Tag Archives: security

So what if the camera is on the internet?

Also available in: Polski Polski

Sekurak [1] [ Polish portal providing substantive information on cyber security.] recently published an article about cameras at one of the railway stations being directly accessible from the internet. Comments such as ‘so what?’ quickly appeared under the post. At first glance, it may indeed seem that this is not a big deal – just an image from one camera.

The problem begins when we look at such data through the prism of today’s analytical capabilities. In the age of AI, image recognition and big data analysis, even a single video source can provide very valuable information: about the movement of people, behaviour patterns, meetings or logistics in a given place.

It is worth comparing this seemingly trivial situation with a recent report by The Telegraph, which stated: ‘Israel hacked Tehran’s traffic cameras to spy on Khamenei […] Israel hacked nearly all of Tehran’s traffic cameras to spy on Ali Khamenei before launching an attack to kill Iran’s supreme leader.’ This shows that camera infrastructure – especially when it covers public spaces – can have significance far beyond simple surveillance.

Even a single camera at a station, with audio enabled or not, can be a very valuable source of information. What is more, it is easy to be misled into thinking that such a device is only a passive sensor. In practice, however, an IP camera is nothing more than a small computer connected to a network.

This means that it often runs on an old, outdated operating system with a vulnerable web interface and many known security vulnerabilities. In such a scenario, the camera can become an entry point into the infrastructure, act as a jump host, enable network reconnaissance, and even lead to privilege escalation through vulnerabilities in the management interface (e.g., XSS or other classic web application errors).

In short, it is not just a camera. It is an element of IT infrastructure operating in a very sensitive location.

Additionally, I am willing to bet that the first thing the “administrator” of this camera did after receiving information that it was accessible from the Internet was to panic and log in from their workstation (with a million other tabs open, cached permissions, and perhaps even an administrative account). He logged into the unfortunate camera to check and “change the password”. If the editors of Sekurak could log into it, so could thousands of others. They might not have been so nice and could have modified its software and introduced malicious modifications to its code. Such devices should be treated as compromised and dangerous. Just as a doctor would treat a patient who came to a visit with bleeding tears and blisters on their skin.

And if we start to consider scenarios in which the compromise of such infrastructure could lead to real, kinetic effects in the physical world… that’s a topic for a separate post.

[1] https://www.linkedin.com/posts/michal-sajdak_kamera-z-jednego-z-polskich-dworc%C3%B3w-by%C5%82a-activity-7431610592974594048-2v82?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAEbrCYBiG9XAnLpx0DqmwqjjuBF1MrYIkE

[2] https://www.telegraph.co.uk/world-news/2026/03/03/israel-hacked-iranian-traffic-cameras-to-spy-on-khamenei/

