HN
Today

My security camera shipped a GitHub admin token in its login page

A security researcher's deep dive into Hanwha Vision security camera firmware uncovered a significant GitHub admin token leak, a result of carelessly exposed environment variables in the build process. The discovery also revealed unexpected references to US Department of Defense IP addresses, sparking speculation given the manufacturer's defense industry ties. Hacker News found the blend of technical vulnerability and geopolitical intrigue particularly captivating.

20
Score
6
Comments
#1
Highest Rank
8h
on Front Page
First Seen
Jul 24, 1:00 PM
Last Seen
Jul 24, 8:00 PM
Rank Over Time
71113344

The Lowdown

Security researcher 'hhh' embarked on an investigative journey into Hanwha Vision security camera firmware, a pursuit that unveiled a critical security lapse. What started as routine firmware analysis quickly escalated into a more profound discovery.

  • Firmware Fortunes: Initial attempts to decrypt the firmware using a previously known method worked for an outer layer, but a deeper, more robust encryption scheme required reverse-engineering the fwupgrader binary. This process revealed that the AES key and IV were hardcoded and XOR-obfuscated within the binary, ultimately allowing full access to the root filesystem.
  • Token Treasure: Upon gaining access, trufflehog immediately flagged a GitHub admin token, which was astonishingly duplicated across approximately 30 files within the firmware. This token held extensive administrative privileges over hundreds of repositories in Hanwha's GitHub organization.
  • Build Blunder: The root cause of the token's exposure was traced back to the camera's UI build process, where the entire process.env was inadvertently written into various build files, exposing sensitive CI environment variables.
  • DoD Data: Further analysis unearthed environment variables referencing IP addresses belonging to the US Department of Defense. This raised questions, particularly given Hanwha's parent company, Hanwha Group, has significant defense divisions like Hanwha Aerospace and Hanwha Defense USA.
  • Limited Scope, Broad Impact: While a broader scrape of ~500 Hanwha firmwares showed that only 3 contained this specific token, the implications of such a leak, especially from a company with defense ties, are considerable.
  • Responsible Disclosure: The researcher promptly reported the vulnerability to Hanwha, who swiftly responded within 12 hours to confirm the token's revocation, demonstrating a surprisingly efficient resolution process for such a significant find.

This incident serves as a stark reminder of the persistent and often surprising ways sensitive credentials can be exposed in embedded systems, underscored by the unsettling potential for connections to national security interests.

The Gossip

DoD IP Debates

Commenters were particularly fixated on the discovery of US Department of Defense IP addresses within the firmware's environment variables. Some posited that companies might 'black-hole' such IP ranges for internal use, treating them as 'free real estate' because they expect no external interaction. Others expressed concern, questioning the implications for a Korean security product and the potential for a deeper, more unsettling connection between Hanwha and the DoD.

Pervasive Credential Problems

The discussion extended beyond the specific GitHub token to the broader, recurring issue of organizations embedding sensitive credentials directly into products or firmware. One commenter recounted a similar widespread flaw involving OBD-II dongles that shared the same MAC address, which then served as a universal authentication key for various associated apps and websites, highlighting a systemic failure in credential management across different industries.