Table of Contents
Introduction
Movies have made us believe that hackers are dubious, introverted characters sitting in a dark room with a hoodie and have the state of the art technology to break into anywhere. Though this depiction is valid for 5% of the hackers, most hackers use straightforward techniques to break into systems!
The majority of the hacks result from user negligence rather than a fault of the technology or the company! It is far more common for a hacker to attack one of the below-mentioned office devices to penetrate the network.
A hacker, like any person, aims to find the easiest way to get his job done, and the following devices prove to be easiest to hack! This article explains how these devices are vulnerable and how to make them secure.
Security Cameras
Ironic. Security cameras are installed to catch a thief and can be a great tool to protect a home or a small business. Most security cameras are connected to the internet and allow users to access them remotely. However, the misconfiguration of these devices makes them highly vulnerable to hacking!
Most of the time, the security camera has the default admin and password enabled as the login credentials. Hackers know that people are sluggish in changing these settings and quickly gain access to these devices through the manufacturer’s default login credentials.
After logging in, they can spy on all business activities or plan a more sophisticated cyber-attack. However, sometimes the camera companies can also make mistakes, as shown by HikVision in 2017. Even if the company rolls out security updates, most people have never updated their camera’s firmware, making it easy for even a novice hacker to penetrate your system.
The best way to increase the security of your cameras is to change the default login credentials to a high entropy password, regularly update the camera’s firmware, and enabling multi-factor authentication on your cameras. These simple steps will make your cameras as strong as a computer with a robust anti-virus!
For people who wish to go a little further, statically assign an IP address for each camera and subnet mask, and leave the gateway blank. If you cannot leave it blank, then set it to an unused dedicated IP address, thereby preventing the camera from sending information off the company’s local network. For more information, read this Forbes article.
Printers, Scanners, Fax Machines
Your first reaction to this must be – Who would want to hack a printer? What might seem absurd to us is an excellent opportunity for a hacker. As was proven in 2018, a hacker named TheHackerGriaffe gained access to 50,000 printers to increase his favorite YouTube channel’s subscriptions!
By scanning for unprotected ports in the printers, hackers can control the printers to print documents and even read the document’s contents! All confidential information like financial, personal transactions, internal reports can be accessed by the hacker. Further, the printers can be used in a DoS and DDoS attack by making it a part of the botnet!
Luckily, you can protect your printer from external control by installing an effective and regularly tested firewall in your network. Like with every other device, ensure that the printer’s firmware is updated and that you change the default username and password.
For people who are willing to make technical changes, Kaspersky recommends that you close ports 9100, 515, and 721-731. It is a good practice to restrict your printer and network to communicate only through a specific port, as it prevents hackers from searching for vulnerable ports.
Router
A Wi-Fi router is a central node for your entire network. Hackers aim to control this device to change your network settings, access your internet data, and even install malware in your computers. Further, hacking a Wi-Fi router can enable hackers in a successful Man In the Middle Attack!
Like before, the hackers rely primarily on a user’s lack of security awareness to gain access to the router. If you have the default login credentials for the router, anyone can access the router settings. Failing to update the router’s firmware allows hackers to take advantage of an old vulnerability to do extensive damage to your network and business.
Lastly, a short and easy-to-guess password can be cracked within minutes by even a novice hacker. It is imperative that you use a long and complex password for your router. Also, ensure that the router is physically secure from unauthorized access and that you enable the guest network settings on your router for guests, customers, and vendor’s use.
More technical solutions include disabling remote access to your router and hiding your Wi-Fi Network. These simple measures will protect your hackers from 99% of the hacks.
Remember, all the network traffic, and consequently, information, travels through the router, and if hacked, it can lead to severe data theft! Further, suppose the hacker gains control of the router. In that case, he can trick you into submitting information over an HTTP page versus an HTTPS page and even install malware on the router to prepare for an advanced cyber attack. For more information, please read this article.
USB Media
While USBs are no longer common, they still pose a danger to your business’s security. USBs are pretty handy – they allow you to transfer files from one device to another and were extensively used before cloud technology became mainstream.
While they are not in as much use today, some people still use them as a force of habit. However, USBs are a significant security risk and must be handled with caution. As the manufacturers of USBs don’t protect the firmware, malware can potentially overwrite the USB firmware to take control of the device.
This malware can then falsely act as either a keyboard or network card to install malware or redirect network traffic. These infected devices can infect the computers more when they intervene in the boot stage before the anti-virus can take any action.
Fortunately, there are several solutions to help secure these devices. Write protectors that prevent any data from deletion and prevent malware from written on the device are an excellent preventive measure. ClamWin is an anti-virus for USB that you can use to help protect it from being infected by malware when transferring files. Further, use BitLocker on Windows to prevent unauthorized users from accessing the USB’s content by enforcing a password. Even if the device is stolen or lost, no one will be able to access the device!
If you are a fan of the Mission Impossible movies, you can now buy a USB drive that self-destructs after a set number of incorrect password attempts!
Smart Devices
Although there are no unhackable devices, smart devices make it too easy for hackers! Smart devices are relatively new to the market and do not have any government security standards or requirements. Resulting in ambiguity amongst the vendors in implementing security practices in their products.
Moreover, these devices are rarely, if ever, updated and patched for vulnerabilities. When the companies send updates, they are done insecurely, allowing hackers to upload their code to these smart devices and get complete control!
While user oversight like using default login credentials, weak passwords, and others are relevant here, the biggest issue is the lack of a security standard for smart devices, leading to overall poor security!
Nevertheless, things are improving in securing smart devices. Until we have a defined security standard and regulations requiring these companies to ensure security, we can still adopt reasonable security practices to minimize the hacking chances of our smart devices.
Ensure you only buy smart devices with a proven security track record, enable auto-update, and change the default login credentials with a unique and robust password. Further, using security products like McAfee Secure Home Platform can help you secure all these devices from a central location.
Conclusion
All the devices mentioned above are used extensively in a home and a business. Although most of them have high-security standards, the majority are victims of cyber-attacks due to user oversight and negligence. All of us must adopt the following practices to ensure the highest security for these devices and make it much more difficult for a hacker to access them.
As we have mentioned multiple times before, it is easy to avoid most cyber-attacks if users improve their cyber hygiene and adopt a cybersecurity mindset! Cybersecurity takes a little effort but has enormous returns in ensuring safety, organizational reputation, and business continuity.
