1. Current Location: Home >  Comprehensive classification >  Will home cameras be spied on? I checked all six heads in the house one by one, and the most dangerous hole was made by the camera itself

Will home cameras be spied on? I checked all six heads in the house one by one, and the most dangerous hole was made by the camera itself

Home camera security self-check: cloud weak password, bare-knit port, second-hand unbinding—three routes plus five steps for self-check

A couple of days ago, my wife was scrolling through short videos and came across an investigation report secretly filmed by a camera. After reading it, she handed me her phone: "Could those six heads in our family be watched like this too?" I said, 'No way, it's all legitimate brands.' That said, that night I still went through all six heads one by one—you wouldn't know until you checked, and by the end, my palms were sweating: the biggest hole wasn't the password, but a door that the POE camera in the yard had quietly opened on the router.

first make your situation clear. The post my wife saw wasn't made up by social media. Back in December 2021, CCTV exposed cameras secretly filming the black industry chain, with hundreds of people watching a shower, and the person involved was completely unaware. The black market's approach is, frankly, very dumb but effective: use software to bulk scan public internet cameras, then use dictionaries to crack weak passwords, and admin, 123456, 888888 and similar systems get through in one round. Later reports said that cracked footage was bundled and sold for 260 yuan, allowing "permanent viewing." So there's no need to panic, but it's worth spending half an hour investigating.

to be clear: when others look at your camera

there are only three paths. Let's summarize all the cases. If your home camera is watched, there are only three main entrances.

first is to walk the clouds. If the manufacturer's account password is too weak for the camera, the black market takes the dictionary to the vendor's app interface for database mixing. Breaking through means they get all your footage and can even share and forward it. The second is the port route. Some people, in order to view surveillance on the external network, expose the camera's port 554 (RTSP stream port) to the public network via port forwarding or UPnP. A single address starting with rtsp:// username:password@yourIP:554 can directly pull away the footage. If the username and password are still factory-set, it's like the door isn't locked. Hikvision's port 8000 once had an authentication bypass vulnerability, CVE-2017-7921, which was widely exploited back then. The third and most unfair point: buying a second-hand camera, the original owner's account isn't unbound, you install it at home, and you can still see it in the previous owner's app.

How do you get into the black market where do you check
cloud weak passwords dictionary credential filling vendor accounts Camera App account settings
port bare scan the 554/8000 ports of the public network router port forwarding, and UPnP list
second-hand unbound, the original owner's account is still bound and the buyer and seller are still binding to perform the unbinding process face-to-face

my home has six heads. The one at the door with cloud storage occupies the first lane, and the five POE terminals in the yard connect to the VCR, occupying the door of the second lane. Below is the order in which I checked.

Step one: Check cloud accounts. This is the black market's favorite doorway

The cloud storage camera at the entrance was installed in 2022, and the account password was randomly set at the time—like a house number and birthday. This kind of password is no different from 123456 in a dictionary. I directly changed it to a 16-bit random string, saved it in the password manager, and enabled all verification methods for the account bound to the phone number.

two places prone to leakage. One is the device sharing or family member list in the app—for convenience, I once shared the camera with my wife's account, but later switched phones, and the share list still had an old account that had long been deleted. Posts that aren't needed are deleted entirely; the fewer people who can see the footage, the better. Second, device login management. Legitimate vendor apps have this section where you can see which phones have logged into the account. Unfamiliar devices are directly removed and passwords changed. If you have a remote login reminder feature, you can casually enable it. If your account is logged in in a strange place, you can immediately find out.

finished checking, the door to the cloud was closed. By the way, two-step account verification is open if possible; an extra step is useless no matter how large the database stuffing dictionary is.

Step two: Check the router. This step I found a cold sweat

second router. At my home, I use optical modem for bridge and AX3000T dial-up. I went to the 31.1 backend and first checked the port forwarding option in advanced settings—empty, as expected. A couple of years ago, I had one port on while experimenting with NAS remote control, but later switched to another plan and deleted it. I wrote about this in my post about using a VPN on router to remotely return home I stopped pursuing port forwarding long ago.

real problem lies in the UPnP mapping list. UPnP is a protocol that allows LAN devices to automatically open doors on routers. When I clicked to check, the list showed a line: the POE connector in the yard, which had registered the 554 port mapping on the router. In other words, the camera's firmware has "UPnP automatic port mapping" enabled by default. It opened the door itself the year it was built, and after three years, I never knew about it. To determine if this door is truly exposed to public networks, you need to see if your broadband has IP public network: WAN ports are shared outlets starting with 100.64, so if they can't scan you, that's a blessing in disguise; If there is a genuine public IP address, this port is just blatantly posted online waiting for someone to scan.

three steps to processing: delete this mapping from the router; The camera firmware backend turns off UPnP automatic mapping; otherwise, deleting it will re-register; If you find it troublesome, you can just turn off the router's main UPnP switch. I wrote about the cost and trade-offs in the article UPnP whether to turn it off or not. I don't have a game console or NAS at home that needs automatic hole punching, so turning it off is the most worry-free. As for what port forwarding itself is, why external ports use high positions, and the difference between port forwarding and DMZ that article explains this in detail.

