Breaking News

Viltrox Announces AF 15mm F1.7 Air MSI Prestige 16 AI Mercedes-AMG Motorsport Limited Edition Laptop GAMEMAX Introduces AERIS 330 Series micro-ATX PC Case COLORFUL Launches Rimbook Series Laptops Circular Smart Rings Offer Early Detection of Sickness Symptoms

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Printers Are Open To Hack Attack, Researchers Say

Printers Are Open To Hack Attack, Researchers Say

PC components Nov 29,2011 0

Researchers at Columbia University claim they've discovered a new class of computer security flaws that could impact millions of businesses, consumers, and even government agencies. Printers can be remotely controlled by computer criminals over the Internet, with the potential to steal personal information, attack otherwise secure networks and even cause physical damage, the researchers argue in a vulnerability warning first reported by msnbc.com. They say there's no easy fix for the flaw they've identified in some Hewlett-Packard LaserJet printer lines - and perhaps on other firms' printers.

The researchers described the flaw in a private briefing for federal agencies two weeks ago. They told Hewlett-Packard about it last week.

The flaw involves firmware that runs on computer printers, which are commonly connected to the Internet. Professor Cui and Stolfo say they've reverse engineered software that controls common Hewlett-Packard LaserJet printers. Those printers allow firmware upgrades through a process called "Remote Firmware Update." Every time the printer accepts a job, it checks to see if a software update is included in that job. But they say printers they examined don't discriminate the source of the update software - a typical digital signature is not used to verify the upgrade software's authenticity - so anyone can instruct the printer to erase its operating software and install a booby-trapped version.

In a demonstration of an attack based on the flaw, the researchers showed how a hijacked computer could be given instructions that would continuously heat up the printer's fuser - which is designed to dry the ink once it?s applied to paper - eventually causing the paper to turn brown and smoke.

HP described the reporting regarding the potential security vulnerability as "inaccurate". "No customer has reported unauthorized access. Speculation regarding potential for devices to catch fire due to a firmware change is false," HP said.

HP added that its LaserJet printers have a hardware element called a "thermal breaker" that is designed to prevent the fuser from overheating or causing a fire.

However, HP admits that it has has identified a potential security vulnerability with some HP LaserJet printers, although none of its customers has reported unauthorized access.

"The specific vulnerability exists for some HP LaserJet devices if placed on a public internet without a firewall, Hp said. "In a private network, some printers may be vulnerable if a malicious effort is made to modify the firmware of the device by a trusted party on the network. In some Linux or Mac environments, it may be possible for a specially formatted corrupt print job to trigger a firmware upgrade," the company added.

HP is building a firmware upgrade to mitigate this issue.

Tags: HPPrinters
Previous Post
Facebook Settles FTC Charges
Next Post
Google Maps Goes Indoors

Related Posts

  • An Intel-HP Collaboration Delivers Next-Gen AI PCs

  • OMEN AND HYPERX POWER UP COOLEST PORTFOLIO YET FOR PERSONALIZED PLAY

  • New KIOXIA RM7 Series Value SAS SSDs Debut on Hewlett Packard Enterprise Servers

  • HYPERX EXPANDS CONSOLE GAMING HEADSET LINEUP WITH CLOUD STINGER 2 FOR PLAYSTATION AND CLOUDX STINGER 2 FOR XBOX

  • KIOXIA first to launch data center NVMe E3.S SSDs on Hewlett Packard Enterprise systems

  • HP debuted its newest HP Spectre and HP Envy laptops

  • HP Announces Omen 16 and Victus 15 new gaming laptops

  • HP Threat Research Shows Attackers Exploiting Zero‐Day Vulnerability Before Enterprises Can Patch

Latest News

Viltrox Announces AF 15mm F1.7 Air
Cameras

Viltrox Announces AF 15mm F1.7 Air

MSI Prestige 16 AI Mercedes-AMG Motorsport Limited Edition Laptop
Consumer Electronics

MSI Prestige 16 AI Mercedes-AMG Motorsport Limited Edition Laptop

GAMEMAX Introduces AERIS 330 Series micro-ATX PC Case
Cooling Systems

GAMEMAX Introduces AERIS 330 Series micro-ATX PC Case

COLORFUL Launches Rimbook Series Laptops
Enterprise & IT

COLORFUL Launches Rimbook Series Laptops

Circular Smart Rings Offer Early Detection of Sickness Symptoms
Consumer Electronics

Circular Smart Rings Offer Early Detection of Sickness Symptoms

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

be quiet! Pure Base 501

be quiet! Pure Base 501

Terramaster F8-SSD

Terramaster F8-SSD

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed