Moobot botnet spreading via Hikvision camera vulnerability

mlapaglia

Getting comfortable
Joined
Apr 6, 2016
Messages
849
Reaction score
506
anyone seen this?
"A Mirai-based botnet called 'Moobot' is spreading aggressively via exploiting a critical command injection flaw in the webserver of many Hikvision products. "

 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,965
Reaction score
6,794
Location
Scotland

mlapaglia

Getting comfortable
Joined
Apr 6, 2016
Messages
849
Reaction score
506
is there any easy way to check if a hikvision camera has access to the internet? i've got them on a separate vlan with no access, but it'd be nice to double check
 

Mike_Larry

n3wb
Joined
Nov 9, 2022
Messages
26
Reaction score
5
Location
London
Hi guys, I’ve recently purchased some Hilook/Hikvision products. Was having issues with my previous Wifi camera setup in our estate with people jamming the cameras. Having issues with my new hikvision products which has led me to believe my devices are being hacked.

Are there any tools out there which i can use to test my devices for the vulnerability. Even better still, if i was to provide the ip addresses is there anyone who can test the devices for me as im very new to this whole networking stuff. Am willing to pay for the service.

If no one is available to do this maybe they know someone who can. Would be grateful if they could pass on the contact details.

Appreciate the help. Thanks
 

SpacemanSpiff

Known around here
Joined
Apr 15, 2021
Messages
1,471
Reaction score
2,474
Location
USA
Wifi can be jammed over the air, without having direct access to any of the devices. Are you sure the jamming was not simply a congested area? Meaning, a higher density of human population, leading to a lot of wifi routers all vying for channels and airtime?

You could employ the use of online vulnerability scanning tools, however it is only going to confirm what you already set-up... ports are open on your network putting any devices at risk. As for scanning the specific devices, identify the current firmware, and research the vulnerabilities of the version.

Do not allow your cameras direct access to the Internet. If the cams can't get out, then people hackers will not be able to get to the cameras.


 
Top