Flock cameras are riddled with security vulnerabilities and hard-coded credentials
micahflee
Flock cameras are riddled with security vulnerabilities and hard-coded credentials
This morning, DDoSecrets published an exciting new dataset: Filesystem images of the partitions from an in-use Flock ALPR camera. 404 Media and Wired published a joint investigation into it. I downloaded the dataset and am now thoroughly nerd-sniped.
Hackers from a collective called stegan0gram collected the data. “Why
Despite being a relatively recent build, the Flock camera was running Android 8.1. This version of Android was released in 2017, and officially stopped getting support from Google in 2021 (see the Android end-of-life page for more info). And despite Google publishing security fixes for Android 8.1 until 2021, the Android patch level is 2018-06-05. This camera is missing Android security updates for the last eight years.
I’d like to see a practical guide to leveraging this information
kali Linux with metasploit will do a lot of the heavy lifting. I imagine you could turn your local installations into a free wifi access point, for starters.
Are you able to provide greater detail?
Kali and metasploit are a complicated topic. For a general just how do these things work, below is a pretty good video. It might be hard to find instructions for how to leverage this against flock cameras, but people who are skilled in Kali and other security tools can get into almost anything
m.youtube.com/watch?v=cPNXqBofZGQ&pp=0gcJCYsCo7Vq…
download kali onto a computer and it should have an application called metasploit.
open your terminal and type in “man metasploit” and it should have enough info on the actual application to get you started but if you need more info go on youtube or kali docs
I mean, the api keys are literally in the post
I need the complete idiots guide. I’d like to participate as a disruptive force, but my level of tech knowledge is limited.
You’re in luck Micah Lee (the author of this post) literally wrote a book on this
https://micahflee.com/hacks-leaks-and-revelations-the-art-of-analyzing-hacked-and-leaked-data/
i wonder if this a majority of us – everyone has different skill levels with a huge majority of us having the needful basics to be turned into a critical mass.
the only problem i can foresee is that a huge majority in this space are either liberal or libertarian – which history proves are easily co-optible or are already aligned by the same epstein class that wants the flock cameras.
Oh, so you could work up a war driving rig to fry them. Neat.
That would scan your license plate. Better to use a drone.
Edit: that’s not what this post suggests at all
Because a war rig would have a license plate
I think the mode of war driving is done in a Toyota with license plates.
Any RCEs though? Or do they all require local privileges?
I think the idea is to chop them down and use the exploits to extract api keys to then attack their cloud infrastructure
Hmm, thinking bootloader sploits
I mean if you have physical access, then yea all bets are off. I was more thinking about remote exploits since most people (who aren’t actually stealing/hacking on them directly) wouldn’t be able to gain access otherwise.
Well if it’s android good bet that OTA is probably working
I hope people hack/compromise them and use them against the police and the people in charge to embarrass and expose them. That’s likely the only way they will finally get removed.
Good.
Don’t tell them where they are.
Deflock app. Me everyone should have it
Guessing this is deliberate to enable warrantless use of the resource by people who wouldn’t have been authorized to use it in the first place.
That doesn’t surprise me.