Vending machines and printers open network threat

As common office items such as printers, vending machines and lifts become more advanced and run embedded operating systems, they could easily create vulnerabilities that are often overlooked by administrators.

The warning came from Steve Reddock, technical services manager at Internet Security Systems Australasia (ISS), who was presenting on the first day of the AusCERT 2006 conference in Queensland's Gold Coast.

"The second most common network device is the printer. Printers have moved along and have an awful lot of computing power in them but when was the last time you heard of an organisation that was trying to patch their printers? Like patching your routers, it is just not done very often," said Reddock.

According to Reddock, along with printers, vending machines, lifts and a diverse range of common office equipment can run on embedded versions of Windows and various flavours of Unix. Because these embedded systems are never patched, if they are connected to the network then they are vulnerable to virus attack.

"A US retail company found out -- the hard way -- that their vending machines were running the blaster worm," said Reddock.

Another example Reddock gave was of a company that discovered its elevator control systems were, unknown to the IT department -- surfing the Internet. "It gives a whole new meaning to the term crashing," he joked.

"These practices are incompatible with good security," he said.

The solution, according to Reddock, is putting additional protections on the network and to vigilantly monitor network traffic.

"If you clarify the network traffic properly and keep an eye on [it,] then suddenly when your vending machine starts surfing the Internet then it will stick out like a sore thumb," he added.

Munir Kotadia travelled to the Gold Coast as a guest of AusCERT.

Advertisement

Talkback 1 comments

    Old News Anonymous -- 24/05/06 (in reply to #120134884)

    This whole idea was first presented in San Diego, CA back in 2001.

    http://members.cox.net/ltlw0lf/printers/index.html

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • Array IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • More blogs »

Tags

Back to top

Featured