training-scraper

Secure DVR web interface exposed to public internet

draft · equipment securitydvr

Generated by docuprocessor (prompt article/v3) · 2026-04-22 13:12

Source thread

thread_id: spaces/AAAA05BdS6s/threads/cqrVhf-ygnk · 2 msgs · first 2024-08-16 · participants: Tech ATech B

Tech A 2024-08-16 12:51
We got an email from Black Talon regarding Mark Steins office - their DVR web interface login page is publicly accessible and is not secure (http) , do we have a specific policy for handling this? They gave the options to Accept the Risk, Implement a Fix, or "Apply Compensatory Controls" . I believe we ran into some issues trying to fix this in the past (upgrading firmware did not help, etc)
Tech B 2024-08-16 13:16
Don't know about our policy, but most security companies won't allow DVR to be accessible in public through port forwarding. They allow maximum access through apps (cloud). ( They are even hosted on separate local networks, without access from other networks)

Generated article

Unsaved edits.
draft