Quantcast
Channel: CodeSection,代码区,网络安全 - CodeSec
Viewing all articles
Browse latest Browse all 12749

If you’re still using a fax machine for ‘security’ think again

$
0
0

If you’re still using a fax machine for ‘security’ think again

At this year's Def Con, Check Point researchers Yaniv Balmas and Eyal Itkin unveiled how they infiltrated the HP Officejet Pro 6830 all-in-one printer/copier/fax (it was the cheapest). It's important to understand that these machines are typically connected to a network. So if that piece of hardware is compromised, it's a gateway to the rest of the computers and devices it's attached too. Since the banking, legal and medical industry still use fax machines in their offices, that's bad news.

The team encountered an impressive list of technical hurdles. The weirdest included finding out that HP's firmware was using compression software built by Softdisk and was only used once before in the game Commander Keen .

After decoding the firmware and figuring out the operating system was ThreadX . They learned that the system reads everything as a print job (even firmware updates). With that information, they constructed a JPEG (since they could tweak the header and data) file to send to the all-in-one and it belonged to them.

During the demo, they sent over EternalBlue an NSA hacking tool (aka exploit of windows XP and above) stolen by theShadow Brokers. The exploit actively searches a network for unpatched machines and infects them. It was the vulnerability that allowed theWannaCry ransomware to spread so quickly and cripple hospitals in the UK.

The researchers disclosed the vulnerability to HP which quickly created and distributed a fix. So if you have an all-in-one HP, you should patch it if you haven't already. But more importantly, if you or your office uses a fax machine it's important to understand that these devices are not any more secure than email.

All computers systems are prone to infiltration. A fax machine is not only connected to your network but also the outside world via a phone line. There is no firewall. Now, look at the reception area of most doctor's offices. Chances are there's an all-in-one fax machine. The real estate world is also stuck in the past. Mostly because they many require real signatures for the litany of paperwork you need to fill out to become a homeowner. There are alternatives like digital signatures. But, it's easy to see why someone would think an analog document is more secure if they are under the impression it's never connected to a computer.

It's a bit terrifying that those industries are lulled into a sense of false security because fax machines have been around forever. That's really the lesson here. Just because something has been around forever and may have originally been analog, at some point it went digital and with that convenience, there is the potential for hacking. That's the world we live in and it's important for everyone to remember that. Even your doctor.


Viewing all articles
Browse latest Browse all 12749

Trending Articles