My security camera shipped a GitHub admin token in its login page
A security researcher details the process of reverse-engineering a Hanwha security camera's firmware to uncover hardcoded encryption keys and a GitHub admin token. The author used AI tools to assist in navigating obfuscated code and decrypting the device's root filesystem.
Why it matters
This highlights significant security vulnerabilities in IoT devices and demonstrates how AI can accelerate both defensive and offensive security research.
i took the image and threw it at binwalk hoping it was just a rootfs or something, but inside there was a separate tarball with some AI stuff for the camera and a fwimage.tgz that binwalk was flagging as encrypted.
I was googling around and saw that Matt Brown has a writeup on these cameras that got me through . basically the passphrase is HTW + the model number so HTWXNP-9300RW worked.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in