Who is responsible? You are!

July 2016 News & Events

Gone are the days of installing IP cameras without a care about security; and by that I mean information security or cyber security, or whatever you want to call it. A security company, Sucuri, was recently asked to help a small jewellery business suffering a distributed denial of service (DDOS) attack. The business’s website was receiving around 35 000 requests per second, which basically made the website useless for everyone.

Sucuri dealt with the attack, only to find the number of requests increasing to almost 50 000 after the site came back online. This is where the IoT (Internet of Things) comes into the picture. IoT devices have been used in attacks before, but this time the IoT devices were surveillance cameras that were connected to the Internet. To be more specific, Sucuri was able to identify over 25 000 IP addresses from cameras located around the world.

The cameras were located in 105 different countries. What is nice is that for once South Africa wasn’t in the top 10, although it was one of the 105.

The key issue here was the vulnerability the attackers took advantage of dates back to 2014. The software was developed in China and affects over 70 vendors who use it in their DVRs – which means the cameras attached to the DVRs can be compromised. You can read a technical investigation into the vulnerability at www.securitysa.com/*ksrce1, as well as a list of the affected vendors.

Fortunately, most of the vendors are small companies you probably haven’t heard of, but there are enough recognisable names to make one nervous. Of course, one doesn’t know who may have bought from these vendors and put their own branding on the product.

We also don’t know which vendors may have patched their products since the article was published, but we do know there are over 25 000 cameras out there that are still vulnerable. But these are only the ones discovered in this incident, how many more may be out there?

You can read the story at www.securitysa.com/*subot1, but the moral of the story is simply that you can not expect security when you are on the Internet for any reason. It would be nice if we could expect our vendors and service providers to do their jobs and ensure security, but at the end of the day it’s you who must take responsibility for your own kit.

This means buying trusted brands from suppliers and service providers who know what they are doing and won’t vanish into thin air after the account is paid. It also means taking responsibility for your own upgrades and security patches – even on cameras, NVRs and DVRs, as well as computers, laptops and servers. At the very least, include it in your SLA and check that it’s done.

This won’t solve all the malware and similar problems, but it will make it harder for malware deviants to ply their trade. Also, maybe it’s time for physical security vendors to upgrade their patch release schedules?

Andrew Seldon

Editor



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

AURA appoints Taryn Winer as global head of people
News & Events Security Services & Risk Management
Following its €13,5 million Series B funding round last year and accelerating international expansion, particularly across the United States, AURA has appointed Taryn Winer as global head of people.

Read more...
Gallagher Security releases new fence controllers
Perimeter Security, Alarms & Intruder Detection News & Events
Gallagher Security has announced the release of its new F5 and F6 Fence Controllers, marking the latest generation of enhanced-safety, monitored-pulse fence technology, designed to meet the demands of modern security environments.

Read more...
Paxton set to launch game-changing new system
Paxton Access Control & Identity Management News & Events
Access control is evolving fast. Installers and end users are looking for systems that are simple to install, easy to manage remotely, and flexible enough to scale. In response, Paxton is exploring how emerging technologies can reshape access control.

Read more...
From the editor's desk: When the rules change
Technews Publishing News & Events
         Welcome to the SMART Surveillance & AI Handbook 2026. We were a bit nervous about including AI in the title, since it either has a good or bad reputation depending on the individual – very few people ...

Read more...
Proactive estate security in Cape Town
neaMetrics OneSpace Technologies Technews Publishing SMART Security Solutions Fang Fences & Guards ATG Digital Editor's Choice News & Events Integrated Solutions Infrastructure Residential Estate (Industry)
SMART Security Solutions started the year with our annual SMART Estate Security Conference in Cape Town on 26 February 2026. Held at Anna Beulah Farm, the conference saw a number of delegates enjoying the farm’s excellent cuisine, while listening to outstanding presenters.

Read more...
The impact of misguided viral campaigns
News & Events Training & Education
For many years, traditional media have been perceived as slower, more inflexible, and less responsive compared to digital platforms. But in an ecosystem flooded with content, its value is becoming clearer: verification, context, and accountability.

Read more...
Gallagher Security strengthens KwaZulu-Natal presence
Gallagher News & Events Integrated Solutions
Gallagher Security has reinforced its commitment to the KwaZulu-Natal region with its Command the Future event. The full-day event welcomed over 100 channel partners, end users, and consultants, marking Gallagher’s third major event in Durban.

Read more...
Rise in malicious insider threat reports
News & Events Information Security
Mimecast Study finds 46% of SA organisations report a rise in malicious insider threat reports over the past year: reveals disconnect between security awareness and technical controls as AI-powered attacks accelerate.

Read more...
Surveillance & AI roundtable
DeepAlert Lytehouse Refraime SMART Security Solutions Technews Publishing Editor's Choice Surveillance Integrated Solutions AI & Data Analytics
SMART Security Solutions held an online roundtable with a few surveillance experts to explore the intersection of surveillance and AI, gaining insights into the market and how control rooms are evolving.

Read more...
Centurion raises the bar at HomeSec Expo
Centurion Systems News & Events Access Control & Identity Management Residential Estate (Industry) Smart Home Automation Commercial (Industry)
Centurion Systems unveiled its latest product lines at HomeSec Expo 2026, introducing SMART+, a simpler way for installers and end users to manage their Centurion installations - as well as a few new products.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.