Risk
8/10/2010
12:36 PM
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Xerox Advises Securing Data In Printer Hard Drives

Network printer and MFP hard drives may contain sensitive data that can be secured using encryption or overwriting.

And while the installed base of printers turns over rapidly as a whole, many users hang onto their printers and MFPs, "the Xerox 914 is still out there and in use," according to Kovnat. (According to Xerox, the Xerox 914, introduced in 1959, was "the first automatic, plain-paper commercial copier.")

It's important to remember that the concern doesn't automatically go away when your company is done with a printer, Kovnat stresses. For unencrypted disks that a company wants to re-use, one option is to overwrite the disk to the point where previous data cannot be retrieved -- the same as what gets done with hard drives from desktops, notebooks, and servers, external hard drives, NAS/SANs, and so on.

If the company doesn't plan to re-use the disk, Xerox has a Data Crush Program, where drives that qualify for the program get shredded. "Machines including the disk go into a big industrial crusher, and are then hauled off to a materials recyclers where the crushed material is put through an industrial shredder to quarter-or-small sized pieces which are then separated," says Kovnak. Here's a video of Xerox's Competitive Product Crush Program.

(Many channel partners and other companies offer certified disk/data destruction services; you can also buy hard drive shredders, and even un powered hard drive whacking mechanisms... or -- being sure you're wearing goggles and know what you're doing -- you can try using a power drill or a real big hammer.)

Security in terms of your company's network printers and MFPs isn't just about data stored on them, Kovnat adds. These devices are, in essence, specific-purpose computers... which means that they're running an operating system, and are vulnerable to network attacks and other exploits, letting them be used as an entry point into. And often, the operating system and application software on printers is out-of-date, leaving the devices more vulnerable to network-based attacks.

Previous
3 of 3
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-1421
Published: 2014-04-22
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php.

CVE-2013-2105
Published: 2014-04-22
The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a symlink attack on /tmp/browser.html.

CVE-2013-2187
Published: 2014-04-22
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to the home page.

CVE-2013-4116
Published: 2014-04-22
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

CVE-2013-4472
Published: 2014-04-22
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

Best of the Web