ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Zscaler tool can find unprotected embedded web servers

By | March 5, 2012, 2:10pm PST

Summary: The web-based tool can scan IP ranges to find multi-function printers and photocopiers, VOIP devices and video-conferencing systems that are currently available over the internet.

Security firm Zscaler has released a tool capable of scanning networks to find embedded web servers that may be publicly accessible without any protections.

The web-based tool, called brEWS (Basic Request Embedded Web Server Scanner), can scan IP ranges to find things like multi-function printers and photocopiers, VOIP devices and video-conferencing systems that are currently available over the internet.

brEWS leverages a two phased approach to quickly identify exposed EWSs. The initial scan retrieves headers from identified web servers. Content obtained from the server headers is then used to query a back end database which returns appropriate tests to be run in order to attempt identification of potential EWSs.

follow Ryan Naraine on twitter

Malicious hackers are already using the Shodan computer search engine to find Internet-facing SCADA systems that use insecure mechanisms for authentication and authorization and Zscaler’s Michael Sutton warns that thousands of embedded systems are currently online without the necessary protections.

According to a report by The H Security, Sutton delivered a presentation at the RSA Conference on this issue:

The scan managed to examine the targeted one million web servers in a short time and came up with the following results: many thousands of multi-function devices (more than 3,000 devices by Canon, 1,200 Xerox photocopiers, 20,000 Ricoh devices, among others), 8,000 Cisco IOS devices and almost 10,000 VoIP systems and phones didn’t require any log-in authentication. The latter included 1,100 devices by the German manufacturer Snom. These devices include packet tapping features and PCAP tracing by default. Imported into Wireshark, the trace can be converted into a sound file of the telephone conversation.

The majority of the detected devices were not protected by passwords, Sutton said. This means that any web user can access their web interfaces through a browser and view the documents that are stored on such photocopiers and printers, forward incoming faxes to an external number, or record scan jobs. With HP devices, such intrusions can be carried out by a script that, every second, calls a URL whose only variable is UNIX epoch time, which can easily be guessed.

Sutton’s scan also discovered more than 9,000 video conferencing systems by Polycom and Tandberg (now Cisco).

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
1
Comments

Join the conversation!

0 Votes
+ -
Wow. That's impressive.
Dietrich T. Schmitz * Your Linux Advocate 5th Mar
I don't think I'd waste my time with this--just go straight to using nmap for pentesting.
Use zenmap gui if you'd rather avoid command line.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix