论文标题
多服务威胁:攻击和保护网络打印机和VoIP电话
Multi-service Threats: Attacking and Protecting Network Printers and VoIP Phones alike
论文作者
论文摘要
目前,通过网络打印并通过VoIP技术进行通话是常规的。本文研究了这些服务在现实世界中使用免费软件的攻击,如果不牢固地配置它们。在发现至少可以从内部人士那里安装高影响力的攻击,称为Printjack和Phonejack家族,文章还观察到,安全配置似乎并未被广泛采用。 具有必要技能的用户可能会与打印机一起采取现有的安全措施,但需要采取新颖的措施,该措施是用手机和手机进行的,以便一对同行可以安全地互相呼叫,而不信任其他任何人,包括Sysadmins。
Printing over a network and calling over VoIP technology are routine at present. This article investigates to what extent these services can be attacked using freeware in the real world if they are not configured securely. In finding out that attacks of high impact, termed the Printjack and Phonejack families, could be mounted at least from insiders, the article also observes that secure configurations do not appear to be widely adopted. Users with the necessary skills may put existing security measures in place with printers, but would need novel measures, which the article prototypes, with phones in order for a pair of peers to call each other securely and without trusting anyone else, including sysadmins.