الكاميرات وكلمة مرور المصنع
الكاميرا تظهر في محركات الفحص العامة لسببين مترابطين: أن الراوتر مرّر منفذها إلى الإنترنت، وأنها ما زالت على كلمة مرور المصنع. سُور يعالج السببين معًا من داخل الشبكة قبل أن يجدها الماسح الخارجي.
سُور لا يجرّب كلمة مرور على أي كاميرا، لأن هذا يجعله أداة هجوم. بدلًا من ذلك يكشف الضعف بثلاث طرق دفاعية: يقرأ جدول UPnP في الراوتر ليعرف إن كان منفذ الكاميرا مفتوحًا إلى الإنترنت، ويتعرّف على طراز الكاميرا فيقول لك إن هذا الطراز يُشحن ببيانات دخول معروفة للعامة، ويقرأ صفحة دخولها إن أعلنت أنها بلا كلمة مرور أو قبلت البث دون مصادقة.
القائمة نفسها من بيانات المصنع هي ما تستعمله محركات الفحص، ووجودها في المشروع للتوعية بضرورة تغييرها لا لاستعمالها.
Cameras and the factory password
A camera appears on public scanning engines for two linked reasons: the router forwarded its port to the internet, and it is still on its factory password. Soor addresses both from inside the network before an outside scanner finds it.
Soor never tries a password on any camera, because that would make it an attack tool. Instead it detects the weakness three defensive ways: it reads the router's UPnP table to see whether the camera's port is open to the internet, it identifies the camera model and tells you that model ships with publicly known login details, and it reads the login page when it announces it has no password set or serves the stream without authentication.
The same factory-credential list is what scanning engines use; it is in the project to raise awareness that they must be changed, not to be used.