Site navigation

Fax Machine Cybersecurity Weaknesses Put Companies at Risk

Ross Kelly

,

Fax Machine Cybersecurity

Two cybersecurity experts have exposed significant security vulnerabilities in fax machines that could be putting millions of companies at risk. 

Cybersecurity researchers have revealed security flaws in fax machines that enable attackers to use image data to break into company networks.

The study was conducted at the Def Con hacker conference, held in Las Vegas, Nevada, and the two researchers that carried it out claim millions of companies worldwide could be at risk due to inadequate fax line security.

Booby-Trapped Images

Many companies use fax machines that also double as printers and photocopiers, which often have a connection to a firm’s internal network. Using booby-trapped image data, attackers are able to exploit formatting protocols established during the 1980s.

The hack involves attackers sending an image file through a phone line (or a file that the machine believes to be an image file) that is specifically coded to contain malicious software. Upon receiving the message, the image is decoded and uploaded into a fax printer’s memory – this then enables the hacker to seize control of the device and begin spreading malicious code throughout a company network.

For their test case, security experts Yaniv Balmas and Eyal Itkin used software exploit, Eternal Blue, as the payload. External Blue is the software best known for its use in the devastating WannaCry attack that took place last year.

Fax Machine Cybersecurity

Balmas and Itkin used Hewlett Packard‘s OfficeJet Pro all-in-one fax printers as part of their research. As a global market leader for fax machines, companies across the globe use hardware provided by the US-based firm. Security vulnerabilities weren’t restricted to HP’s products, however, with Canon and Epson machines also highlighted as vulnerable.

According to Balmas, fax machines could be putting companies at risk due to outdated security measures. Speaking to the BBC, he said: “Fax has no security measures built in – absolutely nothing”.

He added: “The protocols we use for fax were standardised in the 1980s and have not been changed since.”

Fax Protocols, Balmas said, were “poorly worded” and as such, manufacturers had interpreted them in different ways. It is this lack of consistency that contributed to the vulnerabilities highlighted in their research.

Around 45 million fax machines are still used by companies around the world and are widely used in the healthcare, banking and legal sectors – NHS England alone is known to use around 9,000 fax machines. With such sensitive data at risk, manufacturers and businesses must ensure that adequate security protocols are in place.

As of yet, there is no evidence to suggest that attackers have been using booby-trapped images to gain access to company networks, however, the vulnerabilities highlighted are significant. HP has issued a patch for its products, which it says will close all gaps in security.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data