Columbia University's Intrusion Detection Systems Lab has found a significant core vulnerability in certain networked HP printers that lets a remote system infiltrate print jobs, remotely inject malware into the printer's firmware that takes control of the machine.
The lab, headed by Professor Salvatore J. Stolfo, has been doing research on the vulnerabilities of embedded systems for the last year, identifying more than 540,000 publicly accessible embedded devices configured with factory default root passwords: this includes routers, VoIP phones, webcams, digital energy systems, and IPTV/Cable boxes.
Networked printers are a part of this environment, and researcher Ang Cui discovered certain HP LaserJet printers have a critical remote firmware update vulnerability. Stolfo and Cui show how a remote system can take complete control of these printers in the video we've embedded below. It's a definite must see.
"This work started by looking at printers as a device that could harbor malicious software that could do very bad damage…physical damage, for example. So we attempted to develop malicious software that would make the printer burn," Stolfo says in the presentation. "I can't think of a better way of demonstrating the vulnerabilities that are inherent in printers…the paper only browned rather than burned. Then, however, looking at what was achieved, it became crystal clear that the problem was far worse than burning paper or burning printers. Printers are everywhere, they're reachable through email, through thumb drives, through downloads, any perimeter defenses can be pierced because documents freely flow across perimeters, and documents that are printed to these devices can harbor firmware updates that are entirely stealthy and cannot be viewed. There's just no antivirus software to stop this type of threat."
The team released this information a little more than a week ago, and HP told MSNBC that it has to verify the vulnerability itself before any comments can be made (or security bulletins can be issued.)
Europe may be plunging the world into another recession but American shoppers apparently don't care. In yet another validation of the surge in consumer spending we witnessed during Black Friday and Cyber Monday, consumer electronics goliath Sony also enjoyed a sales spike and -- here's the kicker -- without slashing prices.



Microsoft's window of opportunity when it comes to tablets is closing. Release of Windows 8 is expected
If you maintain a server or network, you understand the importance of being able to monitor it around the clock. There are a number of tools available that can be used to keep an eye on your network whilst on that network, but there will be numerous occasions when you are away from the office but still need to check that things are running smoothly. PRTG Network Monitor is one such network monitoring tool, but for when you are out and about you can turn to
RootsMagic has updated its popular family history software to version 5.0. RootsMagic 5, which can be road-tested as a cut-down Essentials version, adds a number of new features for those who purchase the full version. These include media tagging, a research manager and timeline view.
Research in Motion is accepting to the realities of the smartphone industry, saying Tuesday its new Mobile Fusion device management software will work with iOS and Android devices in addition to BlackBerry smartphones. The announcement suggests RIM might be ready to concede the market to its bigger rivals.



Observing Registry activity on your PC can be very useful when you’re troubleshooting odd problems. There are some great tools around to help. Sysinternals