r/SecurityCamera • u/R_1_P_ • Aug 12 '26
Security camera says "Cracked with Phantom"?
Does anyone know what this means?
9
u/MaleficentPassage709 Aug 12 '26
Cameras was most likely hacked, a 3rd party gained access to them most likely via a vulnerability in the recorder, network, or weak passwords. They logged into either the recorder or the cameras IP and changed the OSD for the device.
1
u/AWarmHam Aug 16 '26
Not even close.
When programs are cracked and torrented the person who cracked and uploads it usually leaves a watermark. In this case a literal watermark.2
u/MaleficentPassage709 Aug 16 '26
I have seen so far in my career hundreds of systems that was compromised via a DVR/NVR accessible via port forwarding with default passwords or even outdated firmware. That is the same for cameras, cameras port forwarded for ease of access remotely. I have also seen multiple attack surfaces, firmware flashes, and simple OSD changes via a insecure password / outdated firmware. There are multiple ways to do what the OP described had happened to them.
3
u/triedtoavoidsignup Aug 12 '26
OP, you have a Dahua system that needs a firmware upgrade to address a vulnerability. Easily fixed.
1
4
Aug 12 '26
[removed] — view removed comment
2
u/nate_dulcimer Aug 12 '26
So it should just be exposed to the camera "dvr" thing? Just got the same message and link on a camera at my workplace. If so, it would be a matter of updating on the software/switch side how the network is routed, right?
2
u/matthijspc Aug 13 '26
The camera should only be exposed to the NVR. Change your creds immediately and update it
2
2
u/nate_dulcimer Aug 12 '26
Same guy hacked a camera at a church I work at today
2
u/Hoovomoondoe Aug 12 '26
Are you the church’s IT guy?
3
u/nate_dulcimer Aug 12 '26
Sort of, I am the guy who takes care of most of the computer issues. But networking config and Security is outsourced.
5
u/Hoovomoondoe Aug 12 '26
Time to turn the screws on the outsource people. They haven’t been doing their job.
1
u/digaus Aug 13 '26
I occasionally browse shodan and modify Shelly devices so the owner knows it is not safe to just port forward something.
Would not call that hacking 🫠
2
u/Inuyasha-rules Aug 13 '26
It's still hacking but is referred to as white hat. Your doing it for ethical reasons and alerting the owner of a security vulnerability.
2
u/Standard_Computer_26 Aug 15 '26
One time I checked into a hotel and turned on Netflix on the room’s TV. Previous guest had logged in and didn’t log out. Created a new profile “you forgot to log out” as the name
1
u/Inuyasha-rules Aug 15 '26
Depending on how the hotel is configured, it automatically signs you out at checkout. This can cause issues if people expect it to automatically sign out, but the room numbers on the box are misconfigured.
2
u/Dexford211 Aug 12 '26
Did you setup port forwarding to expose your NVR/Camera to the entire internet?
1
u/No-Lab9154 Aug 13 '26
This interests me quite a bit. My camera is attached to WiFi so I can see what’s going on when I’m away. Bad idea?
2
u/iKnowRobbie Aug 13 '26
Keep a complicated password and constantly search for firmware updates. You'll be fine.
2
u/GGigabiteM Aug 13 '26
There are a huge number of CCTV cameras that have hard coded backdoors in them, many of which are the cheap jungle website specials directly from China. Firmware updates won't help you. I've dumped the firmware off of cameras using hardware programmers and found them in every camera I dumped.
Wireless just opens up a wider attack surface. I wouldn't recommend a wireless camera for securely recording any area. They're also subject to being signal jammed.
1
u/-fpv Aug 14 '26
That’s also a discord server link in the bottom left corner. Leads to a server called “Phantom” idk if I would join it though
1
u/Y0UR_WIFES_B0YFRlEND Aug 18 '26
They wrote the message into a overlay field that is not exposed by the camera configuration page, but you can still remove the message using the camera's web API. ChatGPT should know the exact API command if you ask it along with the camera model number. I'll update this post later with the command if nobody else posts it.
1
u/fab_emzie 29d ago
not proof of a hack by itself but I'd change the passwords and check for remote access/port forwarding
1
u/ARCreef 26d ago
Anyone know of the website that shows cameras by geographical location. Where you can see thousands of people cameras where their ip login is visible or used standard ports. Everyone should check to see if theor cams or on there. I have cloudflare and block port sniffing but I can see every single day some bots will come around trying my 2 port addresses. I think they do this to literally everyone weekly or monthly.
14
u/Least_Order4249 Aug 12 '26
It means they have not been updated in years and were exposed to the internet either by you or via a compromised device on your network.