Multi Function p0wnage just getting worse, researcher finds

  • 5 August 2014
  • 1 reply
  • 187 views

Userlevel 7
Badge +54

Konica Minolta, Sharp, Dell, Canon and HP printers spew credentials when probed

By Darren Pauli, 5 Aug 2014
 
It is now easier than ever to hack corporate networks through multifunction printers, which can even offer up access to Active Directory accounts according to security consultant Deral Heiland.
The mustachioed Rapid 7 tech veteran said his team now gained access to corporate active directory credentials through credentials stored in the latest printers in one in every two attempts. Four years ago they had only a 10 to 15 percent success rate.
 High end Konica Minolta, Sharp, Dell, Canon and HP enterprise multi function printers spewed usernames, email addresses and passwords from address books, even after some vendors released fixes. They coughed up Active Directory usernames and application data and offered hostname information.
 
Full Article and Video

1 reply

Userlevel 7
good article jasper....... this is just another avenue corporations have to deal with. The manufacturers need to step up on these vulnerabilities.

Reply