【24h】

You Overtrust Your Printer

机译:您过度信任打印机

获取原文

摘要

Printers are common devices whose networked use is vastly unsecured, perhaps due to an enrooted assumption that their services are somewhat negligible and, as such, unworthy of protection. This article develops structured arguments and conducts technical experiments in support of a qualitative risk assessment exercise that ultimately undermines that assumption. Three attacks that can be interpreted as post-exploitation activity are found and discussed, forming what we term the Printjack family of attacks to printers. Some printers may suffer vulnerabilities that would transform them into exploitable zombies. Moreover, a large number of printers, at least on an EU basis, are found to honour unauthenticated printing requests, thus raising the risk level of an attack that sees the crooks exhaust the printing facilities of an institution. There is also a remarkable risk of data breach following an attack consisting in the malicious interception of data while in transit towards printers. Therefore, the newborn IoT era demands printers to be as secure as other devices such as laptops should be, also to facilitate compliance with the General Data Protection Regulation (EU Regulation 2016/679) and reduce the odds of its administrative fines.
机译:打印机是通用设备,其网络使用极为不安全,这也许是由于人们根深蒂固的假设,即打印机的服务在某种程度上可以忽略不计,因此不值得保护。本文提出了结构化的论据并进行了技术实验,以支持定性的风险评估活动,该活动最终破坏了该假设。找到并讨论了三种可以解释为利用后活动的攻击,形成了我们所谓的Printjack系列打印机攻击。一些打印机可能会遭受将其转变为可利用的僵尸的漏洞。此外,发现至少在欧盟的基础上,大量打印机可以满足未经认证的打印请求,从而提高了攻击风险,使骗子耗尽了机构的打印设备。在攻击过程中,也存在着显着的数据泄露风险,其中包括在向打印机传输数据时恶意拦截数据。因此,新生的物联网时代要求打印机与笔记本电脑等其他设备一样安全,还应促进遵守通用数据保护条例(EU条例2016/679)并减少行政罚款的几率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号