పట్టించుకోని ముప్పు

భద్రతా బృందాలు తమ attack surface‌ను జాబితా చేసేటప్పుడు, సాధారణంగా servers, endpoints, cloud identities, మరియు mobile devices గురించి ఆలోచిస్తారు. కానీ చాలా తక్కువ సంస్థలు office multi-function printer (MFP)-ను first-class security citizen‌గా పరిగణిస్తాయి. అది పెద్ద తప్పు. Printer‌లు మిగతా అన్నిటితో అదే network‌ను పంచుకుంటాయి, అయినా అవి తరచుగా patching programs, segmentation policies, మరియు monitoring నుంచి మినహాయింపును పొందుతాయి — దాడి చేసేవారు ఇష్టపడే నిర్లక్ష్యం ఇదే.

Apple-కేంద్రిత enterprises సందర్భంలో, Apple యొక్క DEP మరియు identity-based security వంటి device management పద్ధతులు పరిపక్వంగా ఉన్నప్పటికీ, printer మాత్రం గతకాలపు పరికరంగానే మిగిలిపోతుంది. AirPrint ఒక document‌ను printer‌కు పంపడం చాలా సులభం చేస్తుంది, కానీ ఆ సౌలభ్యాన్ని సాధ్యం చేసే servicesనే దుష్ట traffic‌కు gatewayగా కూడా మారుస్తాయి. ఒకే printer compromise అయితే, అది servers, file shares, లేదా cloud management APIs‌లోకి వెళ్లే pivot point‌గా మారవచ్చు.

Printer‌లు ఎందుకు ప్రత్యేకంగా భద్రత లేనివి

Printer‌లను అత్యల్ప భద్రత కలిగిన పరికరంగా మార్చే ఒకే design flaw లేదు. బదులుగా, కారకాల కలయిక వల్ల అవి అత్యంత చెడు risk profile‌ను కలిగి ఉంటాయి.

Firmware నిర్లక్ష్యం

నెలవారీ security updates పొందే laptops‌లా కాకుండా, printer‌లు చాలా సంవత్సరాలు ఒక్క patch కూడా లేకుండా ఉండిపోతాయి. చాలా IT సంస్థలు printer‌ను ఇంటి appliance‌లా చూస్తాయి: plug చేయండి, ఒకసారి configure చేయండి, ఆపై మర్చిపోండి. Vendors themselves కూడా తరచుగా sporadic firmware fixes మాత్రమే అందిస్తారు, formal security advisory channel లేకుండా. ఒక critical vulnerability బయటపడినప్పుడు, active exploitation‌ను ఆపడానికి స్పందన చాలా నెమ్మదిగా ఉంటుంది. End-of-life printer‌లు మరింత చెడ్డవి — అవి zero updates మాత్రమే పొందుతాయి, తెలిసిన లోపాలను అనిర్దిష్టకాలం తెరిచి వదిలేస్తాయి.

Default Credentials మరియు Open Protocols

బాక్స్‌ నుంచి బయటకు వచ్చిన వెంటనే, printer‌లలో సాధారణంగా default credentials‌తో సులభమైన administrative interfaces ఉంటాయి, ఉదాహరణకు "admin:password" లేదా "admin:1234." దాడి చేసేవారు open port 9100 (raw printing), 515 (LPD), లేదా 631 (IPP) ఉన్న devices కోసం scan చేసి ఆ defaults‌ను ప్రయత్నిస్తారు. Credentials మార్చిన తర్వాత కూడా, embedded web servers తరచుగా విస్తృతమైన system information‌ను బయటపెడతాయి, తద్వారా మరింత దాడులకు సహాయపడతాయి.

నెట్‌వర్క్‌లో ప్రాధాన్య స్థితులు

Printer‌లు బలంగా నియంత్రించబడిన మూలలో ఉంచబడవు. అవి office rooms‌లో, సాధారణంగా workstations‌తో అదే subnet‌లో ఉంటాయి. అక్కడి నుంచి అవి outbound connections‌ను ప్రారంభించగలవు, అనవసరంగా వచ్చే inbound traffic‌ను స్వీకరించగలవు, మరియు network‌లోని ఇతర ఏ device‌తోనైనా మాట్లాడగలవు. ఇది zero-trust సూత్రానికి విరుద్ధం: ప్రతి device‌కు అది తప్పనిసరిగా అవసరమైన access మాత్రమే ఉండాలి. Printer‌లకు ప్రతి employee computer‌తో, మరింతగా అన్ని servers లేదా internet‌తో మాట్లాడాల్సిన అవసరం చాలా అరుదు.

