# LiNuX-Mallu/CAM-DUMPER

Take webcam shots from target by just sending a malicious link

Repository: https://github.com/LiNuX-Mallu/CAM-DUMPER
Canonical: https://ross.abutalabs.com/products/cam-dumper
Language: Shell
License: GPL-3.0
License Family: copyleft
Topics: camera-hacking, camera-phishing
Last push: 2022-02-02T03:00:48+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2444, "days_push": 1673, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1203, forks 121 (observed 2026-08-28T04:03:58.739998+00:00)

## What it is
CAM-DUMPER is a shell-based security testing tool that generates a malicious HTTPS page served via Serveo or Ngrok port forwarding to capture webcam photos from targets. It abuses the browser MediaDevices.getUserMedia() API to trick users into granting camera access and uploads the captured images back to the attacker.

## Use cases
- capture webcam shots from a target by sending a phishing link
- demonstrate browser camera permission social-engineering risks in security awareness training
- test how users respond to getUserMedia permission prompts
- run a red-team exercise demonstrating malicious link camera access
- host a fake HTTPS page through ngrok or serveo for a phishing simulation

## When to choose
- you need a quick, scriptable proof-of-concept for camera-based social engineering on Kali Linux or Termux
- you want to demonstrate getUserMedia permission abuse during a security awareness session
- you prefer a lightweight bash tool with no dependencies beyond php, curl, and jq

## When to avoid
- you need a full-featured phishing framework with template management and tracking
- you want a maintained tool with regular updates and broad platform support
- your use case is legitimate webcam capture without user deception - use standard browser APIs instead
- you require stealth or evasion capabilities beyond a simple hosted page

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: penetration-testing, security, http-server
- domain: security, penetration-testing, privacy
- platform: cli
- tags: social-engineering, phishing, webcam, camera-hacking, ngrok, serveo, shell-script, kali-linux, termux, linux, android

## Member repositories
- LiNuX-Mallu/CAM-DUMPER (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:58.739998+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:19:42.061150+00:00, confidence not recorded.
  - readme: https://github.com/LiNuX-Mallu/CAM-DUMPER (fetched 2026-08-28T04:03:58.739998+00:00, sha cc0b6a65675e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
