Discovery: A Webcam Running Linux

▶ Watch (0:04)

Mickey bought a 60 fps webcam and later sought a firmware update. The updater extracted files including an ash script, Uboot, and OTAA. He opened the device and found a Sigma Star SoC with no visible memory. After soldering UART pads, he saw Linux booting. The firmware was an 8 MB binary containing a full Linux system. That discovery triggered the research.

Firmware Update Over USB: UVC and SCSI

▶ Watch (5:43)

Jesse explains the update process. The tool uses UVC extension units to switch the camera into update mode. The camera reboots as a mass storage device. Vendor-specific SCSI op codes send Uboot and updater.bin. Uboot commands are transmitted as literal strings. The update erases the root filesystem and kernel before writing new data. No rollback on checksum failure.

Custom Firmware: From Camera to Attack Platform

▶ Watch (13:13)

Mickey built a custom kernel with HID gadget support. He added an environment variable “implant”. When set to 1, the camera boots as a keyboard that opens an admin command prompt and types a payload, then reboots normally. He also added an RNDIS network gadget and used Windows Internet Connection Sharing to give the camera internet access. A Metasploit reverse shell from the cloud to the camera was established via the gadget.

Other Vendors and an Uboot Zero-Day

▶ Watch (27:35)

The team checked other cameras: Opal Tadpole (Ambarella SoC), OBSBOT, Nexigo, and TPLink. For Opal Tadpole, they discovered an 0-day. By holding Enter during boot, they accessed Uboot, changed environment variables to mount NAND read-write and init to /bin/sh, then saved. This gave a root shell. After reverting, the camera boots normally. The disclosure was rated medium severity.

Q&A

How long did it take to reverse the camera? Minutes. ▶ 36:36

Can anyone buy one of these, flash it, and resell it? Yes. ▶ 37:06

How many times did Linux fail to build? Several times due to incomplete source code and a bug in the HID gadget that was patched in the second GPL code drop. ▶ 37:36

Could this method be used to implement an IP webcam? Yes, but they lacked kernel modules for the IR and CMOS chips. ▶ 40:10

Notable Quotes

What the [ __ ] Why does a webcam need almost an 8meg firmware update? Mickey Shkatov · ▶ 3:04

i can’t believe i’m saying this Um there’s uh apparently there’s Linux and webcams now. Mickey Shkatov · ▶ 31:37

It’s a bash bunny basically with a camera. Audience member paraphrased by speaker · ▶ 41:10

This is not a camera. Mickey Shkatov · ▶ 35:29

Key Takeaways

  • Many webcams run full Linux on Sigma Star SoCs, turning them into attack platforms via USB gadgets.
  • Firmware updates over USB lack integrity checks; erasing before writing risks bricking.
  • GPL compliance requests to Chinese vendors often require public shaming or contacting co-founders on LinkedIn.

About the Speaker(s)

Mickey Shkatov has been involved in security research for over a decade, specializing in breaking down complex concepts and identifying security vulnerabilities in unusual places. His experience spans a variety of topics, which he has presented at security conferences worldwide. His talks have covered areas ranging from web penetration testing to the intricacies of BIOS firmware.

Jesse Michael is an experienced security researcher focused on vulnerability detection and mitigation who has worked at all layers of modern computing environments from exploiting worldwide corporate network infrastructure down to hunting vulnerabilities inside processors at the hardware design level. His primary areas of expertise include reverse engineering embedded firmware and exploit development. He has also presented research at DEF CON, Black Hat, PacSec, Hackito Ergo Sum, Ekoparty, and BSides Portland.