Most Popular Stories
- One on One with Arpan Shah of Microsoft Sharepoint
- IBM will snag half of India's outsoucing work by 2010
- Vendors prepare for Obama's electronic medical records change
- Teen sends 14,528 text messages in a single month
- Coke uses RFID for drink dispensers
- Forrester report predicts web content management will grow in spite of economy
Events
- CTO Telecom Summit
Nov 8-11, 2009 — Four Seasons Resort – Scottsdale, AZ
Sponsored Links
Free Newsletter
FierceCIO is the leading source of executive IT management news and information. Join 32,000+ CIOs, CTOs and Sr. IT managers who get FierceCIO twice a week via email and save time.
About | View Sample | Privacy
Latest News
Popular Topics
Whitepapers
- TechOnTap Article: Choosing the Right Backup Technology
- Gartner Magic Quadrant for Content Monitoring and Filtering and Data Loss Prevention
- Web Services Addressing 1.0 - Metadata
- Forrester Consulting: Optimizing Users and Applications in a Mobile World
- What Every CXO Should Know About the "Web 2.0"
- Why Traditional Monitoring Tools Cannot Deliver True Mobile User Management for the BlackBerry Platform
Hackers may target your printer
Spam has a new target, and it's your printer. By using a little-known capability found in most Web browsers, Aaron Weaver, a security manager from Pennsylvania, figured out how to hack into a printer. In a research paper published Tuesday on the Ha.ckers.org Web site, Weaver described how he launched the attack successfully with both the Internet Explorer and Firefox browsers. And he has found a way out, too. Because the attack works only on network printers, a printer plugged directly into a PC would not be vulnerable.
The attack is possible because most browsers can connect to the networking port used by most printers to look for new print jobs. So, by using the browser as a stepping stone, attackers are able to connect with something they should never be able to reach: a printer on the local area network. While this type of hack attack hasn't gotten any attention and there are no reports that it's infecting computer sites, Weaver's research uses cross-site scripting attacks and vulnerabilities in the way browsers handle the Internet Protocol.
"There is no precedent for [this hack]," said Robert Hansen, CEO of Web security consultancy SecTheory and owner of the Ha.ckers.org Web site. "But...what he did was marry two different concepts that we've been talking about for a long time." This could be the first step in another bad scenario because if hackers figure out how to send information about their print jobs to the Internet, Weaver's experiment could have far greater security implications. So maybe it's a good idea to turn your printers off for the night or when you are out of the office--because one never knows what might happen if they remain on.
For information on hacking printers:
- Check out this ComputerWorld article
Related Stories
- Is it only a myth that Firefox is more secure?
- Mozilla plugs 13 holes in Firefox
- IE market shares slip under 70 percent; Windows drops below 90 percent
- Faster CPUs on the way
- Identity theft dropped in 2007
- Crossing the border gets tougher
- A CIO must prevent attacks
- Data lost on 650,000 accounts
- Security woes dog Microsoft
- Spare no expense
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2009 FierceMarkets, Inc. All rights reserved. |
![]() |







Click here to get the FierceCIO email newsletter for FREE!
Be the first to comment