Hasty Briefsbeta

Bilingual

My security camera shipped a GitHub admin token in its login page

4 hours ago
  • AXIS is pushing for Linux apps on cameras, increasing security risks.
  • Hanwha Vision cameras have accessible firmware blobs for analysis.
  • Initial firmware decryption uses passphrase 'HTW' + model number.
  • Inner firmware has AES encryption with key XOR-obfuscated in binary.
  • Decryption uses hardcoded key and IV across the model line.
  • Reconstructed OpenSSL command reveals key and IV for decryption.
  • A GitHub token with admin privileges found in 30 firmware files.
  • Token exposure stems from build process dumping CI environment variables.
  • CI environment also contained DoD IP addresses, suggesting ties to defense.
  • Out of ~500 firmwares, only 3 had the same GitHub token; Hanwha revoked it promptly.