Technology Get the latest on technology, electronics and software…

Your printer may kill you

Thread Tools
 
Old 11-29-2011, 08:13 AM
  #1  
Team Owner
Thread Starter
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,456
Received 2,211 Likes on 1,210 Posts
Your printer may kill you

I never knew that HP printers looked at each print job to see if it contained new firmware. Looks like a pretty big hole.

Click the link for entire article, it's too large to post the entire thing.

http://redtape.msnbc.msn.com/_news/2...esearchers-say
Printer security flaws have long been theorized, but the Columbia researchers say they've discovered the first-ever doorway into millions of printers worldwide. In one demonstration of an attack based on the flaw, Stolfo and fellow researcher Ang Cui showed how a hijacked computer could be given instructions that would continuously heat up the printer’s fuser – which is designed to dry the ink once it’s applied to paper – eventually causing the paper to turn brown and smoke.

In that demonstration, a thermal switch shut the printer down – basically, causing it to self-destruct – before a fire started, but the researchers believe other printers might be used as fire starters, giving computer hackers a dangerous new tool that could allow simple computer code to wreak real-world havoc.
Cui and Stolfo say they've reverse engineered software that controls common Hewlett-Packard LaserJet printers. Those printers allow firmware upgrades through a process called "Remote Firmware Update." Every time the printer accepts a job, it checks to see if a software update is included in that job. But they say printers they examined don't discriminate the source of the update software – a typical digital signature is not used to verify the upgrade software’s authenticity – so anyone can instruct the printer to erase its operating software and install a booby-trapped version.
Rewriting the printer's firmware takes only about 30 seconds, and a virus would be virtually impossible to detect once installed. Only pulling the computer chips out of the printer and testing them would reveal an attack, Cui said. No modern antivirus software has the ability to scan, let alone fix, the software which runs on embedded chips in a printer.

“First of all, how the hell doesn't HP have a signature or certificate indicating that new firmware is real firmware from HP?” said Mikko Hypponen, head of research at security firm F-Secure, when told of the flaw. “Printers have been a weak spot for many corporate networks. Many people don’t realize that a printer is just another computer on a network with exactly the same problems and, if compromised, the same impact.”
Old 11-29-2011, 08:15 AM
  #2  
Moderator
iTrader: (1)
 
justnspace's Avatar
 
Join Date: Feb 2010
Posts: 86,295
Received 16,267 Likes on 11,974 Posts
phase 2 of skynet.
Old 11-29-2011, 08:17 AM
  #3  
Team Owner
Thread Starter
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,456
Received 2,211 Likes on 1,210 Posts
I predict a large botnet consisting mostly of HP printers in our future.

Corporate printers with hard drives are a major security risk. Never return your leased corporate printer without wiping the hard drive. The hard drives can contain a crap load of documents. Want to know what your CEO just printed? Go up to the printer and request a copy of the last print job.
The following users liked this post:
#1 STUNNA (11-29-2011)
Old 11-29-2011, 08:20 AM
  #4  
Moderator
iTrader: (1)
 
justnspace's Avatar
 
Join Date: Feb 2010
Posts: 86,295
Received 16,267 Likes on 11,974 Posts
^probably tickets to a football game, or something
Old 11-29-2011, 08:29 AM
  #5  
Go Giants
 
Whiskers's Avatar
 
Join Date: Aug 2004
Location: PA
Age: 53
Posts: 69,918
Received 1,236 Likes on 825 Posts
:tinfoilhat:
Old 11-29-2011, 10:31 AM
  #6  
The sizzle in the Steak
 
Moog-Type-S's Avatar
 
Join Date: Nov 2001
Location: Southern California
Posts: 71,436
Received 1,877 Likes on 1,297 Posts
I'm a firestarter, twisted firestarter,
you're the firestarter, twisted firestarter.
Old 11-29-2011, 10:54 AM
  #7  
Senior Moderator
 
Ken1997TL's Avatar
 
Join Date: May 2003
Location: Better Neighborhood, Arizona
Posts: 45,641
Received 2,329 Likes on 1,309 Posts
I caused a dial-up modem to catch on fire 'back in the day'
Old 11-29-2011, 10:55 AM
  #8  
Senior Moderator
 
Ken1997TL's Avatar
 
Join Date: May 2003
Location: Better Neighborhood, Arizona
Posts: 45,641
Received 2,329 Likes on 1,309 Posts
Originally Posted by doopstr
I predict a large botnet consisting mostly of HP printers in our future.
All running WebOS no less.
The following users liked this post:
#1 STUNNA (11-29-2011)
Old 11-29-2011, 04:01 PM
  #9  
Three Wheelin'
 
silver3.5's Avatar
 
Join Date: May 2009
Location: WISCONSIN
Age: 49
Posts: 1,299
Received 51 Likes on 41 Posts
Oh shit! I have 4 printers hooked to my internet at home! I better guard them with my AR in case any intruders get in.
Old 11-29-2011, 08:05 PM
  #10  
Sanest Florida Man
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,496
Received 10,805 Likes on 6,561 Posts
Originally Posted by doopstr
I predict a large botnet consisting mostly of HP printers in our future.
Originally Posted by Ken1997TL
All running WebOS no less.
Old 12-09-2011, 09:18 PM
  #11  
uʍop ǝpısdn ǝdʎʇ uɐɔ ı
 
thelastaspec's Avatar
 
Join Date: Apr 2010
Posts: 1,363
Received 47 Likes on 41 Posts
updated a hp fax all in one business machine once. The firmware update consisted of an application that started a print job containing the firmware. Kind of interesting procedure.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
VA2000TL
2G TL (1999-2003)
39
10-02-2015 08:26 AM
95oRANGEcRUSH
Car Talk
35
09-25-2015 12:50 PM
STL TL-S
3G TL Problems & Fixes
9
09-23-2015 08:52 PM



Quick Reply: Your printer may kill you



All times are GMT -5. The time now is 11:58 AM.