Hacking security camera with an old smart bulb

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024
  • TheTechieGuy hacked a real security camera just with a bulb that was thrown away! You may think it's not possible but watch this video, and you''ll find out how much information a smart bulb can contain. (P.S That much that it can hack you)
    Watch the full video: • Don't use security cam...
    #securitycamera #Hack #Sumsub #Shorts
    Sumsub - empowering compliance and anti-fraud teams to fight money laundering, terrorist financing, and online fraud.
    More about us:
    sumsub.com
    / sumsubcom
    / sumsubcom
    / admin

Комментарии • 256

  • @Sumsubcom
    @Sumsubcom  Год назад +28

    Watch the full version of this cool experiment: ruclips.net/video/5Zcv4-HP0do/видео.html

    • @takingdollar
      @takingdollar Год назад +2

      ❤❤❤

    • @pfoxhound
      @pfoxhound Год назад

      So he bought a programmer, desoldered memory chip. Looked all over for the necessary data... Not an easy job.

    • @HossanMonjorulof
      @HossanMonjorulof 4 месяца назад

      The link doesn’t work though 😂

  • @user-28qhfk65
    @user-28qhfk65 Год назад +334

    This is actually kinda clever

    • @__Rizzler__
      @__Rizzler__ Год назад +2

      bro thinks hes arthur morgan

  • @ohnoanyway7791
    @ohnoanyway7791 Год назад +168

    Bro plzz .. I just followed you 2 days ago..now I'm in trauma 💀

    • @jimmy3797
      @jimmy3797 Год назад +5

      don’t worry about it, it’s super unlikely.

    • @user-xf7mu7ub9d
      @user-xf7mu7ub9d Год назад +8

      That's why you should be careful when you throw away something. Criminals love dumpster diving.

    • @kyllax
      @kyllax Год назад

      @@jimmy3797 no.

  • @scienceMicroguy77
    @scienceMicroguy77 Год назад +33

    Better yet don't put any cameras inside your house whatsoever. Don't use any smart bulbs. Don't use any Amazon echoes.

    • @apfelfreund6859
      @apfelfreund6859 Год назад +8

      Cameras yes. But localized.....no connection via internet

    • @scienceMicroguy77
      @scienceMicroguy77 Год назад

      @@apfelfreund6859 Unless it's a hard wired camera it's hackable.

    • @tinostarks
      @tinostarks Год назад +1

      @@apfelfreund6859 so when they break in and steal your cameras where are your cloud saves of the break-in?

    • @NeFjuS
      @NeFjuS Год назад +3

      @@tinostarks in my virtual machine, that uploads it on the cloud :)

    • @Comrade_YG
      @Comrade_YG Год назад +3

      This is the same reason why we never use smart security devices in our home, because they’re so weak and easy to hack.

  • @dblbogy397
    @dblbogy397 Год назад +33

    For this to work it has to be a perfect storm. You have to go thru their trash for years until one of those bulbs go bad. It's easier to drive up and down the street with a garage door modulator and see what opens and then break in.

    • @Bomkz
      @Bomkz Год назад +4

      you could also sit nearby, wait for someone's device to connect 99 the wifi, and sniff out the credentials

    • @greatestone4eva
      @greatestone4eva Год назад

      ​@@Bomkzdamn we're all fucked

    • @Bomkz
      @Bomkz Год назад +9

      @@greatestone4eva I'd advice you not to really worry about it tbh.
      You really shouldn't worry about it unless you make yourself a target.
      i.e. are a politician with access to juicy data, or have a lot of money or generally a person of interest that would make somebody want to take time out of their day to hack your stuff.
      you're pretty likely not even close to being remotely worth it, mean that in a non offensive way.

