Part 4 and 5 of the "Verkracked" independent security research project. Specifically covering the subghz protocol framework and the cloud emulator, enabling use of Verkada alarm hubs locally.
Category: Vulnerablility/Security Research
Verkracked – Security Research on Verkada Anti-Crime Devices – Part 0
Part 0 of the ongoing long form independent security research project Jon "GainSec" Gaines is doing to assess the security posture of various Verkada devices and hardware.
Bird Hunting Season at Def Con 34
I spoke on the main stage of Def Con 34 on the same day Flock Safety’s Private Bug Bounty closed. My talk, titled The Final Flight was an overview of the entire research project including my experience from an independent researcher perspective. Of course the talk will be on YouTube eventually and in the meantime … Continue reading Bird Hunting Season at Def Con 34
AOL Desktop Gold Security Research Public Release
As mentioned in my last post, I have some very backlogged projects I’ve decided to just release to get them out of my backlog. This one is related to AOL Desktop Gold, the modern successor to the AOL desktop software a lot of us remember from the 90s. Yes it does still exist (and hence … Continue reading AOL Desktop Gold Security Research Public Release
Digital Ally ThermoVu DTM-600 / Uniview LAPI Security Research Release
I have some very backlogged projects I’ve decided to just release to get them out of my backlog. This one is related to the Digital Ally ThermoVu DTM-600, which is a Uniview/OEM OET-213H-NB-style facial recognition and thermal access-control device. This release is the majority of my notes, tools, findings, and research artifacts from looking at … Continue reading Digital Ally ThermoVu DTM-600 / Uniview LAPI Security Research Release
AutoPro and 3rd Party Carplay/Android Auto Dongle Security Research
I have some very backlogged projects I've decided to just release to get them out of my backlog. The first one is related to aftermarket Apple CarPlay and Android Auto dongles. This release is the majority of my notes, tools, findings, and research artifacts from looking at the Mayton/AutoPro-style dongle ecosystem. It includes documentation, test … Continue reading AutoPro and 3rd Party Carplay/Android Auto Dongle Security Research
Finding 67 Flock Safety Live PTZ Camera/LPR Feeds and Debug Web Interfaces accidentally exposed without authentication to the internet
How I took a security researchers initial discovery and found another 63 instances of Flock Safety Camera Feeds and Debug Web Service exposed unauthenticated to the internet. Also learn how it ended up being exposed to the internet and how to ensure it doesn't happen to you.
BirdEye
A TensorFlow Lite harness I threw together for some security research in regards to my long going Bird Hunting Season project!
Formalizing my Flock Safety Security Research.
My Flock Safety independent security research has reached the point where it felt necessary to compile it all into a formal white paper and statement. Moving forward, all vulnerabilities will be added first to this white paper during the responsible disclosure embargo.
Button Presses to Wireless RCE: Shell on Flock Safety’s License Plate Cameras Over Wi-Fi
A combination of reused default passwords, hidden triggers, and completely unauthenticated APIs results in reliable wireless RCE, data disclosure, and device control in the field on Flock Safety's License Plate Readers.