Apple enterprises కూడా మినహాయింపు కావు

మొత్తం Mac వాతావరణం సహజంగానే మరింత భద్రమని భావించడం సులభం. అది endpoints‌కు నిజమే, కానీ printer‌లు platform agnostic. AirPrint printer తన సేవలను ప్రకటించడానికి Bonjour‌ను ఉపయోగిస్తుంది, దీని వల్ల ఏ Mac, iPhone, లేదా iPad‌కైనా దాన్ని సులభంగా కనుగొనవచ్చు. సమస్య ఏమిటంటే Bonjour discovery local network‌లో ఇప్పటికే ఉన్న దాడి చేసేవారికి కూడా పనిచేస్తుంది. వారు printer‌లను enumerate చేసి, suspicious‌గా కనిపించకుండా management interfaces‌ను యాక్సెస్ చేయడానికి ప్రయత్నించగలరు.

అదనంగా, Apple కనెక్టెడ్ ecosystem‌ను ముందుకు నెట్టి కొనసాగిస్తున్న కొద్దీ, మరిన్ని devices corporate వాతావరణంలోకి చేరుతున్నాయి. దాంతో printing workflows ద్వారా మరింత data ప్రవహిస్తుంది, compromised printer‌లు sensitive documents‌ను విని పొందడానికి లేదా బయటకు తరలించడానికి మరిన్ని అవకాశాలు కలుగుతాయి. Printer ఇకపై కేవలం కాగితాన్ని కదిలించే hardware మాత్రమే కాదు; అది office మీద పూర్తి దృష్టి ఉన్న ఒక network endpoint.

అత్యల్ప భద్రత కలిగిన పరికరాన్ని బలపరచడం

సంతోషకరమైన విషయం ఏమిటంటే, ఉత్పాదకతను కోల్పోకుండా ఎక్కువ risk‌ను తొలగించగల సూటి చర్యలు ఉన్నాయి.

  • Printer‌లను isolated VLAN‌లో లేదా కఠినమైన firewall rulesతో ప్రత్యేక print network‌లో ఉంచండి. Authorized devices నుండి print jobs మరియు admin subnet నుండి management traffic వంటి నిర్దిష్ట, అవసరమైన communications‌ను మాత్రమే అనుమతించండి.
  • Firmware update schedule‌ను రూపొందించండి. Operating systems‌లా, printer patches‌ను తనిఖీ చేసి deploy చేయడానికి quarterly లేదా monthly reminder‌ను ఏర్పాటు చేయండి. దీనిని standard lifecycle management process‌లో భాగంగా చేయండి.
  • FTP, Telnet, అవసరం లేని HTTP, మరియు network printer‌లు IPPS వంటి మరింత భద్రమైన protocols‌ను ఉపయోగించగలిగితే raw port 9100 సహా అన్ని unused services‌ను disable చేయండి. అలాగే SNMP మరియు community strings‌ను read-only‌గా పరిమితం చేయండి.
  • అన్ని printing devices‌లో default passwords‌ను మార్చి, బలమైన administrative credentials‌ను తప్పనిసరి చేయండి. వాటిని నిర్వహించడానికి central vaults లేదా directory services‌ను ఉపయోగించండి.
  • Logging‌ను enable చేసి, printer‌లను మీ security information and event management (SIEM) tool‌తో integrate చేయండి. అసాధారణ burst printing, business hours‌కు బయట admin logins, మరియు outbound scan behavior‌ను గమనించండి.
  • ప్రతి సంవత్సరం printer security assessment చేయండి. ఇందులో manufacturer security advisories‌ను సమీక్షించడం, model EOL status‌ను అంచనా వేయడం, మరియు device config‌ను baseline‌తో పోల్చి చూడడం ఉండాలి. Printer‌లను మార్చేటప్పుడు, నిర్ధారించదగిన update commitments మరియు secure boot capabilities ఉన్నవాటినే కోరండి.