    • @haroldgar12
      @haroldgar12 Год назад

      I don’t understand what the smart bulb has to do with hacking the wifi

    • @SteveGillham
      @SteveGillham Год назад +3

      @@haroldgar12 For the Smart Bulb to work properly (ie be a smart Bulb),
      The bulb needs to connect to the home Wi-Fi, thus it needs the store the Wi-Fi credentials within the bulbs onboard chips.
      By taken the bulb and then recovering the Wi-Fi credentials the attacker can then uses those stolen credentials to connect to the persons Wi-Fi network, and then scan any other device(s) on the home network for vulnerabilities, then the attacker can attempt to exploit those vulnerabilities and gain access to those devices.

  • @fuzzyg18
    @fuzzyg18 Год назад +5

    I struggle to even log into my ring doorbell

  • @nickolassmaltz9546
    @nickolassmaltz9546 Год назад +3

    This is why we can't have nice things.

  • @Very_Grumpy_Cat
    @Very_Grumpy_Cat Год назад +13

    Who the hell dispose of electronics in a trashcan, it must be disposed of in electronic waste

    • @JaakkoF
      @JaakkoF Год назад +2

      Secured eWaste now it seems, as even a mundane light bulb can contain secure credentials and passwords.

    • @transientaardvark6231
      @transientaardvark6231 Год назад

      agree on the principle, but that actually makes the exploit easier. Now you know where to find loads of bulbs. And they will also tell you the SSID and google happens to have a geographic map saying where that ssid is.

    • @jenius00
      @jenius00 Год назад

      Unfortunately I suspect most people do.

  • @50PullUps
    @50PullUps Год назад +77

    This implies that anyone within the company, who also knew the WiFi password, could also run a port scan and access the cameras.
    Good grief, there are a lot of rotten, incompetent IT people out there. 🤦‍♂️

    • @zadekeys2194
      @zadekeys2194 Год назад +23

      May I assume you are not in I.T? There is no need for the WiFi password to do a port scan. :)
      You can port scan the WAN or plug into the network, both of which require no WiFi PW.
      This is why ACL / whitelisting of Mac addresses is essential. Nothing is bullet proof. Best you can do is educate yourself, monitor your network, segment the network and never assume that you can't be a victim.

    • @zadekeys2194
      @zadekeys2194 Год назад +9

      Also, many internet facing devices are running out of date firmware which often opens them to existing or zero-day CVE's.
      Even a disgusted TV, old phone etc etc can be used to get a Mac address, that can then be cloned to try access the network. Assuming that the Mac address is toll in the whitelist :)

    • @wraithfvcker
      @wraithfvcker Год назад +5

      ​@@zadekeys2194Not all devices are forwarded to WAN though, so unless they are made publicly available, you will still need access to the internal network. Which is what i believe was done here, the camera was only internally accessible.

    • @neww0lf611
      @neww0lf611 Год назад +2

      Underpaid not incompetent

    • @zadekeys2194
      @zadekeys2194 Год назад

      @@wraithfvcker correct, not all devices are forwarded to the wan. A vulnerable router is all you need to find, and then a bit of patience to exploit it and hopefully gain access to the device or Lan.

  • @bernhardvonbarret1729
    @bernhardvonbarret1729 Год назад +3

    the song of Deus Ex was playing in my mind while the hack was ongoing XD.

  • @mr_redstone6699
    @mr_redstone6699 6 месяцев назад

    That smart bulb got its revenge for getting thrown out LOL 😂😂

  • @OrbitalRoc
    @OrbitalRoc Год назад

    people you waste money on smart bulbs deserve what comes to them.

  • @Haessige
    @Haessige Год назад +2

    You dont put a bulb in the garbage in the first place, especially not a smart bulb...

  • @Boo-pv4hn
    @Boo-pv4hn Год назад

    This should be illigal, companies have a duty of care, this is a huge failure

  • @elhombreloco3680
    @elhombreloco3680 Год назад +1

    I don't consider finding a smart light bulb in the thrash as "easy"

    • @KJ-xt3yu
      @KJ-xt3yu Год назад

      Given enough time on the market, "smart home" devices become a low hanging fruit.

