<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>MFD on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/mfd/</link>
    <description>Recent content in MFD on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 07 Aug 2013 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/mfd/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>MFD Vulnerabilities</title>
      <link>https://insinuator.net/2013/08/mfd-vulnerabilities/</link>
      <pubDate>Wed, 07 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/mfd-vulnerabilities/</guid>
      <description>&lt;p&gt;A recent &lt;a href=&#34;http://seclists.org/bugtraq/2013/Aug/28&#34;&gt;post&lt;/a&gt; describing some nasty vulnerabilities in HP &lt;a href=&#34;http://www.google.de/search?hl=en&amp;amp;site=imghp&amp;amp;tbm=isch&amp;amp;source=hp&amp;amp;biw=1276&amp;amp;bih=663&amp;amp;q=multifunction+device&amp;amp;oq=multifunction+device&amp;amp;gs_l=img.3..0j0i5j0i24l7.2450.5517.0.5606.20.15.0.4.4.0.99.959.15.15.0....0...1ac.1.24.img..1.19.973.43a2mDdYMDE&#34;&gt;multifunction devices&lt;/a&gt; (MFDs) brings back memories of a &lt;a href=&#34;https://www.troopers.de/wp-content/uploads/2011/04/TR11_Schaefer_Luft_Multifunction_devices.pdf&#34;&gt;presentation&lt;/a&gt; Micele and I gave at &lt;a href=&#34;https://www.troopers.de/archives/troopers11&#34;&gt;Troopers11&lt;/a&gt; on MFD security. The published vulnerabilities are highly relevant  (such as unauthenticated retrieval of administrative credentials) and reminded me of some of the basic recommendations we gave. MFD vulnerabilities are regularly discovered, and it is often basic stuff such as hardcoded $SECRET_INFORMATION (don’t get me wrong here, I fully appreciate the quality of the published research, but it is just surprising — let’s go with this attribute 😉 — that those types of vulnerabilities still occur that often). Yet many environments &lt;em&gt;do not&lt;/em&gt; patch their MFDs or implement other controls. As it is not an option to not use MFDs (they are already present in pretty much every environment, and the vast majority of vendors periodically suffer from vulnerabilities), let’s recall some of our recommendations as those would have mitigated the risk resulting from the published vulnerability:&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Wrap-up on MFD Security</title>
      <link>https://insinuator.net/2011/11/a-wrap-up-on-mfd-security/</link>
      <pubDate>Wed, 16 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/a-wrap-up-on-mfd-security/</guid>
      <description>&lt;p&gt;On last year’s &lt;a href=&#34;http://www.troopers.de/archives/troopers11/&#34;&gt;TROOPERS11&lt;/a&gt;, Matthias (mluft) and I gave a &lt;a href=&#34;http://www.troopers.de/wp-content/uploads/2011/04/TR11_Schaefer_Luft_Multifunction_devices.pdf&#34;&gt;talk&lt;/a&gt; on Multifunction Devices. Hardly surprising: It was related to the state of &lt;em&gt;secure&lt;/em&gt; operation of MFDs. It was heavily motivated by experiences we collected out in the wild. We faced a frightening low level of awareness concerning the role of MFDs for the overall security picture – in particular regarding the processing of sensitive data…&lt;/p&gt;&#xA;&lt;p&gt;However, instead of only showing and proving well-known weaknesses and vulnerabilities, we decided to adapt ERNW’s *&lt;a href=&#34;http://www.ernw.de/content/e7/e181/e1612/download1614/ERNW_LANline_VirtCloudSec_Keynote_ger.pdf&#34;&gt;Seven Sisters&lt;/a&gt; *model in order to match the needs of secure MFD operation and to develop some kind of guideline. As Matthias already lost some &lt;a href=&#34;http://www.insinuator.net/2011/04/sisters-act-of-mfd-security/&#34;&gt;words&lt;/a&gt; on this, I’m not gonna waste your valuable time by repeating, what has already been said. However I described our approach and our thoughts on that topic in a recently published &lt;a href=&#34;http://ernw.de/content/e15/e28/index_ger.html&#34;&gt;ERNW Newsletter&lt;/a&gt;. If for what ever reason you didn’t see our talk or even didn’t attend &lt;a href=&#34;http://www.troopers.de/archives/troopers11/&#34;&gt;TROOPERS11&lt;/a&gt; at all, have a look on Newsletter 37 and give us feedback on what you think about the whole topic…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sisters’ Act of MFD Security</title>
      <link>https://insinuator.net/2011/04/sisters-act-of-mfd-security/</link>
      <pubDate>Thu, 07 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/sisters-act-of-mfd-security/</guid>
      <description>&lt;p&gt;Recently Micele and I were researching for our talk about the current state of security of Multifunction Devices (MFDs). Since we’re both seasoned pentesters who are quite familar with MFDs, we were really surprised that very little new research is going on on the topic of MFD security. While diving deeper into the topic, we found a very simple explanation for this: As in 2002, it is still possible to download print or scan jobs using &lt;a href=&#34;http://h20000.www2.hp.com/bc/docs/support/SupportManual/bpl13208/bpl13208.pdf&#34;&gt;PJL&lt;/a&gt;, many devices still offer default FTP or Telnet access, and, of course, stored files can be recovered from MFD hard drives — on an enterprise wide scale. To even strengthen our impression of the current state of MFD security, most devices crashed or did go wild while performing some scans — and we do not talk about fuzzing here.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
