పట్టించుకోని ముప్పు
భద్రతా బృందాలు తమ attack surfaceను జాబితా చేసేటప్పుడు, సాధారణంగా servers, endpoints, cloud identities, మరియు mobile devices గురించి ఆలోచిస్తారు. కానీ చాలా తక్కువ సంస్థలు office multi-function printer (MFP)-ను first-class security citizenగా పరిగణిస్తాయి. అది పెద్ద తప్పు. Printerలు మిగతా అన్నిటితో అదే networkను పంచుకుంటాయి, అయినా అవి తరచుగా patching programs, segmentation policies, మరియు monitoring నుంచి మినహాయింపును పొందుతాయి — దాడి చేసేవారు ఇష్టపడే నిర్లక్ష్యం ఇదే.
Apple-కేంద్రిత enterprises సందర్భంలో, Apple యొక్క DEP మరియు identity-based security వంటి device management పద్ధతులు పరిపక్వంగా ఉన్నప్పటికీ, printer మాత్రం గతకాలపు పరికరంగానే మిగిలిపోతుంది. AirPrint ఒక documentను printerకు పంపడం చాలా సులభం చేస్తుంది, కానీ ఆ సౌలభ్యాన్ని సాధ్యం చేసే servicesనే దుష్ట trafficకు gatewayగా కూడా మారుస్తాయి. ఒకే printer compromise అయితే, అది servers, file shares, లేదా cloud management APIsలోకి వెళ్లే pivot pointగా మారవచ్చు.
Printerలు ఎందుకు ప్రత్యేకంగా భద్రత లేనివి
Printerలను అత్యల్ప భద్రత కలిగిన పరికరంగా మార్చే ఒకే design flaw లేదు. బదులుగా, కారకాల కలయిక వల్ల అవి అత్యంత చెడు risk profileను కలిగి ఉంటాయి.
Firmware నిర్లక్ష్యం
నెలవారీ security updates పొందే laptopsలా కాకుండా, printerలు చాలా సంవత్సరాలు ఒక్క patch కూడా లేకుండా ఉండిపోతాయి. చాలా IT సంస్థలు printerను ఇంటి applianceలా చూస్తాయి: plug చేయండి, ఒకసారి configure చేయండి, ఆపై మర్చిపోండి. Vendors themselves కూడా తరచుగా sporadic firmware fixes మాత్రమే అందిస్తారు, formal security advisory channel లేకుండా. ఒక critical vulnerability బయటపడినప్పుడు, active exploitationను ఆపడానికి స్పందన చాలా నెమ్మదిగా ఉంటుంది. End-of-life printerలు మరింత చెడ్డవి — అవి zero updates మాత్రమే పొందుతాయి, తెలిసిన లోపాలను అనిర్దిష్టకాలం తెరిచి వదిలేస్తాయి.
Default Credentials మరియు Open Protocols
బాక్స్ నుంచి బయటకు వచ్చిన వెంటనే, printerలలో సాధారణంగా default credentialsతో సులభమైన administrative interfaces ఉంటాయి, ఉదాహరణకు "admin:password" లేదా "admin:1234." దాడి చేసేవారు open port 9100 (raw printing), 515 (LPD), లేదా 631 (IPP) ఉన్న devices కోసం scan చేసి ఆ defaultsను ప్రయత్నిస్తారు. Credentials మార్చిన తర్వాత కూడా, embedded web servers తరచుగా విస్తృతమైన system informationను బయటపెడతాయి, తద్వారా మరింత దాడులకు సహాయపడతాయి.
నెట్వర్క్లో ప్రాధాన్య స్థితులు
Printerలు బలంగా నియంత్రించబడిన మూలలో ఉంచబడవు. అవి office roomsలో, సాధారణంగా workstationsతో అదే subnetలో ఉంటాయి. అక్కడి నుంచి అవి outbound connectionsను ప్రారంభించగలవు, అనవసరంగా వచ్చే inbound trafficను స్వీకరించగలవు, మరియు networkలోని ఇతర ఏ deviceతోనైనా మాట్లాడగలవు. ఇది zero-trust సూత్రానికి విరుద్ధం: ప్రతి deviceకు అది తప్పనిసరిగా అవసరమైన access మాత్రమే ఉండాలి. Printerలకు ప్రతి employee computerతో, మరింతగా అన్ని servers లేదా internetతో మాట్లాడాల్సిన అవసరం చాలా అరుదు.
