Article may be outdated

This article is 68 days old. Some details may have changed since publication.

Hacker News·5 min read·hard

My security camera shipped a GitHub admin token in its login page

H
hhh
My security camera shipped a GitHub admin token in its login page
✦AI Summary

A security researcher details the process of reverse-engineering a Hanwha security camera's firmware to uncover hardcoded encryption keys and a GitHub admin token. The author used AI tools to assist in navigating obfuscated code and decrypting the device's root filesystem.

Why it matters

This highlights significant security vulnerabilities in IoT devices and demonstrates how AI can accelerate both defensive and offensive security research.

✦Dive DeeperCreate a free account to unlock

i took the image and threw it at binwalk hoping it was just a rootfs or something, but inside there was a separate tarball with some AI stuff for the camera and a fwimage.tgz that binwalk was flagging as encrypted.

I was googling around and saw that Matt Brown has a writeup on these cameras that got me through . basically the passphrase is HTW + the model number so HTWXNP-9300RW worked.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in