  • @Renarification
    @Renarification Год назад

    guy was cheking garbage for 1year, waiting for broken smart bulb, 😂😂😂

  • @CM-xr9oq
    @CM-xr9oq Год назад +1

    Good luck. Coming across a light bulb is sometimes trash is not going to be something you will often come across. Same with the whole "reset your printer's wifi info before you sell it". The chances of someone who buys your old printer also finding your home address is very unlikely. Not to mention, that buyer would also have to be a hacker

    • @transientaardvark6231
      @transientaardvark6231 Год назад

      not all 2nd hand printer buyers are hackers, but all hackers are 2nd hand printer buyers ;)

  • @terrifictomm
    @terrifictomm Год назад +1

    The first time I heard a bunch of engineers going orgasmic (as disgusting as it sounds) about the Coming of the Internet of Things I was rightly terrified and I wondered that no one was concerned about the loss of privacy and personal security.

  • @Dog_gone_it
    @Dog_gone_it 11 месяцев назад

    "On another episode of Let's Teach Criminals"

  • @LoneWolf0648
    @LoneWolf0648 Год назад

    behold the wonders of the modern smart home.
    ill keep my wired cameras and dumb thermostat... my microwave doesn't need an update...

  • @vici._
    @vici._ Год назад +21

    I don't get it, why is their password stored on a lightbulb? Also, how did he access the camera with just the ip? I have a security camera as well but you need to be on the same wifi to access it.

    • @ankitkumar6130
      @ankitkumar6130 Год назад +7

      He hacked the wifi bro and then learnt what software is used in the cctv camera he then googled for any already existing exploit and then used it to view the camera

    • @notcamer0n
      @notcamer0n Год назад +30

      Smart devices have memory and storage so the smart lightbulb still had wifi credentials on a chip. Once they grabbed the password from the lightbulb they could log onto the network. That’s when they scanned, found the camera IPs on the same wifi, and could then see how they could go about accessing them

    • @vici._
      @vici._ Год назад +2

      Ah, this makes a lot more sense now. Thanks!

    • @s_l_v_m_r
      @s_l_v_m_r Год назад +5

      The crucial problem here is that the camera has default credentials, and this could cause trouble. Powerful search engine as Shodan can track camera in the world and if you don't have at least a strong password could be a problem ☠️

    • @notcamer0n
      @notcamer0n Год назад +3

      @@s_l_v_m_r Yes and no. By default (generally at least) routers won’t port forward. So your cameras aren’t accessible outside your private network in most cases. If you or someone gets into your network and changes the configuration yeah it’s definitely a major security issue that’s discoverable in Shodan. All default credentials that can be changed should. Ideally to secure passwords.

  • @d13x001
    @d13x001 Год назад +2

    Saying "aaannnd done" does not do all the hackinbg for you lol

  • @mauromortier7808
    @mauromortier7808 Год назад +4

    I used shodan for a bit and found some open cameras aswell. Pretty fun to make an alarm go off and see the owners react

  • @alexschubert
    @alexschubert 11 месяцев назад

    The hardest part is getting on their network. Do you think he wore gloves when he went through their garbage?

  • @jaywulf
    @jaywulf 11 месяцев назад

    5 seconds in the microwave should fix the smart lightbulb

  • @RapSolo
    @RapSolo Год назад

    There's no such thing as a strong password. The dude who suggested it wrote a whole book explaining why it's pointless.

  • @howlingcommandose
    @howlingcommandose Год назад

    Basically you need to be a hacker.

  • @marc-andreservant201
    @marc-andreservant201 11 месяцев назад

    By the way, we have reasonably secure microcontrollers now. There should be no excuse for a Wi-Fi password to be extractable from discarded devices without the owner's credentials.

  • @highrider9168
    @highrider9168 Год назад

    And this is why my cameras are wired and locally stored. 😂😂😂

  • @Wheresmy240
    @Wheresmy240 Год назад

    How "easy" it is. Thats a lot of work for no potential payoff.

  • @LironSegev
    @LironSegev 9 месяцев назад

    Thanks for sharing. The full video goes into more details for all the keyboard warriors 😂

  • @clubcyberia8572
    @clubcyberia8572 Год назад

    back in my day, we called it dumpster diving.