Apple enterprises కూడా మినహాయింపు కావు
మొత్తం Mac వాతావరణం సహజంగానే మరింత భద్రమని భావించడం సులభం. అది endpointsకు నిజమే, కానీ printerలు platform agnostic. AirPrint printer తన సేవలను ప్రకటించడానికి Bonjourను ఉపయోగిస్తుంది, దీని వల్ల ఏ Mac, iPhone, లేదా iPadకైనా దాన్ని సులభంగా కనుగొనవచ్చు. సమస్య ఏమిటంటే Bonjour discovery local networkలో ఇప్పటికే ఉన్న దాడి చేసేవారికి కూడా పనిచేస్తుంది. వారు printerలను enumerate చేసి, suspiciousగా కనిపించకుండా management interfacesను యాక్సెస్ చేయడానికి ప్రయత్నించగలరు.
అదనంగా, Apple కనెక్టెడ్ ecosystemను ముందుకు నెట్టి కొనసాగిస్తున్న కొద్దీ, మరిన్ని devices corporate వాతావరణంలోకి చేరుతున్నాయి. దాంతో printing workflows ద్వారా మరింత data ప్రవహిస్తుంది, compromised printerలు sensitive documentsను విని పొందడానికి లేదా బయటకు తరలించడానికి మరిన్ని అవకాశాలు కలుగుతాయి. Printer ఇకపై కేవలం కాగితాన్ని కదిలించే hardware మాత్రమే కాదు; అది office మీద పూర్తి దృష్టి ఉన్న ఒక network endpoint.
అత్యల్ప భద్రత కలిగిన పరికరాన్ని బలపరచడం
సంతోషకరమైన విషయం ఏమిటంటే, ఉత్పాదకతను కోల్పోకుండా ఎక్కువ riskను తొలగించగల సూటి చర్యలు ఉన్నాయి.
- Printerలను isolated VLANలో లేదా కఠినమైన firewall rulesతో ప్రత్యేక print networkలో ఉంచండి. Authorized devices నుండి print jobs మరియు admin subnet నుండి management traffic వంటి నిర్దిష్ట, అవసరమైన communicationsను మాత్రమే అనుమతించండి.
- Firmware update scheduleను రూపొందించండి. Operating systemsలా, printer patchesను తనిఖీ చేసి deploy చేయడానికి quarterly లేదా monthly reminderను ఏర్పాటు చేయండి. దీనిని standard lifecycle management processలో భాగంగా చేయండి.
- FTP, Telnet, అవసరం లేని HTTP, మరియు network printerలు IPPS వంటి మరింత భద్రమైన protocolsను ఉపయోగించగలిగితే raw port 9100 సహా అన్ని unused servicesను disable చేయండి. అలాగే SNMP మరియు community stringsను read-onlyగా పరిమితం చేయండి.
- అన్ని printing devicesలో default passwordsను మార్చి, బలమైన administrative credentialsను తప్పనిసరి చేయండి. వాటిని నిర్వహించడానికి central vaults లేదా directory servicesను ఉపయోగించండి.
- Loggingను enable చేసి, printerలను మీ security information and event management (SIEM) toolతో integrate చేయండి. అసాధారణ burst printing, business hoursకు బయట admin logins, మరియు outbound scan behaviorను గమనించండి.
- ప్రతి సంవత్సరం printer security assessment చేయండి. ఇందులో manufacturer security advisoriesను సమీక్షించడం, model EOL statusను అంచనా వేయడం, మరియు device configను baselineతో పోల్చి చూడడం ఉండాలి. Printerలను మార్చేటప్పుడు, నిర్ధారించదగిన update commitments మరియు secure boot capabilities ఉన్నవాటినే కోరండి.
