Penetration Testing mailing list archives
Re: Webcams
From: ManInWhite <maninwhite () tpg com au>
Date: Fri, 24 Aug 2007 20:18:32 +0930
One way to do this would be to write a batch script to scan all known PC hosts (export list from Active Directory) one by one with DevCon http://support.microsoft.com/kb/311272/ and dump the results of a listclass for multimedia device type. This could then be filtered for "Logitech QuickCAM" or "webcam" etc
This tool also allows a user with administrative rights to install, list or remove devices. (or disable) This tool works on 2k/xp/2003. It was written pre-Vista so i do not know what luck you will have probing machines running that.
Doing this all remotely is neat too...Imagine the webcam users surprise when when returning to work monday and suddenly find video skype calls to their uncle in new york is broken.
Might be a good way to do an automated site wise hardware audit too. MiW p1g wrote:
You could maybe query WMI via vbs, perl, WMI, nessus, etc. You could query the filesystem or registry for installed camera software. query registery for usb devices. If you knew what model of camera was being used, it would ne easier :) , yea, i know... FYI.. The nessus-users list would be a good place to ask. Sometimes this list(pen-test) reacts differently to the 'I want to search my network for stuff' questions. On 8/23/07, Holstein, Robert - BLS CTR <Holstein.Robert () bls gov> wrote:Does anyone have a method for remotely detecting webcams installed on Windows hosts? I have the need to conduct an audit to find out if certain staff are using webcams. I may have administrative rights to the targets remotely, but no physical, or console access. Any input would be appreciated. Thank you, Robert C. Holstein IT Security Analyst Bureau of Labor Statistics (202)-691-7611 ------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
Current thread:
- Webcams Holstein, Robert - BLS CTR (Aug 23)
- Re: Webcams p1g (Aug 23)
- Re: Webcams ManInWhite (Aug 24)
- RE: Webcams Holstein, Robert - BLS CTR (Aug 24)
- Re: Webcams Luca Carettoni (Aug 24)
- RE: Webcams Richard Lane (Aug 25)
- Re: Webcams Jan Heisterkamp (Aug 26)
- Re: Webcams rajat swarup (Aug 28)
- Re: Webcams Jan Heisterkamp (Aug 26)
- <Possible follow-ups>
- Re: Webcams anastasiosm (Aug 24)
- Re: Webcams p1g (Aug 23)