All the latest UK technology news, reviews and analysis

Zscaler finds major security holes in scanners, photocopiers and phones

by Shaun Nichols

30 Jul 2011

Be the first to comment

  • Tweet this

Attackers are exploiting the browser-based management and configuration tools found in common office appliances to compromise systems and steal data, according to researchers at Zscaler.

The security firm will deliver a presentation a next week's Black Hat conference which shows the ease with which an attacker can exploit web-enabled devices such as scanners, photocopiers and telephony equipment to steal information.

Michael Sutton, vice president of security research at Zscaler, told V3 that in many cases, an attacker can simply scan addresses until a connected device is found and a target selected.

Such devices have little to no security protection, resulting in what Sutton describes as "corporate espionage for dummies".

"There is not really any hacking involved. You just find this device and it is there sitting ready for abuse. This is functionality that was designed so you could use it," he said.

Zscaler found that security components are often unpatched or on their default settings, allowing an attacker to look up passwords and access codes from online support material.

Sutton explained that if an attacker compromised a photocopier, for example, all scanned documents and stored data on the device could be harvested.

"I am literally able to connect to photocopiers for private companies and clearly see documents," he said.

"If you had confidential a document you wouldn't leave it on an employee's desk, but you are practically doing the same thing."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

40%

0%

10%

50%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Business Development Executive

A Multi-national data analytic's and cloud computing...

C# Developer

A multi-national software solutions organisation are...

UI Application Designer

A multi-national software solution provider are looking...

Service Delivery Manager

Service Delivery Manager, Customer Service, PCT, Primary...

To send to more than one email address, simply separate each address with a comma.