home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1767
Discussions: 188,470, Posts: 2,244,168, Members: 232,723
Old August 8th, 2006, 12:01 PM   Digg it!   #1 (permalink)
Fossil
 
Theophylact's Avatar
 
Join Date: Oct 2001
Location: inside the Beltway
Posts: 5,234
Blog Entries: 35
Your printer is a computer...

...and it needs to be secured:
Quote:
LAS VEGAS--The multifunction printers found in many offices are not dumb devices, but are computers that can be hacked, a security expert has warned. In a presentation at the Black Hat security conference, Brendan O'Connor, a security expert at an unnamed U.S. financial company, showed how he could gain control over a Xerox device and wreak all kinds of havoc.

"Stop treating them as printers. Treat them as servers, as workstations," O'Connor said in his presentation on Thursday. Printers should be part of a company's patch program and be carefully managed, not forgotten by IT and handled by the most junior person on staff, he said.

In the case of the Xerox system, O'Connor said the multifunction device was, in essence, a Linux server. He was able to exploit a weakness in the security of the device and gain full control of the machine. O'Connor noted that he also looked at devices from other manufacturers and found similar security faults, but did not list any names.

Once a printer was under his control, O'Connor said he would be able to use it to map an organization's internal network--a situation that could help stage further attacks. The breach gave him access to any of the information printed, copied or faxed from the device. He could also change the internal job counter--which can reduce, or increase, a company's bill if the device is leased, he said.

The printer break-in also enables a number of practical jokes, such as sending print and scan jobs to arbitrary workers' desktops, O'Connor said. Also, devices could be programmed to include, for example, an image of a paper clip on every print, fax or copy, ultimately driving office staffers to take the machine apart looking for the paper clip.

One of the weaknesses in the Xerox system is an unsecured boot loader, the technology that loads the basic software on the device, O'Connor said. Other flaws lie in the device's Web interface and in the availability of services such as the Simple Network Management Protocol and Telnet, he said.

O'Connor informed Xerox of the problems in January. The company did issue a fix for its WorkCentre 200 series, it said in a statement. "Thanks to Brendan's efforts, we were able to post a patch for our customers in mid-January which fixes the issues," a Xerox representative said in an e-mailed statement.

However, O'Connor believes the fix is inadequate, and therefore he decided to make the presentation at Black Hat. The threat is real, even though printers are mostly on internal networks, he said. "There is always the insider threat," O'Connor said.
(Hat tip to Bruce Schneier.)
__________________
Editing! Gerunds! Death!

Theophylact is offline   Reply With Quote
Old August 8th, 2006, 03:08 PM     #2 (permalink)
Free Thinker
 
M_Six's Avatar
 
Join Date: Oct 2001
Location: Charleston, Illinois
Posts: 4,198
Hey Theo.

Good tip. We deal with these issues all the time here. Networked printers need to be behind a firewall and have security set, otherwise they mysteriously start spewing out mountains of gibberish strewn paper.
__________________
You can't fix stupidity.

M_Six is offline   Reply With Quote
Old August 9th, 2006, 12:12 AM     #3 (permalink)
Ultimate Member
 
usslindstrom's Avatar
 
Join Date: Sep 2003
Location: From my house
Posts: 1,134
Oh man, I would LOVE to get my hands on the knowledge to do that kinda' stuff. I have some serious practical jokes that are comin' to mind right now.
__________________
And thus it was spoken by the mighty Uss. And it was so.

usslindstrom is offline   Reply With Quote
Old August 9th, 2006, 12:26 AM     #4 (permalink)
Ultimate Member
 
GiPilot12's Avatar
 
Join Date: Jan 2005
Location: Lugano, Switzerland
Posts: 2,307
Send a message via MSN to GiPilot12
That could get annoying if someone got into your printer.
__________________
"I thought what I'd do was, I'd pretend to be one of those deaf-mutes" Or Should I?
Chapter 25, The Catcher in the Rye
GiPilot12 is offline   Reply With Quote
Old August 9th, 2006, 12:31 AM     #5 (permalink)
Ultimate Member
 
Mickwish's Avatar
 
Join Date: Dec 2001
Location: BrisVegas, Australia
Posts: 10,421
Blog Entries: 1
Don't forget wireless network printers either. I managed to accidentally connect to an unsecured wireless networked printer at the school across the road from where I used to live. So I sent them a nice print job explaining that they should secure it, and included my email address. Got a nice email back thanking me and stating they had fixed it.

Could have been some nasty pranks by someone, though.

Cheers
Mick
__________________
I don't like sigs on forums like this.
Mickwish is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
trying to get my computer to recognize a network printer ShuckyD Networking and Internet 14 October 4th, 2005 02:46 PM
how can i set up a different computer print to my printer? formulasoap Networking and Internet 0 January 5th, 2005 04:47 PM
Win2K Printer Prob: Printer operation cannot continue due to lack of resources. buddhafest Applications and Operating Systems 10 January 5th, 2004 04:43 AM
Sharing printer on windows 2000 to XP computer voogru Applications and Operating Systems 7 March 10th, 2003 11:57 AM
HP940c printer Locks UP MY Computer! amdkt7 General Tech Discussion 11 January 2nd, 2002 08:25 AM

Most Active Discussions
Is It Just Me? (2996)
Intel Pentium 4 531 (7)
"mastermind" of London at.. (65)
Please don't divorce us (40)
AMD Phenom II X4 940 Black Edition (11)
Replacing integrated video card (5)
nVidia GTX 295 now available (20)
Folderchat Weekday thread (458)
building a gaming computer, input p.. (14)
Recent Discussions
Folderchat Weekday thread (458)
Could I run this set-up (15)
Bought the Visiontek Radeon 387.. (1)
nVidia GTX 295 now available (20)
CPU Overheating ?? (18)
Computer will not boot(powers o.. (2)
*TechIMO's Top 30 PCs* (44)
New psu question (1)
Finishing off my first built co.. (4)
Blackberry Storm, Gears of War .. (2)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 05:32 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28