Friday, January 14, 2005

geocamming - unsecurity cameras revisited

geocamming - unsecurity cameras revisited - hack a day - www.hackaday.com

"this one is for all the people who couldn’t see the netcams from sunday’s post. it turns out that the web interface to these cameras can serve both motion-jpeg and traditional jpeg frames (the latter with browser refresh). unfortunately, many browsers (including safari on my machine) don’t appear to handle motion-jpeg.

no need to switch browsers, though. you can use google to filter out the motion-jpeg urls. you’ll even benefit by reducing the amount of bandwidth you use (really nice for the slow camera connections). just google for inurl:"ViewerFrame?Mode=Refresh"

there’s something incredibly cool about seeing what is happening around the world. you can change the interface language to english by setting the language id to 4 in the url.

..."

If you need a daily voyeur fix, the above google search will help.

I'm getting 713 hits. And in non-scientific random clicking, about 50-70% of the links are active, meaning I'm getting access to the camera's controls and see pictures. And there's no hacking involved... These are just open links, thought that are not probably intended to be open.

It's another example of how Google can be used to find stuff that people don't necessarily want or intend to be public.

Ladies and Gentleman, SECURITY BY OBSECURITY DOESN'T WORK!




No comments: