Feeds

HP plugs password-leaking printer flaw

Bad news: Most office bods won't patch it. Good news: Most office bods won't find password

Intelligent flash storage arrays

Security flaws in a range of HP printers create a way for hackers to lift administrator's passwords and other potentially sensitive information from vulnerable devices, infosec experts have warned.

HP has released patches for the affected LaserJet Pro printers to defend against the vulnerability (CVE-2013-4807), which was discovered by Michał Sajdak of Securitum.pl. Sajdak discovered it was possible to extract plaintext versions of users' passwords via hidden URLs hardcoded into the printers’ firmware. A hex representation of the admin password is stored in a plaintext URL, though it looks encrypted to a casual observer.

Sajdak also discovered Wi-Fi-enabled printers leaked Wi-Fi settings and Wi-Fi Protected Setup PIN codes, as an advisory from the Polish security researcher explains.

HP has released firmware updates for the following affected printers:

  • HP LaserJet Pro P1102w,
  • HP LaserJet Pro P1606dn,
  • HP LaserJet Pro M1212nf MFP,
  • HP LaserJet Pro M1213nf MFP,
  • HP LaserJet Pro M1214nfh MFP,
  • HP LaserJet Pro M1216nfh MFP,
  • HP LaserJet Pro M1217nfw MFP,
  • HP LaserJet Pro M1218nfs MFP and
  • HP LaserJet Pro CP1025nw.

HP's advisory is here.

Consumers aren't very good at patching their computers, much less their printers, which rarely need security updates.

"The bad news is that many printer owners probably aren’t aware that the security issue exists, or simply won’t bother to apply the firmware update," security watcher Graham Cluley notes. ®

Remote control for virtualized desktops

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Seattle children’s accelerates Citrix login times by 500% with cross-tier insight
Seattle Children’s is a leading research hospital with a large and growing Citrix XenDesktop deployment. See how they used ExtraHop to accelerate launch times.
10 threats to successful enterprise endpoint backup
10 threats to a successful backup including issues with BYOD, slow backups and ineffective security.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?