Performing VA/PT On Uniview CCTV devices: Steps of penetration and secure approach

These attackers use techniques by discovering vulnerabilities in the network and subtly exploiting them by injecting backdoor as an example without leaving any trace. Furthermore, people lives are even more important and the rules for privacy have been stricter than ever. Moreover, with the increased demand by people for of their homes and private properties to be monitored using CCTV networks, these cameras should be secure as any intrusion in this network may exploit the daily lives and routines.To simulate a penetration test and scan the network for possible vulnerabilities and exploit them, we believe the most dangerous attacks come from attackers who have all the technical knowledge of the flaws and vulnerabilities exist in the network. The main objective of our research is to setup a network using devices that can be used and bought by a normal user having them not knowing the vulnerabilities that they put themselves into, as we are going to use different tools and devices to scan the network and exploit the network and show the normal user what kind of dangers, they put themselves into and how can it be resolved. Hence, our research project will be used around the below scenario.“It was a Sunday afternoon. Rashid was in his office when he suddenly received an anonymous message containing a link. We he clicked on the link it was a video of him leaving his home today and going to work. Rashid immediately called home and asked them to power down the devices as he knew they were compromised and are being controlled by an attacker. Rashid instantly contacted his friend Marwan who is a penetration tester and forensic analyst to find out how the devices were hacked and how was the attacker able to successfully intrude the network and get access to the CCTV devices” [1]In this research project, the research type will be experimental. We are going to provide an introduction and comparison among different scanning and penetration tools to pave the way for penetration approaches. In addition, the above scenario going to aid us in conducting a meaningful experiment. Furthermore, we are going to discuss about the role of a well-designed and secure network when it comes to securing a home network internally and from the outside. Moreover, the scans that will be conducted will aid us in analyzing the network and exposing the back doors and misconfigurations and help prevent future attacks. We are going to illustrate a Raspberry Pi device can be connected to the network using the initiate scans to find the holes within it to provide the attacker with the necessary information and we will also monitor the traffic and the authentication between the cameras and the NVR, then we will use credentials if found to use by installed device and act as a man in the middle and route the stream to the attacking  During the experiments, we might face some challenges which will be mentioned in our research project, for instance, the stream may be interrupted as two devices will act as the main NVR, also, the tools used may have different readings and may have inaccurate information, Finally, we seek to provide in our research useful information on the different methods in penetration testing so we can have a better understanding of how the attacks are initiated. 