Skip to Main Content (Press Enter)

Logo UNIMORE
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze

UNI-FIND
Logo UNIMORE

|

UNI-FIND

unimore.it
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze
  1. Pubblicazioni

Finding (and Exploiting) Vulnerabilities on IP Cameras: The Tenda CP3 Case Study

Contributo in Atti di convegno
Data di Pubblicazione:
2024
Citazione:
Finding (and Exploiting) Vulnerabilities on IP Cameras: The Tenda CP3 Case Study / Stabili, D.; Bocchi, T.; Valgimigli, F.; Marchetti, M.. - 14977 LNCS:(2024), pp. 195-210. ( 19th International Workshop on Security, IWSEC 2024 Kyoto, Japan September 17–19, 2024) [10.1007/978-981-97-7737-2_11].
Abstract:
Consumer IP cameras are now the most widely adopted solution for remote monitoring in various contexts, such as private homes or small offices. While the security of these devices has been scrutinized, most approaches are limited to relatively shallow network-based analyses. In this paper, we discuss a methodology for the security analysis and identification of remotely exploitable vulnerabilities in IP cameras, which includes static and dynamic analyses of executables extracted from IP camera firmware. Compared to existing methodologies, our approach leverages the context of the target device to focus on the identification of malicious invocation sequences that could lead to exploitable vulnerabilities. We demonstrate the application of our methodology by using the Tenda CP3 IP camera as a case study. We identified five novel CVEs, with CVSS scores ranging from 7.5 to 9.8. To partially automate our analysis, we also developed a custom tool based on Ghidra and rhabdo-mancer.
Tipologia CRIS:
Relazione in Atti di Convegno
Elenco autori:
Stabili, D.; Bocchi, T.; Valgimigli, F.; Marchetti, M.
Autori di Ateneo:
MARCHETTI Mirco
Stabili Dario
VALGIMIGLI FILIP
Link alla scheda completa:
https://iris.unimore.it/handle/11380/1372231
Link al Full Text:
https://iris.unimore.it//retrieve/handle/11380/1372231/739645/2406.15103v2.pdf
Titolo del libro:
Advances in Information and Computer Security
Pubblicato in:
LECTURE NOTES IN COMPUTER SCIENCE
Journal
LECTURE NOTES IN COMPUTER SCIENCE
Series
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.4.5.0