Microsoft Patches 10/2016

Also available in: Polski Polski

Microsoft starts to provide ‘update bundles’…

Critical and Security Updates
Update for Windows 7 (KB3177467)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
Update for Windows 7 for x64-based Systems (KB3177467)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
October, 2016 Security Only Update for .NET Framework 3.5.1 on Windows 7 SP1 and Windows Server 2008 R2 SP1 for x64 (KB3188730)
A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system.
October, 2016 Security Only Update for .NET Framework 3.5.1 on Windows 7 SP1 (KB3188730)
A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system.
October, 2016 Security and Quality Rollup for .NET Framework 3.5.1 on Windows 7 SP1 and Windows Server 2008 R2 SP1 for x64 (KB3188740)
A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system.
October, 2016 Security and Quality Rollup for .NET Framework 3.5.1 on Windows 7 SP1 (KB3188740)
A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system.
October, 2016 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB3185330)
A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system.
October, 2016 Security Monthly Quality Rollup for Windows 7 (KB3185330)
A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system.
Security Update for Microsoft SharePoint Server 2010 (KB3118377)
A security vulnerability exists in Microsoft SharePoint Server 2010 that could allow arbitrary code to run when a maliciously modified file is opened. This update resolves that vulnerability.
Security Update for Microsoft Office 2010 (KB3118317) 32-Bit Edition
A security vulnerability exists in Microsoft Office 2010 32-Bit Edition that could allow arbitrary code to run when a maliciously modified file is opened. This update resolves that vulnerability.
Security Update for Microsoft Word 2010 (KB3118312) 64-Bit Edition
A security vulnerability exists in Microsoft Word 2010 64-Bit Edition that could allow arbitrary code to run when a maliciously modified file is opened. This update resolves that vulnerability.
Security Update for Microsoft Silverlight (KB3193713)
This security update to Silverlight includes fixes outlined in KB 3193713. This update is backward compatible with web applications built using previous versions of Silverlight.
Security Update for Microsoft SharePoint Server 2010 (KB3118377) farm-deployment
A security vulnerability exists in Microsoft SharePoint Server 2010 that could allow arbitrary code to run when a maliciously modified file is opened. This update resolves that vulnerability.
Security Update for Lync 2010 X86 (KB3188397)
A security issue has been identified in a Microsoft Lync software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system.
Security Update for Lync 2010 X64 (KB3188397)
A security issue has been identified in a Microsoft Lync software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system.
Security Update for Microsoft Office 2010 (KB3118311) 64-Bit Edition
A security vulnerability exists in Microsoft Office 2010 64-Bit Edition that could allow arbitrary code to run when a maliciously modified file is opened. This update resolves that vulnerability.
Security Update for Microsoft Web Applications (KB3118384)
A security vulnerability exists in Microsoft Web Applications that could allow arbitrary code to run when a maliciously modified file is opened. This update resolves that vulnerability.
Security Update for Lync 2010 Attendee – Administrator level installation (KB3188400)
A security issue has been identified in a Microsoft Lync software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system.
Security Update for Microsoft Office 2010 (KB3118311) 32-Bit Edition
A security vulnerability exists in Microsoft Office 2010 32-Bit Edition that could allow arbitrary code to run when a maliciously modified file is opened. This update resolves that vulnerability.
Security Update for Microsoft Office 2010 (KB3118317) 64-Bit Edition
A security vulnerability exists in Microsoft Office 2010 64-Bit Edition that could allow arbitrary code to run when a maliciously modified file is opened. This update resolves that vulnerability.
Security Update for Microsoft Word 2010 (KB3118312) 32-Bit Edition
A security vulnerability exists in Microsoft Word 2010 32-Bit Edition that could allow arbitrary code to run when a maliciously modified file is opened. This update resolves that vulnerability.
Security Update for Microsoft Web Applications (KB3118384) farm-deployment
A security vulnerability exists in Microsoft Web Applications that could allow arbitrary code to run when a maliciously modified file is opened. This update resolves that vulnerability.
October, 2016 Security Only Quality Update for Windows 7 (KB3192391)
A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system.
October, 2016 Security Only Quality Update for Windows 7 for x64-based Systems (KB3192391)
A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system.
Other Updates
Windows Malicious Software Removal Tool – June 2016 (KB890830)
After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product.
Windows Malicious Software Removal Tool x64 – June 2016 (KB890830)
After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product.
Update for Windows 7 (KB3063109)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
Update for Windows 7 for x64-based Systems (KB3063109)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
Update for Windows 7 for x64-based Systems (KB2952664)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
Update for Windows 7 (KB2952664)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
Microsoft Silverlight (KB3193713)
Microsoft Silverlight is a Web browser plug-in for Windows and Mac OS X that enables users to experience high quality media and to access rich Internet applications (both in and out of browser) within the browsers’ security model. For video and audio, Silverlight supports various media formats including Windows Media and H.264 up to HD quality. A comprehensive platform for creating rich user experiences, Silverlight includes the .NET framework, is supported by the Visual Studio and Expression tools, and integrates with Microsoft and other internet and server technologies.
Windows Malicious Software Removal Tool x64 – October 2016 (KB890830)
After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product.
Update for Windows 7 (KB2952664)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
Windows Malicious Software Removal Tool – October 2016 (KB890830)
After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product.
Update for Windows 7 for x64-based Systems (KB2952664)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
Update for Windows 7 for x64-based Systems (KB3181988)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
Update for Windows 7 (KB3181988)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
Update for Windows 7 for x64-based Systems (KB3184143)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
Update for Windows 7 (KB3184143)
Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.

More: https://blogs.technet.microsoft.com/windowsitpro/2016/08/15/further-simplifying-servicing-model-for-windows-7-and-windows-8-1/