techPowerUp! Forums

Go Back   techPowerUp! Forums > www.techpowerup.com > News

Reply
 
Thread Tools
Old Dec 23, 2011, 10:04 PM   #1
qubit
Overclocked quantum bit
 
qubit's Avatar
 
Join Date: Dec 2007
Location: Quantumville UK
Posts: 8,719 (4.31/day)
Thanks: 4,216
Thanked 3,334 Times in 1,970 Posts

System Specs

HP Printer Firmware Vulnerability Fixed: Opportunistic Lawsuit's Lost Opportunity?

Three weeks ago, we brought you news that researchers had apparently found serious vulnerabilities in the firmware of HP printers that can allow hackers to cause the fuser to overheat and almost make the paper inside catch fire. HP dismissed these claims as exaggerated, but said that they would look into it. Three days later, we reported that some enterprising New Yorker called David Goldblatt sued HP, alleging that he would not have bought their printers had he known about this problem beforehand, which seems a bit unlikely when you consider that HP is the number one printer brand by a mile. Now HP have released patches for these vulnerabilities and issued the following press release:
Quote:
On Nov. 29, HP announced that the potential existed for a certain type of unauthorized access to some HP LaserJet printers and confirmed it has received no customer reports of unauthorized access. HP today issued the following statement:

HP has built a firmware update to mitigate this issue and is communicating this proactively to customers and partners. No customer has reported unauthorized access to HP. HP reiterates its recommendation to follow best practices for securing devices by placing printers behind a firewall and, where possible, disabling remote firmware upload on exposed printers.

The firmware update can be found at www.hp.com/support and selecting Drivers.

Additional printer security information is available at www.hp.com/go/secureprinting.
It will be interesting to see if Goldblatt's opportunistic lawsuit now continues, given that the flaws are easily fixed with a patch and the printers should be sitting behind a firewall anyway. Somehow, it looks like Goldblatt's opportunity has vanished as quickly as one can say "update".
qubit is offline  
Reply With Quote
The Following User Says Thank You to qubit For This Useful Post:
Old Dec 23, 2011, 10:24 PM   #2
newtekie1
Semi-Retired Folder
 
newtekie1's Avatar
 
Join Date: Nov 2005
Location: Indiana
Posts: 17,903 (6.47/day)
Thanks: 785
Thanked 5,185 Times in 3,754 Posts

System Specs

I like how the guy's lawsuit claims the printers can be hacked and compromise an "otherwise secure" network. But the hack requires a compromised computer, or at least a computer to download the compromised firmware and install it on the printers or it requires the printer be directly connected to the internet with a public IP. Both cases would mean the network is not "otherwise secure".
__________________

Rig1: System Specs.
Rig2: A8-5600K@4.4GHz / AsRock FM2A75 Pro4 / 8GB Corsair DDR3-1600 9-9-9-24 / HD7560D / Samsung DVD-Burner / 1.5TB WD Green + 3x3TB WD RED in RAID5
Rig3: Athlon X2 4200+ / M4A79 Deluxe / 4GB G.Skill Pi DDR2-800 4-4-4-12 / GT430 / Sony DVD-Burner / 500GB WD
Rig4: Phenom II x6 1605T @ 3.6GHz / Asus M5A99X Evo / 8GB PNY DDR3-1600 9-9-9 / GTX470 & GTX470 / Samsung DVD-Burner / 1.5TB Seagate
newtekie1 is offline  
Reply With Quote
The Following User Says Thank You to newtekie1 For This Useful Post:
Old Dec 23, 2011, 10:26 PM   #3
qubit
Overclocked quantum bit
 
qubit's Avatar
 
Join Date: Dec 2007
Location: Quantumville UK
Posts: 8,719 (4.31/day)
Thanks: 4,216
Thanked 3,334 Times in 1,970 Posts

System Specs

Yeah, brilliant, isn't it? I wonder how much dough this lawsuit is gonna cost Mr Goldblatt?
__________________
Siggie in the post.
qubit is offline  
Reply With Quote
Old Dec 24, 2011, 06:08 AM   #4
phanbuey
Eligible for custom title
 
phanbuey's Avatar
 
Join Date: Nov 2007
Location: Miami
Posts: 5,011 (2.45/day)
Thanks: 1,484
Thanked 960 Times in 813 Posts

System Specs

its funny if you know what blatt means in russian.
phanbuey is offline  
Reply With Quote
Old Dec 24, 2011, 12:41 PM   #5
Velvet Wafer
3500 Posts
 
Velvet Wafer's Avatar
 
Join Date: Jun 2009
Location: North of Germany
Posts: 3,849 (2.63/day)
Thanks: 2,288
Thanked 1,026 Times in 839 Posts
Send a message via ICQ to Velvet Wafer Send a message via MSN to Velvet Wafer

System Specs

Its funny, as everyone knows that Goldblatt is a jewish name, derived from German... this Jew here wasnt rich enough it seems, so he filed a nice new Lawsuit against HP

Phanbuey, i think you dont mean "Blatt", but rather "Bled"
__________________
CPU-Z validation sig pics temporarily blocked
Velvet Wafer is offline  
Reply With Quote
Old Dec 25, 2011, 11:38 PM   #6
CrAsHnBuRnXp
Eligible for custom title
 
CrAsHnBuRnXp's Avatar
 
Join Date: Oct 2007
Location: United States
Posts: 5,123 (2.48/day)
Thanks: 456
Thanked 644 Times in 530 Posts

System Specs

Quote:
Originally Posted by phanbuey View Post
its funny if you know what blatt means in russian.
Quote:
Originally Posted by Velvet Wafer View Post
Its funny, as everyone knows that Goldblatt is a jewish name, derived from German... this Jew here wasnt rich enough it seems, so he filed a nice new Lawsuit against HP

Phanbuey, i think you dont mean "Blatt", but rather "Bled"
"Blatt" means nothing. "Bled" however, means "pale."
CrAsHnBuRnXp is offline  
Crunching for Team TPU
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Canon IP4000R printer - How to remove printer admin PW? 3400 General Hardware 4 Jun 8, 2011 01:06 AM
[FS] WR Breaker Golden Q9650 - rare opportunity Jor3llBR Buy/Sell/Trade/Giveaway Forum 10 Apr 18, 2010 02:12 AM
GE and Intel Invest $250 million in New Market Opportunity malware News 3 Apr 21, 2009 06:46 PM
New Vulnerability Hits Excel malware News 3 Jan 19, 2008 03:51 PM


All times are GMT. The time now is 09:44 AM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts