Playbook · beginner · 2–4 hours
Compromised IoT camera on home Wi-Fi
Discover a camera, prove weak auth/RTSP exposure on hardware you own, contain it, and harden the LAN so a cam cannot reach trusted devices.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Scenario
You notice an unfamiliar device on the guest/main Wi-Fi. It turns out to be an IP camera (or a lab camera VM). Your job is to inventory it, assess exposure, demonstrate risk proportionally, then remediate and segment.
Goals
Identify the camera via inventory + mDNS/ports
Show default/weak access or open RTSP on owned device only
Document impact in finding form
Apply password, firmware, and network segmentation fixes
Requirements
Camera or lab device you own
Scanning host on the same LAN
Router admin access for segmentation
Safety
Never scan or attack neighbors’ cameras
Cameras can be fragile — avoid aggressive floods
Prefer read-only proofs; do not brick devices
Steps
Inventory and fingerprint
Intent: Know what the device is before touching it.
Actions
- Pull DHCP leases and run arp-scan/nmap -sn
- Lookup MAC OUI; note open ports with a light -sV
- Check mDNS for camera-related services
Web/RTSP surface check
Intent: Prove whether default credentials or unauthenticated streams exist.
Actions
- Browse the web UI from a trusted admin host
- Test only default creds listed by the vendor on your device
- If RTSP is open, use Cameradar only against your camera IPs
Pitfalls
- Do not brute-force forever on fragile cams
- Cloud-tethered cams may phone home — note that
Impact write-up
Intent: Turn access into a professional finding.
Actions
- Use the finding template: impact = privacy, household safety, pivot risk
- Capture evidence; avoid storing personal video
Contain and harden
Intent: Remove easy attack paths and limit blast radius.
Actions
- Change password; disable unused cloud/UPnP features
- Update firmware if available
- Move cam to IoT/guest SSID or VLAN; block IoT → trusted LAN
- Re-scan from trusted segment to verify isolation
Remediation outcomes
Unique strong password; no defaults
Firmware current; auto-update if trustworthy
IoT VLAN/SSID with no lateral access to trusted LAN
No WAN port-forward to camera; remote access via VPN only
Inventory entry updated with last-hardened date