Configuration మార్పులకు మించి, enterprises printer‌ల physical security గురించి కూడా ఆలోచించాలి. అనేక devices‌లో print job images‌ను నిల్వ చేసే removable hard drives ఉంటాయి, కాబట్టి decommissioning విధానాల్లో secure disk wiping తప్పనిసరిగా ఉండాలి. పంచుకునే లేదా బహిరంగ ప్రదేశాల్లో, badge release లేదా PIN వంటి device authentication ద్వారా printing అవసరం కావాలి, తద్వారా sensitive documents tray‌లో వదిలిపెట్టబడకుండా ఉంటుంది.

బాక్స్‌ను దాటి: సంస్కృతి మరియు విధానం

Printer‌లను భద్రపరచడం పూర్తిగా technical సమస్య కాదు. అవి ఇంకా భద్రముగా లేకపోవడానికి కారణం చాలా సార్లు సాంస్కృతికమే. అనేక సంస్థల్లో printer‌లను security teams కాకుండా facilities లేదా office managers నిర్వహిస్తారు. దాంతో అవి asset list మరియు security roadmap‌లో కనిపించవు. దాన్ని సరిచేయడానికి, printer securityకి స్పష్టమైన ownership‌ను IT operations team‌కు అప్పగించి, చర్య తీసుకోవడానికి వారికి budget మరియు mandate ఉన్నట్లు నిర్ధారించండి.

Printable dataను కూడా మళ్లీ ఆలోచించడం అవసరం. Print jobs‌లో తరచుగా personally identifiable information, financial records, లేదా proprietary documents ఉంటాయి. చాలా modern printer‌లు images‌ను disks‌లో నిల్వ చేస్తాయి, ఇవి decommissioning తర్వాత కూడా access చేయవచ్చు. Device decommissioning, disk wiping, మరియు secure pull printing‌పై బలమైన policies risk‌ను గణనీయంగా తగ్గిస్తాయి.

Education కూడా అంతే ముఖ్యమైనది. Users‌కు security measures‌ను దాటవేయడం లేదా ఇతర vectors‌ను తెరచే third-party drivers‌ను install చేయడం సాధ్యం కాకూడదు. Apple-కేంద్రిత వాతావరణంలో, administrators profiles‌ను ఉపయోగించి AirPrint device discovery‌ను పరిమితం చేయవచ్చు మరియు printers‌తో కమ్యూనికేట్ చేసే Apple devices‌కు encryption‌ను enforce చేయవచ్చు. అయితే, ఆ settings Apple వైపునే రక్షిస్తాయి; printer itself harden చేసి patch చేయకపోతే అది ఇంకా బలహీనంగానే ఉంటుంది.

ముందుకు వెళ్లే దారి: సంపూర్ణ రక్షణ నిర్మాణం

ఈ విశ్లేషణ సూచిస్తున్నట్లుగా, చాలా సంస్థల్లో printer‌లు అత్యల్ప భద్రత కలిగిన పరికరంగా ఉండటానికి కారణం అవి సహజంగా చెడ్డవి కావడం కాదు, వాటిని పట్టించుకోకపోవడమే. శ్రద్ధ పురోగతిని తీసుకువస్తుంది. ముఖ్యంగా Apple administrators కోసం, roadmap స్పష్టంగా ఉంది: printer‌లను enterprise security posture‌లోకి తీసుకురావాలి, secure defaults‌ను కోరాలి, మరియు Macs మరియు iPhones‌కు వర్తించే అదే కఠినతతో governance‌ను అమలు చేయాలి. అది జరిగాక, printer ఇకపై బలమైన defenses మధ్య ఉన్న బలహీన స్థానం కాదు.

దాడి చేసేవారు నిరంతరం బలహీన స్థానాలను వెతుకుతున్న కాలంలో, ఒక whole class of devices‌ను unmanaged‌గా మరియు unpatchable‌గా వదిలేయడం కేవలం oversight కాదు — అది ఒక ఆహ్వానం. తదుపరి సారి office printer పక్కన వెళ్లినప్పుడు, ఒకసారి మరోలా చూడండి. అది మీ వద్ద ఉన్న అత్యంత ప్రమాదకరమైన పరికరం కావచ్చు.

ఈ వ్యాసం 9to5Mac నివేదిక ఆధారంగా ఉంది. మూల వ్యాసాన్ని చదవండి.

Originally published on 9to5mac.com