Penetration Analysis of a XEROX Docucenter DC 230ST: Assessing the Security of a Multi-purpose Office Machine
Thomas E. Daniels, Benjamin A. Kuperman, Eugene Howard Spafford · 1999
Recent advances in manufacturing technology have made possible multi-purpose office equipment that handle a large variety of tasks previously relegated to multiple individual machines. In this paper, we examined the Xerox Docucenter 230ST (DC 230ST) which supports copying, faxing (both sending and receiving), network printing, and web-based printing, among other features. Because of the shared comnunication medium, machines that physically host multiple services may pose a greater security risk than individual devices. In the case of the DC 230ST, a CPU and hard drive control the functions of the of the above features. We found that if an attacker can gain physical access to the machine, the programming of the machine can be compromised. A sophisticated attacker can subvert the machine without resorting to opening the physical casing. We were unable to compromise the machine remotely, although we did not exhaust the possibility of such a compromise. The results of our attempts along with recommendations regarding the possible deployment of a DC 230ST are contained within this document. Portions of this work were supported by the sponsors of CERIAS.