All playbooks

Playbook · beginner · 2–4 hours

Compromised IoT camera on home Wi-Fi

Discover a camera, prove weak auth/RTSP exposure on hardware you own, contain it, and harden the LAN so a cam cannot reach trusted devices.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Scenario

You notice an unfamiliar device on the guest/main Wi-Fi. It turns out to be an IP camera (or a lab camera VM). Your job is to inventory it, assess exposure, demonstrate risk proportionally, then remediate and segment.

Goals

Identify the camera via inventory + mDNS/ports

Show default/weak access or open RTSP on owned device only

Document impact in finding form

Apply password, firmware, and network segmentation fixes

Requirements

Camera or lab device you own

Scanning host on the same LAN

Router admin access for segmentation

Safety

Never scan or attack neighbors’ cameras

Cameras can be fragile — avoid aggressive floods

Prefer read-only proofs; do not brick devices

Steps

Step 1

Inventory and fingerprint

Intent: Know what the device is before touching it.

Actions

  • Pull DHCP leases and run arp-scan/nmap -sn
  • Lookup MAC OUI; note open ports with a light -sV
  • Check mDNS for camera-related services
Expected: Sheet row: IP, MAC, vendor, open ports (often 80/443/554/8000/8080).
Step 2

Web/RTSP surface check

Intent: Prove whether default credentials or unauthenticated streams exist.

Actions

  • Browse the web UI from a trusted admin host
  • Test only default creds listed by the vendor on your device
  • If RTSP is open, use Cameradar only against your camera IPs
Expected: Either confirmed strong auth, or a clear PoC (login success / stream path) with screenshot.

Pitfalls

  • Do not brute-force forever on fragile cams
  • Cloud-tethered cams may phone home — note that
Step 3

Impact write-up

Intent: Turn access into a professional finding.

Actions

  • Use the finding template: impact = privacy, household safety, pivot risk
  • Capture evidence; avoid storing personal video
Expected: One complete finding draft with remediation section started.
Step 4

Contain and harden

Intent: Remove easy attack paths and limit blast radius.

Actions

  • Change password; disable unused cloud/UPnP features
  • Update firmware if available
  • Move cam to IoT/guest SSID or VLAN; block IoT → trusted LAN
  • Re-scan from trusted segment to verify isolation
Expected: Camera cannot reach NAS/PCs; admin path documented.

Remediation outcomes

Unique strong password; no defaults

Firmware current; auto-update if trustworthy

IoT VLAN/SSID with no lateral access to trusted LAN

No WAN port-forward to camera; remote access via VPN only

Inventory entry updated with last-hardened date