  • @petiertje
    @petiertje 11 месяцев назад

    One of the reasons I don't use 'smart' devices. My phone is to much enough already, no need to have everything else from my life being stored by something somewhere.

  • @hamoostaffat
    @hamoostaffat Год назад

    If you throw away a digital chip that has had your info on it without turning it to dust first your at risk, may only be small or near zero for some of us but its still possible to do

  • @MrAntiKnowledge
    @MrAntiKnowledge Год назад

    And that's why you don't need smartbulbs, smart coffeemaker, smarttoiletbrush or any other "totally fine but we can charge you double and make it worse by making it smart-product"

  • @topherkrock
    @topherkrock Год назад

    There are ways to do this in half the time it takes to get a bulb out of the garbage.

  • @prahladboro6132
    @prahladboro6132 10 месяцев назад

    Him: I DONT LIKE THIS SMART BULB
    Me: Give me I use it
    Him: ok
    Me in mind: Hehehehehe I will hack my neighborhood WiFi

  • @fanshaw
    @fanshaw Год назад

    If they have to tell you its "smart" it isn't.

  • @simonrad
    @simonrad Год назад

    its easier then that you'll be surprised how many public wifi networks have default camera passwords

  • @leenaright3949
    @leenaright3949 9 месяцев назад

    Research this online.."can LED lightbulbs collect and transmit data ?"

  • @audujoel1736
    @audujoel1736 Год назад

    basement dwellers at work. There should call him stalky

  • @roqueluis5
    @roqueluis5 Год назад

    Moral of the story wired cameras are better. Never use wifi security cameras

  • @verumignis4778
    @verumignis4778 Год назад +1

    No need to steal the light bulb, with an external antenna and a phone with nethunter you can just grab credentials off nearby devices

    • @KJ-xt3yu
      @KJ-xt3yu Год назад

      Passive monitoring vs active intent... ones legal, the other is federal issue.

  • @TheManLab7
    @TheManLab7 Год назад +17

    This is why I take everything apart to see if it's a simple fix so it can be repaired, but if not. Then I stick the PCB in the microwave for 10sec, even though 5 is more than good enough.

    • @Ron-op8es
      @Ron-op8es Год назад +1

      there’s no water in electronics, would that even work

    • @sushai1742
      @sushai1742 Год назад +1

      what??? im so confused
      does microwaving a pcb for 10 seconds really render it useless?

    • @Aera223
      @Aera223 Год назад +2

      imo 5-8s seems to be the balance ⚖️ between fire risk and data erasure

    • @moon.walker
      @moon.walker Год назад +3

      ​​@@sushai1742yeah kinda (it fries the components) can be still repaired though if no important part was damaged, best bet is to completely crush it with a hammer and then throw it in the microwave.

    • @BossModeGod
      @BossModeGod Год назад +2

      Hey.
      Guys...
      Tfs a PCB please..?

  • @bjw8qsrmhgxn4wwk30
    @bjw8qsrmhgxn4wwk30 Год назад

    Connecting to anyones network no matter how secure or open is illegal.

  • @ololh4xx
    @ololh4xx Год назад

    ya i'll be sure to look out for people who seem to want to go through my garbage next time im throwing out a dead smart device, that one time per 365 days 😂

  • @willierants5880
    @willierants5880 Год назад +1

    Just create an IOT zone where nothing else lives and has no access to your internal network. Job done. C'ya.

  • @sauerkraut3496
    @sauerkraut3496 Год назад

    To say it's easy to hack someone is relative. It's not like anyone could just do it then and there. Regardless, it's better to be aware Abt. these things.

  • @Pterodactyl-kn3ve
    @Pterodactyl-kn3ve Год назад

    Let’s not forget about Brandon Jackson who in (June?) 2023 was locked out of his Amazon devices because Amazon thought he was racist.

  • @InsideOfMyOwnMind
    @InsideOfMyOwnMind Год назад

    Now we have to grind the numbers off of the bulbs we throw out.
    I want to live to be 200 just to see where we go.

  • @JonsRegularStuff
    @JonsRegularStuff Год назад

    New excuse for sticking bulb where sun doesn't shine

  • @thomasandrews9355
    @thomasandrews9355 Год назад

    From a company attack, I could see this. From a personal attack...unlikely any normal criminal has the means...I guess its possible but so is becoming a millionare.

  • @shaikhowais8651
    @shaikhowais8651 Год назад

    That's why i never go for exchange offers 😕 just keep my phones in a box in some corners or break other stuff before giving them out

  • @juggernaut6498
    @juggernaut6498 Год назад

    This is why you use closed network cameras 😂

    • @nobeltnium
      @nobeltnium Год назад

      well he was able to login into their wifi and scan the whole net with nmap. In this scenario closed network doesn't help

  • @error-un3fo
    @error-un3fo Год назад

    Reaver is the easiest way to get into a network you just need a good directional arial and the network to have wps enabled.

  • @francischabot1412
    @francischabot1412 Год назад

    Even if you can somehow access the wifi network using the bulb which is already a big fail it's kind of even more fail that anybody having access to the wifi network would be able to log into the camera system.

  • @johnmclain250
    @johnmclain250 Год назад

    And this is why my wifi uses a manually added device white-list, and all cameras are hardwired.

  • @stevenbarkley5067
    @stevenbarkley5067 Год назад

    It is not if you will be hacked, it is are you worth protecting?

  • @dankdigital4058
    @dankdigital4058 11 месяцев назад

    I threw away that bulb to follow the person that stole it by implanting a tracker and malware to allow me to connect to anyone that tries this.

  • @NathanHedglin
    @NathanHedglin Год назад

    What a bright 💡 idea 😂

  • @taurohkea2169
    @taurohkea2169 Год назад

    smart bulb? why do you need that?

  • @chevalsauer
    @chevalsauer Год назад

    Easy when you know how, just like anything

  • @imp_raziel
    @imp_raziel Год назад

    So it's not old bulb, lol

  • @Wowaniac
    @Wowaniac Год назад

    this is why YOU NEVER Connect your phone to a free wifi its not secure and once you do anyone on that network has access to your device!

  • @timothypryor7952
    @timothypryor7952 11 месяцев назад

    Heck yeah. Nice dumpster dive breach.

  • @blankeyezero
    @blankeyezero Год назад

    One question: why is he scavenging someone else' garbage

  • @smaslan9601
    @smaslan9601 Год назад +2

    🤘HACK THE PLANET 😂

  • @paladingeorge6098
    @paladingeorge6098 11 месяцев назад

    Thank god we are storing login tokens in light bulbs. Where would be in the world right now without that?

  • @alex140666
    @alex140666 Год назад

    is that a smart bulb though? looks like a regular LED bulb.

    • @Chozo4
      @Chozo4 Год назад

      It is a basic light bulb by ecosmart. The stuff shown is just the typical power use, lumens, colour temp, etc.

  • @djbass5715
    @djbass5715 Год назад +1

    Bro I did kinda similar to this.. so my school had this projectors for the lesson and stuff so when I scanned the network with nmap and angry ip scanner I found every projector on the network, after I pasted the IP of one of them I got the sign in page, and can you believe it it had the default credentials that I got from the manual that is open source, and at the end I could project my things or change the setting of them also freez and unfreeze the screen(but I've never done it because I didn't want to get in trouble)

  • @gasovensforqcult
    @gasovensforqcult Год назад

    Why would the smart bulb bought at a random retail store contain info like a hardwired IP address, SSID, BSSID, MAC address of the person who eventually bought it after the bulb was discarded? Oh, I see you have a video. Let me watch it and maybe that answers my Q

  • @KJ-xt3yu
    @KJ-xt3yu Год назад

    trash light bulb yes, an in use device that isnt yours...NO. just dont.

  • @nwk2VGtxbs26_eiXlo2wnQ
    @nwk2VGtxbs26_eiXlo2wnQ 11 месяцев назад

    Why can't I get one decent recommendation?

