A recent discovery has revealed that a security camera shipped with a GitHub admin token in its login page. The token, which was found in the camera's firmware, has administrative privileges to hundreds of repositories in the manufacturer's GitHub organization [1]. The firmware was downloaded from the manufacturer's website, and the token was extracted using a combination of tools, including binwalk and ghidra [2]. The discovery was made by a security researcher who was analyzing the camera's firmware and found the token in a file that was not encrypted [3].
The researcher noted that the token was duplicated in multiple files, suggesting that it may have been accidentally included in the firmware. The manufacturer, Hanwha, has since revoked the token and notified the researcher of the action taken [4]. The incident highlights the importance of secure coding practices and the need for manufacturers to ensure that their products do not expose sensitive information, such as admin tokens [5]. In addition to the GitHub token, the researcher also found IP addresses assigned to the US Department of Defense in the camera's firmware, which has raised questions about the potential connection between the manufacturer and the DoD [6].
The researcher has speculated that the IP addresses may be related to the manufacturer's sister company, Hanwha Defense USA, which produces military equipment [7]. The incident has sparked a discussion about the potential risks of including sensitive information in firmware and the need for better security practices in the manufacturing industry [8].
Sources
- https://brownfinesecurity.com/blog/hanwha-firmware-file-decryption
- https://www.axis.com/products/acap
- https://news.ycombinator.com/item?id=49034292
- https://hanwhadefenseusa.com
- https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens
- https://en.wikipedia.org/wiki/Hanwha_Vision
- https://www.facebook.com/WIONews/videos/cisa-credentials-exposed-on-githubcisa-system-tokens-were-left-publicly-accessib/1905906803436931
- https://www.reddit.com/r/webdev/comments/1v5i57x/my_security_camera_shipped_a_github_admin_token/