Configuration మార్పులకు మించి, enterprises printerల physical security గురించి కూడా ఆలోచించాలి. అనేక devicesలో print job imagesను నిల్వ చేసే removable hard drives ఉంటాయి, కాబట్టి decommissioning విధానాల్లో secure disk wiping తప్పనిసరిగా ఉండాలి. పంచుకునే లేదా బహిరంగ ప్రదేశాల్లో, badge release లేదా PIN వంటి device authentication ద్వారా printing అవసరం కావాలి, తద్వారా sensitive documents trayలో వదిలిపెట్టబడకుండా ఉంటుంది.
బాక్స్ను దాటి: సంస్కృతి మరియు విధానం
Printerలను భద్రపరచడం పూర్తిగా technical సమస్య కాదు. అవి ఇంకా భద్రముగా లేకపోవడానికి కారణం చాలా సార్లు సాంస్కృతికమే. అనేక సంస్థల్లో printerలను security teams కాకుండా facilities లేదా office managers నిర్వహిస్తారు. దాంతో అవి asset list మరియు security roadmapలో కనిపించవు. దాన్ని సరిచేయడానికి, printer securityకి స్పష్టమైన ownershipను IT operations teamకు అప్పగించి, చర్య తీసుకోవడానికి వారికి budget మరియు mandate ఉన్నట్లు నిర్ధారించండి.
Printable dataను కూడా మళ్లీ ఆలోచించడం అవసరం. Print jobsలో తరచుగా personally identifiable information, financial records, లేదా proprietary documents ఉంటాయి. చాలా modern printerలు imagesను disksలో నిల్వ చేస్తాయి, ఇవి decommissioning తర్వాత కూడా access చేయవచ్చు. Device decommissioning, disk wiping, మరియు secure pull printingపై బలమైన policies riskను గణనీయంగా తగ్గిస్తాయి.
Education కూడా అంతే ముఖ్యమైనది. Usersకు security measuresను దాటవేయడం లేదా ఇతర vectorsను తెరచే third-party driversను install చేయడం సాధ్యం కాకూడదు. Apple-కేంద్రిత వాతావరణంలో, administrators profilesను ఉపయోగించి AirPrint device discoveryను పరిమితం చేయవచ్చు మరియు printersతో కమ్యూనికేట్ చేసే Apple devicesకు encryptionను enforce చేయవచ్చు. అయితే, ఆ settings Apple వైపునే రక్షిస్తాయి; printer itself harden చేసి patch చేయకపోతే అది ఇంకా బలహీనంగానే ఉంటుంది.
ముందుకు వెళ్లే దారి: సంపూర్ణ రక్షణ నిర్మాణం
ఈ విశ్లేషణ సూచిస్తున్నట్లుగా, చాలా సంస్థల్లో printerలు అత్యల్ప భద్రత కలిగిన పరికరంగా ఉండటానికి కారణం అవి సహజంగా చెడ్డవి కావడం కాదు, వాటిని పట్టించుకోకపోవడమే. శ్రద్ధ పురోగతిని తీసుకువస్తుంది. ముఖ్యంగా Apple administrators కోసం, roadmap స్పష్టంగా ఉంది: printerలను enterprise security postureలోకి తీసుకురావాలి, secure defaultsను కోరాలి, మరియు Macs మరియు iPhonesకు వర్తించే అదే కఠినతతో governanceను అమలు చేయాలి. అది జరిగాక, printer ఇకపై బలమైన defenses మధ్య ఉన్న బలహీన స్థానం కాదు.
దాడి చేసేవారు నిరంతరం బలహీన స్థానాలను వెతుకుతున్న కాలంలో, ఒక whole class of devicesను unmanagedగా మరియు unpatchableగా వదిలేయడం కేవలం oversight కాదు — అది ఒక ఆహ్వానం. తదుపరి సారి office printer పక్కన వెళ్లినప్పుడు, ఒకసారి మరోలా చూడండి. అది మీ వద్ద ఉన్న అత్యంత ప్రమాదకరమైన పరికరం కావచ్చు.
ఈ వ్యాసం 9to5Mac నివేదిక ఆధారంగా ఉంది. మూల వ్యాసాన్ని చదవండి.
Originally published on 9to5mac.com