Step 3: Check the camera's local device, default password, and firmware pause

the third stop to enter the webpage backend one by one. Enter the camera's IP in the browser, and among the five POEs, two still have factory passwords: username admin, password 123456. This password combined with port 554 above is the easiest to exploit on the black market list. All switched to 16-bit random strings, each head different—if you find it troublesome, at least don't let two units share one password, and if one device leaks, the entire line is lost.

check the firmware version while you're at it. Four out of six heads can be upgraded online to the latest level; There's an old model whose firmware hasn't been pushed by the manufacturer for three years. This type of head is either used for pure local recording when offline or moved to monitor less sensitive areas. Devices that stop updating are like old people stopping their medication—patches won't come again. Additionally, for families who don't need third-party software for streaming, turn off ONVIF and RTSP services in the camera backend, and just use the manufacturer's private protocol for the recorder's streaming pickup—one less service and one less entry point are needed.

by the way, the surveillance modified from an old phone actually doesn't have classic entry points like 554 or 8000. It uses the app's cloud channel, so the scan route doesn't exist, which is an unexpected advantage of the old method.

Step 4: Check the location. This step is even more important than the password

After technical checking, check the physics. I went through all six directions one by one: the front door looks outside, the yard looks at the yard, and the living room has diagonals avoiding the sofa—all are compliant. Here's a rule: bedrooms, bathrooms, any places where you can film the bed and changing clothes—a single veto—no matter how good the password is, it can't fix the wrong location—in cases of cloud leaks, the worst thing is never the image at the front door.

two physical foolproof actions are more realistic than any encryption. First, when not filming, turn the head of the gimbal toward the corner of the wall, and close the camera with physical blocking pads; Second, check for operational signs—the PTZ camera spinning on its own at night, unfamiliar rotation commands appear in the app's operation logs, or unfamiliar devices appear in login logins. If any of these three appear, cut off the power first and change the password. Don't hesitate.

Step 5: Essential steps before buying a second-hand camera, and the order of finishing

If you're planning to buy a second-hand camera, add a step before paying: have the seller unbind the device in person's app, then bind it with your own account. If the binding fails, you're usually locked under someone else's account. For carrier-customized phones and project-specific phones, it's especially important to ask carefully—some can't be untied at all, so don't buy them even if they're cheap. After buying, first restore it to the factory, then follow the five steps above.

I finished checking, here are five closing actions in order:

sequence actions my family's situation
1 Cloud account changed to a 16-digit password and enabled two-step verification__ At the HTML108__ gate, Yun Cun's head, I casually cleared old shares
2 deleted router UPnP mapping, turned off firmware auto-mapping found out I had opened it myself three years ago 554
3 camera, set the default password to turn off ONVIF both heads still use admin 123456
4 Checking the orientation and placement of each head, a veto for bedrooms and bathrooms
5 stopping old devices, disconnecting or relocating them moving a head that hasn't been updated for three years to monitor the storage room

checked everything in about forty minutes. If you ask what conclusion my six heads finally discovered: whether the footage was seen or not, I don't know, but the entrances were completely blocked. If you have a lot of surveillance at home, you can take it a step further by isolating devices like cameras on a separate network segment. Even if any one gets caught, they won't be able to reach your NAS and computer. The method is in the article VLAN home network slotting. As for how to plan points before installing surveillance and how to route the POE, the monitoring network planning is a familiar foundation; How many days can videos be stored, how to configure a hard drive, just read article.

Read More


Copyright Notice Scan to read on mobile
All Rights Reserved: 《SHUNOT》 => 《Will home cameras be spied on? I checked all six heads in the house one by one, and the most dangerous hole was made by the camera itself》
Article URL: https://www.shunot.com/en/zhonghe/1053.html
Unless otherwise stated, all articles are original by 《SHUNOT》. Reposting is welcome! Please indicate the original URL when reposting, thank you.

Contact Us

Online Consultation: Click here to send me a message

WeChat ID: master_135

Scan to follow