Slashdot Log In
Thieves Hacking Security Cameras?
Journal written by Erris (531066) and posted by
samzenpus
on Thu Aug 30, 2007 07:04 AM
from the steal-from-home dept.
from the steal-from-home dept.
The FBI is investigating fifteen store robberies in eleven states, committed via phone and internet. The perpetrators hack the store's security system so they can observe their victims. They then make customers take their clothes off and get the store to wire money. From the article, "A telephone caller making a bomb threat to a Hutchinson, Kan., grocery store kept more than 100 people hostage, demanding they disrobe and that the store wire money to his bank account. ... officials were investigating whether the caller was out of state and may have hacked into the store's security system. "If they can access the Internet, they can get to anything," Hutchinson Police Chief Dick Heitschmidt said. "Anyone in the whole world could have access, if that's what really happened.""
Related Stories
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading ... Please wait.

Dumber than dumb (Score:5, Insightful)
"If they can access the Internet, they can get to anything," Hutchinson Police Chief Dick Heitschmidt said. "Anyone in the whole world could have access, if that's what really happened."
Re: (Score:3, Insightful)
Re:Dumber than dumb (Score:5, Informative)
Re:Dumber than dumb (Score:5, Funny)
Re: (Score:2)
Re:Dumber than dumb (Score:5, Interesting)
Those who have a place in the system have no place in a jury.
Re:Dumber than dumb (Score:4, Insightful)
Re:Dumber than dumb (Score:5, Funny)
"If they can access the Internet, they can get to anything," Hutchinson Police Chief Dick Heitschmidt said. "Anyone in the whole world could have access, if that's what really happened."
Yes. I think "No, it's not loaded! Here, I'll prove it to you!" beats it.
Re: (Score:3, Informative)
If only we could get Police Chief Dick Heitschmidt to say that as well
Re:Dumber than dumb (Score:4, Funny)
"internet hate machine"
Wait until these stores get dogs and curtains, than we'll be REALLY fucked.
Re:Dumber than dumb (Score:5, Funny)
"He then demanded that one of Piros' fingers be cut off for every hour his demands were not met, and another employee got a butcher knife on his orders"
Anybody wanna take bets on who was the first person fired after this incident?
Re:Dumber than dumb (Score:4, Interesting)
They'd probably harbor a sleeper cell in the loading dock as long as their supply chain of cheap Chinese crap doesn't slow down.
Hacking security cameras, huh? (Score:5, Funny)
"wire money to his bank account"? (Score:5, Interesting)
Strange.
Re:"wire money to his bank account"? (Score:5, Informative)
Get the RIAA in on the case! (Score:5, Funny)
Re: (Score:3, Funny)
Is the footage on YouTube? (Score:5, Funny)
CCTV (Score:5, Interesting)
Re:CCTV (Score:5, Funny)
Re:CCTV (Score:5, Interesting)
Many companies are cutting back on security staff by eliminating in-store people that watch the TV screens. The stores still have some roving security people, but the TV screen watching is now more automated, more centralized, and in some cases even pushed out to homes where people with broadband can be paid even less than the in-store people to sit and watch a bunch of TV camera images for hours, looking for suspect people.
It might be interesting if someone developed a way to fool those systems into thinking someone is watching (frequently clicking to see the next camera).
Re:CCTV (Score:5, Interesting)
Most of our clients are hell-bent on having internet access so that they can remotely view and control their cameras, card access systems, and PA systems.
Although it is possible to hack these systems, it is a remote chance if configured properly like anything else.
My guess is that these incidents are with default usernames and passwords on the DVR and other equipment.
However, my question is: how did they find the IP of a target store?
It's one thing to want to rob a store, but it's another to know this type of sensitive information.
And in many cases, even large stores are using DSL or Cable where they get a dynamic IP.
Sounds like an inside job to me.
Re: (Score:2)
Re: (Score:2)
In the olden days of modem-connected monitoring equipment, we called it "war dialing". What do the kids call it now, "war surfing"? Start at 0.0.0.0 and increment through FF.FF.FF.FF,
IP sensitive? (Score:2)
Wireless (Score:5, Interesting)
In my WarDriving travels, I've come apon many SSID-hidden wireless networks around stores. Sometimes they aren't even encrypted. My recent curiosity with these nets reveals a few wifi networked cameras in some locations, and sometimes if you log into these networks, you can find a nat. From there it's simply accessing a site that gives you a IP.
But why bother when you already have access to there cameras via a unsecured access point?
Anonymous for obvious reasons.
Re: (Score:3, Insightful)
They rarely are. as a Technology specialist company that also does cameras, we find that 9 times out fo ten the default passwords are set for t
Re:CCTV (Score:4, Informative)
see here [kansas.com]
Oh and no bombs have ever been found, there are a lot of embarrassed people out there who have really overreacted to these 'menacing & scary' phone calls.
Why CCTV is on the internet (Score:5, Informative)
Rather than build a dedicated hardwired telecom network, companies are using the internet to connect everything together (security systems, financial systems, medical records, industrial control, etc.) As we can see from this example, they think they've created their own virtual network (of some degree of privacy), but in practice, the system is extremely vulnerable. I'd bet that more than a few internet-connected security cameras run with factory-default passwords.
Re: (Score:2)
And even if they change it, there's still the "Joshua" back door.
Re: (Score:2)
I don't know that they actually are interwebbed, but if they were, it would be to save money over having a dedicated
Re:CCTV (Score:5, Interesting)
Two weeks after installation, the thieves broke in. When they saw the cameras and the DVR, they set fire to the place to destroy the evidence, but the still photos were enough to identify and convict them. They haven't had a problem since.
Re:CCTV (Score:5, Funny)
Re:CCTV (Score:4, Informative)
Read further in TFA:
Initially, the caller led employees to believe he was observing them.
"After a while, it sounded like he was just taking a shot in the dark at what they might be doing, or what they looked like or how they were reacting to his call," Prescott police Lt. Ken Morley said.
I was fooled too (Score:5, Funny)
Also, would CowboyNeal please send back my $3,000?
Sparks (Score:2)
How are those net-enabled security cameras working out for you?
Re: (Score:3, Funny)
Internet security system .. (Score:3, Insightful)
"If they can access the Internet, they can get to anything"
"Anyone in the whole world could have access, if that's what really happened"
What kind of idiot would connect the security system to the Internet so that 'they' could get to anything. Didn't they put it on a private VPN or use a password even?
"The FBI was looking into whether the calls to the banks and stores were being placed from overseas"
I thought DCSNet [slashdot.org] was designed to provide instant access to such information. Provides absolutly no evidence of any such hacking. Sounds to me like a low level extortion plot apart from the mention of the (scary) Internet and hackers (even more scary). Since when do sophisticated thieves use Western Union and wire themselves $3,000 with a $150 service charge. Who paid the charge I wonder.
We get bomb threats here all the time, so don't take any notice
"hacked" by simply using Google? (Score:3, Insightful)
There are many store monitor camera systems that are installed with poor defaults and wide open access. Several makers' web interfaces have easy formulaic URLs to select different store views, and these commonly can be searched with plain old web search engines. This was a fun thing to do a few years back, with whole sites dedicated to lists of web cams that were likely not intended for global viewership. Without any real evidence that the web cameras were "hacked" I think it's a big stretch to assume any skill was involved here.
Another law broken? (Score:5, Funny)
In other news... (Score:4, Informative)
And have fun...
One of the dumber scams I've ever read about (Score:3, Insightful)
This was a hoax, a prank. Somebody was just having fun jerking people around.
And see how easy it was. Anybody remember the Chinese Fire Drill in the book "Illuminatus?" Act authoritative - or threatening in this case - and spew out some orders, and everybody falls right into line like lemmings.
The first response to the bomb threat should have been, "Fine - set it off. We'll settle up later, asshole."
Cats Pets Donau City Strasse .. (Score:2)
Re:Duh (Score:5, Informative)
ALL of this stuff goes right back to raging incompetence. It's incredible how little these stores pay for IT, I had to teach the IT specialists for Walmart how to do basic networking when we were helping a client set up their network for their restaurant inside a new walmart store. The Walmart head of networking, or so he claimed to be, told me it was impossible to tunnel IP traffic safely through a network, no. he did not understand what a VPN was and then told me that VPN is not allowed as it's insecure and unencrypted!.... and then I had to hold their hands and show them how easy is really is to patch a phone line to a cat 5 jack in the phone room. Their network engineer told me flat out that DSL will not work over cat-5e cable. "The phone company uses Cat6 to your house!" is what he said. I was amazed at how undereducated these IT and networking people were.
With that kind of incompetence due to very low pay, it does not surprise me that security cameras are put on the net directly.
Re: (Score:3, Insightful)
1. The cheapest guy gets the job. Now, the cheapest is never the best, and rarely even good enough to actually do it good.
2. As soon as it "works", stop working on it. As soon
YOU FUCKING LOVE IT (Score:5, Interesting)
Re: (Score:2)
Re:Duh (Score:5, Funny)
"Hi, I am ze plumber. I haf com to examine ze pipework, ver can I place my tooool ? It is ver huge and I can't keep it in here much longer"
Re: (Score:3, Insightful)
Re: (Score:3, Funny)
2. Receive bomb threat
3. Ignore demands, find bomb
4. Sell bomb on black market
5. Profit!!!
6. Goto Step2