Penetration Testing mailing list archives

Re: Webcams


From: ManInWhite <maninwhite () tpg com au>
Date: Fri, 24 Aug 2007 20:18:32 +0930

One way to do this would be to write a batch script to scan all known PC hosts (export list from Active Directory) one by one with DevCon http://support.microsoft.com/kb/311272/ and dump the results of a listclass for multimedia device type. This could then be filtered for "Logitech QuickCAM" or "webcam" etc

This tool also allows a user with administrative rights to install, list or remove devices. (or disable) This tool works on 2k/xp/2003. It was written pre-Vista so i do not know what luck you will have probing machines running that.

Doing this all remotely is neat too...
Imagine the webcam users surprise when when returning to work monday and suddenly find video skype calls to their uncle in new york is broken.

Might be a good way to do an automated site wise hardware audit too.

MiW

p1g wrote:
You could maybe query WMI via vbs, perl, WMI, nessus, etc.

You could query the filesystem or registry for installed camera software.

query registery for usb devices.

If you knew what model of camera was being used, it would ne easier :)
, yea, i know...


FYI..
The nessus-users list would be a good place to ask.

Sometimes this list(pen-test) reacts differently to the 'I want to
search my network for stuff' questions.



On 8/23/07, Holstein, Robert - BLS CTR <Holstein.Robert () bls gov> wrote:
Does anyone have a method for remotely detecting webcams installed on
Windows hosts?  I have the need to conduct an audit to find out if
certain staff are using webcams. I may have administrative rights to the
targets remotely, but no physical, or console access.
Any input would be appreciated.

Thank you,
Robert C. Holstein
IT Security Analyst
Bureau of Labor Statistics
(202)-691-7611


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------






------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: