cam hacking &#124; News for Geek</dc:creator>
		<pubDate>Tue, 21 Apr 2009 06:54:52 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126602</guid>
		<description>[...] has posted information on linksys wireless IP camera hacking. It turns out that some models send the administrator user name and password to the computer when [...]</description>
		<content:encoded><![CDATA[<p>[...] has posted information on linksys wireless IP camera hacking. It turns out that some models send the administrator user name and password to the computer when [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacking Linksys IP Cameras (pt 2) &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/comment-page-1/#comment-126595</link>
		<dc:creator>Hacking Linksys IP Cameras (pt 2) &#124; GNUCITIZEN</dc:creator>
		<pubDate>Mon, 20 Apr 2009 22:58:18 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=2899#comment-126595</guid>
		<description>[...] The Network      Hacking Linksys IP Cameras (pt 2) published: April 20th, 2009 This article is a continuation of the following GNUCITIZEN article, which includes an introduction to the topic and also some initial observations: Hacking Linksys IP Cameras (pt 1). [...]</description>
		<content:encoded><![CDATA[<p>[...] The Network      Hacking Linksys IP Cameras (pt 2) published: April 20th, 2009 This article is a continuation of the following GNUCITIZEN article, which includes an introduction to the topic and also some initial observations: Hacking Linksys IP Cameras (pt 1). [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