  • @_sl1de_
    @_sl1de_ Год назад

    A fucking smart bulb ?!?!😂

  • @nasserqamshui
    @nasserqamshui Год назад

    Bulbs got a network 😅

  • @jays_jae
    @jays_jae Год назад

    Nice! Good pwning, love seeing it. I hope he informed them about the vulnerability

  • @Jon6429
    @Jon6429 Год назад

    Checks for house key under flower pot

  • @tld8102
    @tld8102 Год назад +4

    oh shit. does this mean the smart bulbs i’ve returned to the store?

    • @KJ-xt3yu
      @KJ-xt3yu Год назад +2

      Yes, every time, unless you ask for clarification on the process to validate weather or not.

  • @zachpangus7584
    @zachpangus7584 10 месяцев назад

    Always change username and password of routers and other wifi enabled devices you bring into your home for this reason.

  • @Dan-codes
    @Dan-codes Год назад

    Microwave everything.

  • @nickgardner6340
    @nickgardner6340 Год назад

    damn, all cuz their lightbulbs connect to the internet... that's so crazy...🙄

  • @zadekeys2194
    @zadekeys2194 Год назад +1

    Use Access Control Lists or Blacklist the Mac address when you throw away a network device.

    • @jessewilliams6459
      @jessewilliams6459 Год назад +2

      Just told my grandma to do that. Solved all of her problems and she knew what a Mac address is.

    • @zadekeys2194
      @zadekeys2194 Год назад

      @@jessewilliams6459 your Grandma is a true G. G is also for Google ;)

  • @Thefabfarm250
    @Thefabfarm250 Год назад

    Yeah all those first steps were pretty unnecessary if it’s a simple IOT camera there’s a bunch of websites you can just go and view them like the one in the last clip.

  • @keivah-gaming4973
    @keivah-gaming4973 Год назад

    That's why I remove the insides of things like these before I throw them away. And typically keep the logic board.

    • @mxdanger
      @mxdanger Год назад

      Alternatively just click the factory reset button.

  • @andrews6882
    @andrews6882 11 месяцев назад

    That isn’t a smart bulb. I’m assuming you just used a random video of a LED bulb though

  • @Nyziko
    @Nyziko Год назад

    Wait, you said this was easy? Don't know if that's an insult to all other normal people without that knowledge, or it's just bragging

  • @robertbrzheintzbrz147
    @robertbrzheintzbrz147 Год назад

    Reminds me of the movie “the net”. As a pro one can only laugh about it.

  • @thefool7992
    @thefool7992 Год назад

    Real life watch dogs

  • @highestsettings
    @highestsettings Год назад

    That's how easy it is if you have a shit router and you throw away smart devices without any care in the world.

  • @terrykiser7603
    @terrykiser7603 Год назад

    So he's telling everyone how to do it. Smh

  • @crazeeaz
    @crazeeaz Год назад

    Well, if it's "that easy" I might as well just put my wifi password on a framed card iny living room.

  • @relaxmed3517
    @relaxmed3517 Год назад

    Omg the smartbulb thats brilliant

  • @TRIPPLEJAY00
    @TRIPPLEJAY00 Год назад

    You can simple use google to control web cams

  • @jeeves622
    @jeeves622 Год назад

    Good thing my tech is dumb

  • @MIEVAL
    @MIEVAL Год назад

    A smart bulb has information? How?

  • @bromine_35
    @bromine_35 Год назад +1

    Remember to smash the chip

  • @godn99
    @godn99 Год назад

    No info about electricity yet....? Not yet....

  • @nakibahmed6960
    @nakibahmed6960 Год назад

    I stopped using any thing that has a smart name before device.
    If use something called smart devices before throwing away Fully destroyed first.

  • @fatcat7msk7ru
    @fatcat7msk7ru 11 месяцев назад

    🧐 hmmm.. got some free bulbs from random people.. ok got it, burned at the utilisation barrel. 🙄

  • @aimimusic7765
    @aimimusic7765 11 месяцев назад

    Tank for the tutorial..god bless you