Tens of millions of HP LaserJet printers vulnerable to hacking(extremetech.com)
extremetech.com
Tens of millions of HP LaserJet printers vulnerable to hacking
http://www.extremetech.com/computing/106945-tens-of-millions-of-hp-laserjet-printers-vulnerable-to-hacking
5 comments
If I was HP -- or a third-party toner provider -- I would release a worm that forces printers to use two or three times the usual amount of ink...
I think my HP printer had that worm pre-installed.
We dusted off an old, wired, B&W low res Cannon laser printer last year. It's our utility printer for internal docs or stuff you'd prefer to review on paper. It feels like an old reliable car. I think we're still using the same toner from last year's rebirth.
I bet there are a ton of these old printers sitting in corners shadowed by some glitzy full color, wifi, Internet enabled new hotness printer. It's probably a smart move to grab one of these old workhorses off Craigslist if you just need to print plain docs.
We dusted off an old, wired, B&W low res Cannon laser printer last year. It's our utility printer for internal docs or stuff you'd prefer to review on paper. It feels like an old reliable car. I think we're still using the same toner from last year's rebirth.
I bet there are a ton of these old printers sitting in corners shadowed by some glitzy full color, wifi, Internet enabled new hotness printer. It's probably a smart move to grab one of these old workhorses off Craigslist if you just need to print plain docs.
Even better surely is to just tell the printer to report the toner as empty after say 30% use (like manufacturers do with inkjet carts!). Then when the customer sends the toner cart in you can recycle the toner (or just top it up and reset the cart or whatever) and sell it back to the customer ... instant sales increase.
Of course after a little while the customers going to notice a problem. So then you can sell them a fix (patched firmware) or a new printer. Play it right and you get to run the same scam again then ...
Of course after a little while the customers going to notice a problem. So then you can sell them a fix (patched firmware) or a new printer. Play it right and you get to run the same scam again then ...
Brother already does this. When the printer tells you that toner is empty on a Brother laser printer, you usually have about 15-20% left. However, the printer will refuse to print anything. The solution is (no joke) to put tape over the sensor window on the cartridge, and you can get another 1000 pages or so.
http://www.fixyourownprinter.com/forums/laser/39806
Proud owner of a Brother laser printer here. My guess is that this is how they can afford to sell the printers for so cheap (usually underselling HP).
http://www.fixyourownprinter.com/forums/laser/39806
Proud owner of a Brother laser printer here. My guess is that this is how they can afford to sell the printers for so cheap (usually underselling HP).
The hardware thermal protections kick in before a fire is started. The possibility of stealing information or flat-out bricking the printer are more likely than fire.
HP claims all new models since 2009 enforce digital signatures. Firmware updates for older printers should be able to add this feature, but I don't see any evidence to suggest they do (or don't).
Further, most laser printers are on relatively safe networks, and even if there are infected machines on the network, there are generally a number of other ways to wreak havoc and steal information.
HP claims all new models since 2009 enforce digital signatures. Firmware updates for older printers should be able to add this feature, but I don't see any evidence to suggest they do (or don't).
Further, most laser printers are on relatively safe networks, and even if there are infected machines on the network, there are generally a number of other ways to wreak havoc and steal information.
Ah, ok, much less of an issue if there's a hardware switch that prevents overheating (who's settings can't be changed via the ROM).
Agree it isn't any new from a data loss point of view, but I was imagining thousands of offices having printers catching fire in the middle of the night. (can you imagine?)
Agree it isn't any new from a data loss point of view, but I was imagining thousands of offices having printers catching fire in the middle of the night. (can you imagine?)
...and the worm can be inside a PDF. So what, we can only print plain-text now? Does my virus scanner look for firmware worms in pdf files?
I didn't get that from the article. How's a PDF file supposed to trigger the (vulnerable) firmware update mechanism of the printer?
Right, it only says
"if you can reverse engineer one of HP’s firmware updates so that you can make your own, and then insert it into a print job"
Not clear if a PDF can achieve that.I think know how this is done, I use it to hack my cartridge life all the time. Slightly off topic but bear with it...
When the HP driver software compiles the file code to send to the printer it also encodes other information. I discovered this because I found out it that the system date of the pc gets encoded along with the print data. More shockingly, prior to encoding the file, the printer checks the "best before date" of each cartridge and compares it to the system date. If your cartridge is beyond the date HP would like you to use it by, it introduces artifacts into the print and the issues a "beware you printer could malfunction with out of date cartridges" message.
Simple work around, change your system date to some time in the past before your cartridge expiry date, and hey presto your HP printer starts to work again. Change it back to the present and all of a sudden the artifacts and message appear.
If HP can mess with your PDF pre-print, then so can someone else. Personally, I love my HP printer. I just hate what HP do to try to force you to buy more ink. Whenever have non-perishable goods required a "use by" date?
When the HP driver software compiles the file code to send to the printer it also encodes other information. I discovered this because I found out it that the system date of the pc gets encoded along with the print data. More shockingly, prior to encoding the file, the printer checks the "best before date" of each cartridge and compares it to the system date. If your cartridge is beyond the date HP would like you to use it by, it introduces artifacts into the print and the issues a "beware you printer could malfunction with out of date cartridges" message.
Simple work around, change your system date to some time in the past before your cartridge expiry date, and hey presto your HP printer starts to work again. Change it back to the present and all of a sudden the artifacts and message appear.
If HP can mess with your PDF pre-print, then so can someone else. Personally, I love my HP printer. I just hate what HP do to try to force you to buy more ink. Whenever have non-perishable goods required a "use by" date?
"Every time a vulnerable LaserJet printer accepts a print job, it scans that job to see if it includes a firmware update."
"but what if an employee at a company is spear-phished with a hacked-firmware-laden PDF or DOC?"
I guess the OP thinks it is possible? I wouldn't know.
"but what if an employee at a company is spear-phished with a hacked-firmware-laden PDF or DOC?"
I guess the OP thinks it is possible? I wouldn't know.
Not sure about manipulating firmware but many printers can handle PDF directly (no need to convert to PS/PCL)
Coincidentally, I was updating HP LaserJet firmware last week and when the update tool was running, I was surprised to see it sent the firmware as a 'normal' job to the printer. My guess is this is how the exploit works -- simply disassemble existing firmware and make sure your malicious job looks like said update.
I know I commented earlier, but I slept on it last night and I realised I'd already hacked printers in this way and got paid to do it - I'd just completely forgotten.
Years ago, I was working for well known lighting manufacturer and CD inventor you know who I mean... they had a SAP system that did not have a printer driver for the thermal printers they were using on all their products. I'd been using a bizarre pseudo mark-up language called SAPScript on a couple of projects and discovered quite by accident ;) that you could encode printer commands directly into the SAPscript. Exactly the same principle I guess as including php code in HTML. At some point the machine knows to parse the code not print it. I could get it to do some mad printed stuff as long as you could controll the variables that you passed to the script. I never tried the burn baby burn effect though. I was too nice.
Years ago, I was working for well known lighting manufacturer and CD inventor you know who I mean... they had a SAP system that did not have a printer driver for the thermal printers they were using on all their products. I'd been using a bizarre pseudo mark-up language called SAPScript on a couple of projects and discovered quite by accident ;) that you could encode printer commands directly into the SAPscript. Exactly the same principle I guess as including php code in HTML. At some point the machine knows to parse the code not print it. I could get it to do some mad printed stuff as long as you could controll the variables that you passed to the script. I never tried the burn baby burn effect though. I was too nice.
Meh, sprinkler systems will rain on that parade.
It's not shocking at all that they allow firmware updates through the print port. That's very typical.
What's shocking is the claim that the update isn't signed. I'm at a loss as to how to describe how terrifically awful that is. It's /so/ shocking to me, I have a hard time believing it. If true, it's astoundingly negligent on their part.
What's shocking is the claim that the update isn't signed. I'm at a loss as to how to describe how terrifically awful that is. It's /so/ shocking to me, I have a hard time believing it. If true, it's astoundingly negligent on their part.
It’s worth noting that other (non-HP) printers, copiers, and all-in-one thingamajigs are probably vulnerable to a similar attack, too.
Well anything produced to be mass/IT-managed probably provides an easy method for firmware upgrading. And all firmware encryptions/checksums/etc are of course (at least theoretically) crackable.
I don't see how this could come off as a surprise to anyone in the industry.
Well anything produced to be mass/IT-managed probably provides an easy method for firmware upgrading. And all firmware encryptions/checksums/etc are of course (at least theoretically) crackable.
I don't see how this could come off as a surprise to anyone in the industry.
Wow. I worked on HP printers a long time ago and didn't hear of anything this crazy.
Personally I stopped using HP a while back, thanks for sharing..!
Personally I stopped using HP a while back, thanks for sharing..!
this is f*cking awesome. I feel like I'm in 80s. Thanks, HP.
How many million HP printers are there in how many million offices filled with how many vulnerable PCs?
I'm not usually one to be alarmist, but are we one clever worm away from Printergeddon?