PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
January 1, 2013189 citationsOpen Access

When Firmware Modifications Attack: A Case Study of Embedded Exploitation

View Full Paper
ACAng CuiMCMichael J. CostelloSSSalvatore J. Stolfo

Key Points

  • The study aims to demonstrate how firmware features can be exploited to inject malware into embedded devices.
  • Conducted a case study on HP-RFU LaserJet printer vulnerabilities
  • Developed proof of concept for printer malware capable of reconnaissance and propagation
  • Analyzed vulnerabilities in third-party libraries across 373 LaserJet firmware images.
  • Identified vulnerabilities that allow arbitrary malware injection into printers via printed documents
  • Showcased data from an exhaustive scan of publicly accessible printers across IPv4 space
  • Demonstrated that firmware update signing does not sufficiently protect against embedded system exploits.

Abstract

The ability to update firmware is a feature that is found in nearly all modern embedded systems. We demonstrate how this feature can be exploited to allow attackers to inject malicious firmware modifications into vulnerable embedded devices. We discuss techniques for exploiting such vulnerable functionality and the implementation of a proof of concept printer malware capable of network reconnaissance, data exfiltration and propagation to general purpose computers and other embedded device types. We present a case study of the HP-RFU (Remote Firmware Update) LaserJet printer firmware modification vulnerability, which allows arbitrary injection of malware into the printer’s firmware via standard printed documents. We show vulnerable population data gathered by continuously tracking all publicly accessible printers discovered through an exhaustive scan of IPv4 space. To show that firmware update signing is not the panacea of embedded defense, we present an analysis of known vulnerabilities found in third-party libraries in 373 LaserJet firmware images. Prior research has shown that the design flaws and vulnerabilities presented in this paper are found in other modern embedded systems. Thus, the exploitation techniques presented in this paper can be generalized to compromise other embedded systems.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Cui et al. (2013) studied this question.

synapsesocial.com/papers/6a185df78dad9275931eb800https://doi.org/10.7916/d8p55nkb
Ask AI
Helpful
Bookmark
Share
View Full Paper