Jump to content

Faxsploit will target your grandpa!

source: https://www.tomsguide.com/us/hp-printer-fax-hacks-defcon26,news-27795.html

Last sunday at Defcon 26 some researchers revealed you can hack fax machines now. and it's not just any old fax machine.

Most HP all in ones seem to be affected by it.

The fax protocol is pretty old already and hasn't really been changed. So almost every all in one which has been released since ever will use the same implementation. But:

So by just having a all in one printer with faxing capabilities they can target you by your fax number and enter your network.
If you have an HP all in one please check this message to see if yours is affected:
https://support.hp.com/us-en/document/c06097712
And make sure you update the firmware. And please also check your grandparents because they are most likely to still use fax and not being able to update the firmware of their device.

This attack works on any recent HP OfficeJet printer," Balmas said, which might be only a slight exaggeration. A security bulletin issued by HP earlier this month lists some 150 printer models, not just OfficeJets, that are affected by this flaw and need to have their firmware updated.

In July 2017, news broke of a remote-code-execution vulnerability in the SOAP protocol
[...]
Among other things, the researchers' HP all-in-one printer used SOAP.


But we where lucky because Fax is pretty old, so the vulnarabilities in SOAP weren't that bad for use as they explain here:


Using that flaw, the researchers were able to send a malicious fax that created a buffer overflow in a SOAP operation. The catch was that it required 2GB of data, which took about seven minutes of continuous transmission over the telephone lines.


But fax also supports color transmition. And while the black and white transmission uses the TIFF image format the color transmission uses the JPEF format.
Jpeg needs decompression and in this decompression they where able to implement the SOAP vulnarability too.
Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Sauron said:

In other news, messenger pigeons could be vulnerable to cross site scripting!

And targeted aerial projectiles fired at a great speeds. 

 

And rocks.

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, Sauron said:

In other news, messenger pigeons could be vulnerable to cross site scripting!

If you implement RFC1149 well it shouldn't right?
 

4 minutes ago, JoeyDM said:

And targeted aerial projectiles fired at a great speeds. 

 

And rocks.

That's just considered package loss :).

Link to comment
Share on other sites

Link to post
Share on other sites

RIP the entire Legal and Healthcare fields. Pretty much the only places that still use fax machines

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, GoldenLag said:

We should stop being faxeted on this

Your dad puns are nothing but a faxade

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, Levisallanon said:

If you implement RFC1149 well it shouldn't right?
 

That's just considered package loss :).

 

Absolutely killed me there:

Quote

Because IP only guarantees best effort delivery, loss of a carrier can be tolerated. With time, the carriers are self-regenerating.

 

 

If you want to reply back to me or someone else USE THE QUOTE BUTTON!                                                      
Pascal laptops guide

Link to comment
Share on other sites

Link to post
Share on other sites

It's time we start accepting the  fax. . .

I mean facts. . .

† 

In Flanders fields the poppies blow
Between the crosses, row on row,
    That mark our place; and in the sky
    The larks, still bravely singing, fly
Scarce heard amid the guns below.
 
We are the Dead. Short days ago
We lived, felt dawn, saw sunset glow,
    Loved and were loved, and now we lie,
        In Flanders fields.
 
Take up our quarrel with the foe:
To you from failing hands we throw
    The torch; be yours to hold it high.
    If ye break faith with us who die
We shall not sleep, though poppies grow
        In Flanders fields.

 

 

Cry havoc and let slip the Togs of war.  (Signature V3)

 

If you want me to reply, tag me @Tog Driver, Or quote me.

 

The grace of the Lord Jesus Christ, and the love of God, and the communion of the Holy Spirit be with you all.
‭‭II Corinthians‬ ‭13:14

Link to comment
Share on other sites

Link to post
Share on other sites

At the same point how many people even know how faxing works anymore? Let alone hack it. 

 

*yes I know its popular, we still have 2,000 fax numbers*

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, rcmaehl said:

RIP the entire Legal and Healthcare fields. Pretty much the only places that still use fax machines

Oh there is a bigger one that also loves their fax machines... 

 

... The US Government. 

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, Sauron said:

In other news, messenger pigeons could be vulnerable to cross site scripting!

If you think about it, that old horror movie trope is basically just a DDOS attack!

i5 6600k and GTX 1070 but I play 1600-900. 1440p BABY!

Still, don't put too much faith in my buying decisions. xD 

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, TechyBen said:

@TechyBen Wonders if he should open his new one... it has been sitting there in the box, glaring at him for days.

lol mine is a few years old.

Pixma MX452 *cough* @Dan Castellaneta ;)

a Moo Floof connoisseur and curator.

:x@handymanshandle x @pinksnowbirdie || Jake x Brendan :x
Youtube Audio Normalization
 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, rcmaehl said:

RIP the entire Legal and Healthcare fields.

No joke, lots of sensitive information goes via fax.

 

Can old faxes (sent or received) stored in memory be stolen?

 

If so, my wife's office will need a stand-alone non-networked fax.

System specs:

4790k

GTX 1050

16GB DDR3

Samsung evo SSD

a few HDD's

Link to comment
Share on other sites

Link to post
Share on other sites

10 hours ago, Terryv said:

No joke, lots of sensitive information goes via fax.

They should really consider if this is safe at all because fax is unencrypted in the first place. A wire tab would show the contents of the fax.

10 hours ago, Terryv said:

Can old faxes (sent or received) stored in memory be stolen?

In theory the first approach they showed could be used but you might notice it because the fax would be receiving for almost 30 minutes. But if the fax is also on outside business hours they might be able to access it. if it indeed stores older messages in the memory they would be able to extract that.

10 hours ago, Terryv said:

If so, my wife's office will need a stand-alone non-networked fax.

A fax needs to be on the phoneline to receive messages and they access it by the fax protocol itself, so it would still be vulnerable. You need to have a fax with updated firmware to prevent this attack.

Link to comment
Share on other sites

Link to post
Share on other sites

  • 5 weeks later...
3 hours ago, Levisallanon said:

For people who want to know more about it. The talk is now live!

Necromancy is illegal in most countries.

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, rcmaehl said:

Necromancy is illegal in most countries.

Asking for a friend: in which country/countries is it allowed then?

But the talk is really worth it to watch if you are into hacking etc. that's why I added it to the topic. They go over the whole process of how they found it and give a live demo at the end.

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, Levisallanon said:

But the talk is really worth it to watch if you are into hacking etc. that's why I added it to the topic. They go over the whole process of how they found it and give a live demo at the end.

It probably is. IMO the forums need a Cyber Security section but I can already predict it'd be full of "how do hack the facebooks?" threads

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×