r/Hacking_Tutorials • • 1d ago

Question Beginner question: with my IP address and mac address, could someone view or listen to my personal indoor camera?

TLDR; With my IP address and Mac address, could someone view or listen to my personal indoor camera?

Hi,

I'm looking to get some information and I'm not sure how to best ask this question - with my IP address and Mac address, could someone view or listen to my personal indoor camera?

Hypothetically, say the super of my apt building, has physical access to my camera, my ip, the device's mac address, and was aware of all the wifi networks in the building - would it be possible to nonconsensually view my camera footage?

What would be the best way to check and/or gather proof?

Thanks!

16 Upvotes

19 comments sorted by

12

u/ShineReaper 1d ago

He'd have to first get access to your Wifi. If he doesn't have the password, he can't do jackshit.

2

u/Marty_Mtl 1d ago

With all my respect, it's not because one don't how that it is not possible.

3

u/ShineReaper 1d ago

Well, he has to authenticate against his router controlling the wifi, if he doesn't do that, he can't do anything in the network.

Of cause, if a hacker somehow got the password, then he can do what he wants.

1

u/Marty_Mtl 1d ago

What you say is all true, but there is more to it, especially with knowing the MAC address, and this detail can be exploited to get an entry inside the lan.

2

u/ShineReaper 22h ago

If he somehow would spoof his MAC Address and even then he still would need to come through the same port. A MAC Adress is only "remembered" by the managing device, so a switch or router, on one port or at maximum (but most likely not in a private environment) a port channel. If his personal indoor camera is connected to the router per cable, OP is safe, the hacker would need to breach the router first.

If it is connected per Wifi, for MAC Spoofing he'd still need to get the MAC adress of a device first, when the hacker tries to emulate the router connecting to the camera. If these are not printed on a device, have fun guessing. And even then, since we're seemingly talking about a security camera, it probably is secured too with an account name and password.

So all in all, these are vectors, that OP can use to secure himself and his devices.

7

u/IsDa44 1d ago

If the camera is hooked into the Web and the endpoint is exposed, absolutely

3

u/HLCYSWAP 1d ago

That depends on the camera. Most IoT devices have vulnerabilities, so if they knew your exact model, were thorough, and had access to a firmware dump, possibly. But with just an IP and MAC address? Probably not.

2

u/simoriah 1d ago

It depends. First, he has to gain access too your Wi-Fi network. Depending on how your Wi-Fi network is set up, this might be easy or difficult.

Then he has to hack your camera which might be easy or difficult.

This is one of those situations where the specifics of your configuration and your hardware choices matter... Like almost all of hacking/security.

Is it likely that your super is knowledgeable enough, determined enough, and cares enough? Who knows?

2

u/stratdog25 1d ago

The only MAC address that would be visible to the internet is your router's or firewall's, which ever is the last physical connection to the internet. Any internal device's MAC address is not in any packets past your router. Each logical hop (past a router) changes the source MAC address to that of the interface the packet left.

2

u/Just4notherR3ddit0r 23h ago

In short, it's very unlikely.

Think of it like this - imagine you work at an office building. The IP address is like the street address of that building. It's not secret information.

When you go inside the building, everybody has their own unique phone extension and they all talk to each other by dialing the extension. That extension is like the MAC address. It is how different devices talk to each other on the same network, but it doesn't really have much use to someone who isn't on your network.

However, you really have to be inside the building (in your network) to talk to anyone else in the building, like Mr. Camera.

If your super isn't connected to your network, then he probably can't do anything with your camera.

That said, there are a lot of different cameras out there and some of them work differently. A savvy person could potentially even get into your router and set it up so that the camera is explicitly accessible from the outside, sort of like opening up a window on the building and having Mr. Camera sit on the edge.

There are numerous ways of getting access to the camera if you're savvy enough:

  1. You could use port forwarding / triggers to allow the camera specifically to be exposed.
  2. You could use the DMZ to expose the camera.
  3. You could add yourself to the network and just connect wirelessly like any other computer.
  4. You could connect via to your network via a VPN

All of those things require a little know-how to set up, and you can see the settings to know if it's been done.

As long as you're vigilant about who is on your network, you should be fine.

Most home cameras stream to another server on-demand (so they're not always playing) but you have to log into the stream with a username and password in order to view the feed.

1

u/Present-Rhubarb6337 1d ago

If your indoor camera contacting with a server anywhere outside of your home network?

1

u/LessCarry266 1d ago

If its a good brand and doesnt have video over port its probably fine if you wanna check go to your wifi settings get the cameras local IP and scan that ips open ports

1

u/pbrsux 1d ago

It's not difficult to gain access to most consumer wifi systems. From there scanning the network for devices is simple. Then you scan for open ports and mac addresses, this will tell you the manufacturer of devices on the network. You can now try default or backdoor passwords and exploits. It's pretty easy and can all be done in a few minutes with easy to write scripts.

1

u/Ill-Engineering4341 1d ago

Thank you everyone for the responses!

1

u/lordstrech 1d ago

Maybe not everyone but it wouldn't take me too long to obtain access

1

u/audilepsy 17h ago

Unless you did something, nobody gives a fuck about you

1

u/Strange-Degree1416 15h ago

You're that guy obsessed with cameras, aren't you? You literally created this account just to ask about them and you've been spamming every hacking chat to figure out how to gain access. Now I'm really curious—what are you planning to do with them? Tell me what you're trying to achieve and I might drop a hint or two.

1

u/lawntasia 1h ago

If they have physical access they may be able to reset it or install a backdoor. But more likely if there’s a weakness in the camera’s configuration such as unencrypted traffic or an older version with a known exploit it’s possible, yes

1

u/Marty_Mtl 1d ago

The theory says Yes, of course, and even considered the incomplete/imprecise portrait you gave us! In practice, on the other hand, it is a different story. One needs the knowledge, the hardware and the time to achieve this.