Hewlett-Packard offers fix for printers susceptible to remote hacks

Hewlett-Packard released a firmware update Friday that it says will fix a susceptibility in some of the Palo Alto, Calif., company's popular LaserJet printers that researchers said could allow hackers to remotely take control of the devices.

Last month, MSNBC reported a team of researchers from Columbia University discovered that some Hewlett-Packard LaserJet printers, and possibly similar devices, did not verify software upgrades contained within so-called remote updates. The researchers were able to offer firmware updates that included and then take control of the printer.

Once the researchers were able to take control of printers, they were able to accomplish a host of potentially dangerous tasks. They said they could print a tax return while sending a copy to a hacker's , compromising a host of personal information; easily disable printers; and even command a printer to continuously heat up its ink-drying component until it started to set on fire.

Hewlett-Packard issued a statement after the report was released vehemently denying that printers could be commanded to burst into and saying "no customer has reported unauthorized access," but the company did admit there was a flaw.

"HP has identified a potential security vulnerability with some HP LaserJet printers ... if placed on a public Internet without a firewall. In a private network, some printers may be vulnerable if a malicious effort is made to modify the firmware of the device by a trusted party on the network," the statement read.

On Friday, HP issued a news release reiterating that no customers have reported unauthorized access to their LaserJet printers, and offered a firmware update that the company says will "mitigate this issue." The update is available at www.hp.com/support, in the "Drivers" category.

Researchers warned that if a hacker had gained control of a printer in this manner, however, there would be no way to reverse the process.

"If and when HP rolls out a fix, if a is already compromised, the fix would be completely ineffective. Once you own the firmware, you own it forever. That's why this problem is so serious, and so different," researcher Ang Cui said. "This is nothing like fixing a virus on your PC."

Hewlett-Packard recommends placing printers behind a firewall to protect exposure to remote hacks and disabling remote firmware upload capabilities on exposed printers.

(c)2011 the San Jose Mercury News (San Jose, Calif.)
Distributed by MCT Information Services

Citation: Hewlett-Packard offers fix for printers susceptible to remote hacks (2011, December 26) retrieved 18 April 2024 from https://phys.org/news/2011-12-hewlett-packard-printers-susceptible-remote-hacks.html
This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no part may be reproduced without the written permission. The content is provided for information purposes only.

Explore further

HP slams 'sensational' reports about LaserJet printer hack vulnerability

0 shares

Feedback to editors