domingo, 29 de julho de 2012

Estudo alerta para vulnerabilidades em impressoras sem fios(Study warns of vulnerabilities in wireless printers)


Os fabricantes de impressoras com capacidades de funcionamento em modo wireless estão a descurar as questões de segurança associadas à sua utilização, tornando este tipo de equipamentos cada vez mais vulneráveis a ataques diretos de hackers que, no limite, podem inutilizar as prórpias impressoras.

As conclusões partem de um estudo recente realizado por uma empresa de segurança finlandesa, a publicar no final de julho, numa tentativa de sustentar informações que circulam no mercado, chamando a atenção para as vulnerabilidades das impressoras sem fios, sobretudo no que respeita ao processo de atualização do seu firmware.
Ari Takanen, fundador e responsável técnico da empresa de segurança Codenomicon, refere que "é tudo uma questão de consciência" do utilizador e dos fabricantes. A empresa realizou testes a 15 protocolos de comunicação usados em modelos de impressoras de entrada de gama e para o segmento SOHO de seis marcas diferentes (não reveladas), concluindo que cinco desses protocolos mostraram falhas e que mais de metade dos modelos mostraram vulnerabilidades ao nível dos protocolos de transmissão de dados TCPv4 e IPV6.
Segundo a empresa, a principal falha detetada deve-se às novas capacidades que as impressoras possuem de receber documentos diretamente da cloud, sobretudo emails. "Quanto mais usamos as impressoras para enviar e receber emails, mais sujeitos estamos a ser atacados" defendeu Takanen ao jornal britânico The Guardian.
O mesmo responsável reforça ainda esta situação, referindo que poucas pessoas se apercebem que os dispositivos sem fios que têm em casa não possuem firewalls, nem software antivirus, que normalmente se encontram num PC, comprometendo desta forma a segurança das suas redes domésticas: "estas vulnerabilidades são agravadas por código desatualizado, porque aspessoas não tratam a sua impressora como um PC, cujo software atualizam com regularidade" acrescenta Ari Takanen.

O estudo da Codenomicon vem corroborar uma série de experiências realizadas há cerca de sete meses, no Intrusion Detection System Laboratory da Universidade de Columbia, EUA, quando dois investigadores conseguiram quebrar a segurança de uma impressora HP com ligação sem fios.
Na altura, o professor Salvatore Stolfo e o investigador Ang Cui usaram a funcionalidade de atualização do firmware da impressora para instalar malware num modelo LaserJet.
A experiência foi levada a sério pela HP, que na altura desenvolveu 56 atualizações para resolver os problemas detetados. No entanto, numa pesquisa recente levada a cabo por esses investigadores a impressoras LaserJet conclui que apenas 1 a 2% dos modelos possuem o firmware atualizado; e, desses modelos, uma em quatro impressoras mantém as configurações e a password de origem para efetuar as atualizações.

"Demonstrámos não só que a função de atualização do firmware em determinadas imperessoras é defeituosa, mas também que existem inúmeras vulnerabilidades conhecidas nos sistemas operativos usados num elevadso número de impressoras" sustenta Salvatore Stolfo.

Printer manufacturers with ability to operate in wireless mode are neglecting the security issues associated with their use, making such equipment more vulnerable to direct attacks by hackers, in the limit, can discard the prórpias printers.

The conclusions are based on a recent study by a Finnish security company, to be published in late July in an attempt to sustain information circulating on the market, drawing attention to the vulnerabilities of wireless printers, especially as regards the process upgrade its firmware.
Ari Takanen, founder and technical officer of security company Codenomicon, states that "it's all a matter of conscience" of the user and the manufacturers. The company conducted tests to 15 communication protocols used in models of printers and entry-level for the SOHO segment of six different brands (not revealed), concluding that five of these protocols showed failures and more than half of the models showed the level vulnerabilities protocols for data transmission TCPv4 and IPV6.
The company said the main flaw detected is due to new capabilities that printers have to receive documents directly from the cloud, especially emails. "The more we use the printers to send and receive emails, we are more likely to be attacked" Takanen defended the British newspaper The Guardian.
The same manager reinforces this, stating that few people realize that the wireless devices they have at home do not have firewalls or antivirus software, you usually find on a PC, thus compromising the safety of their home networks, "these vulnerabilities are compounded by outdated code, aspessoas why not treat your PC as a printer, whose software update regularly, "says Ari Takanen.

The study corroborates the Codenomicon a series of experiments carried out for about seven months, the Intrusion Detection System Laboratory at Columbia University, USA, when two researchers were able to break the security of an HP printer with wireless connection.
At the time, Professor Salvatore Stolfo Ang Cui and the investigator used the update functionality of the printer's firmware to install malware on a LaserJet model.
The experience was taken seriously by HP, which developed 56 updates at the time to solve the problems detected. However, a recent survey carried out by these researchers LaserJet concludes that only 1-2% of the models have updated firmware, and these models, one in four printer retains the settings and password of origin to make the updates.

"We have demonstrated not only that the firmware update function in certain imperessoras is flawed but that there are numerous known vulnerabilities in operating systems used in a number of printers elevadso" sustains Salvatore Stolfo.

Sem comentários:

Enviar um comentário