Security researcher found 67 exposed Flock camera feeds and debug interfaces across 15 states
Researcher "GainSec," with input from Benn Jordan and 404 Media's Jason Koebler, found 67 unauthenticated Flock PTZ and LPR feeds and debug web interfaces exposed on Verizon Business infrastructure. Exposed data included device serial numbers and camera IDs, RTSP digest credentials and session IDs, Auth0 tokens, FRP tunnel session identifiers, video file paths, cleartext passwords on some units, and system logs. The root cause was described as devices on cellular connections lacking carrier-grade NAT and ISP-level firewalling, combined with services binding to all interfaces.
The other side The researcher reported the findings before publishing, and says all 67 were no longer exposed by the final check.
Source · GainSec · read it