Network Video Recorders (NVR) are network devices that record and store video from local and remote IP cameras on HDD storage. These NVRs are increasingly used in surveillance systems of homes and businesses. In this presentation, we will analyze the (in)security of NVRs from one of the reputed manufacturers of these devices. The presentation will cover how NVRs work, analysis of NVR firmware and a step-by-step demo of how an attacker could take complete control of these devices. Once an attacker has control of the device, he can monitor videos from all the cameras connected to the device in real time from anywhere via his smartphone.
I will also release a tool to remotely detect and own a vulnerable device in the wild.