Axis video servers are just one example. Tens of millions of IoT devices — printers, routers, medical devices, industrial controllers — are indexed by Google daily. The inurl: operator is a powerful tool for discovery, but it should be used responsibly.
A server that exposes its video feed often exposes other metadata, such as location data or network configurations, which can be used for more targeted cyberattacks. The Responsibility of Manufacturers and Users
I notice you're asking for a paper related to specific technical terms that appear to reference:
The "inurl:indexframe.shtml" string is a window into the past of the unsecured internet. While it may serve as a curiosity for some, it serves as a vital reminder for everyone else: if you don't lock your digital doors, a simple search engine query is all someone needs to walk right in.