Skip to main content
  1. Home
  2. Emerging Tech
  3. Mobile
  4. News

This smartphone-equipped drone breaks into Wi-Fi networks through unsecure printers

Add as a preferred source on Google

If you weren’t already paranoid about the security of your wireless network, listen to this. A team of security researchers from Singapore has reportedly devised a method of intercepting wireless printer transmissions using smartphones attached to drones. In other words, they can gain access to your network by using a smartphone-equipped drone to hack your printer. The technology was developed by researchers from iTrust, a cybersecurity research center at the Singapore University of Technology and Design.

The iTrust system was designed as an inexpensive way for companies to test the security of their Wi-Fi networks, but as the researchers demonstrated, it can also be used for nefarious purposes. It uses drones to transport a smartphone to an area where a wireless network with wireless printers is located. Unlike notebook-based detection systems that require building access, drones can fly outside a fly outside a skyscraper and find vulnerable networks with minimal interference. The system targets wireless printers because they often The weak link in a company’s wireless network. Wireless printers are typically supplied with the Wi-Fi connection open by default, and many companies forget to close this hole when they add the device to their Wi-Fi networks. This open connection potentially provides an access point for outsiders to connect to a network and steal a company’s sensitive data.
drone-stealing-printer
The system designed by iTrust uses a consumer DJI drone and a Samsung smartphone loaded with apps designed by the researchers to test a company’s wireless network. One app, Cybersecurity Patrol, scans for open Wi-Fi printers and alerts a user if a vulnerable device is found. The second app also scans for open Wi-Fi devices but goes a step further by trying to hack into the network. It attempts to access the network by creating a fake access point that mimics the wireless printer. If successful, the smartphone-based fake printer can intercept documents sent to the office printer within seconds and reroute them to a Dropbox account using the phone’s cellular connection.

Recommended Videos

Hacking the network and stealing the printer documents is not a trivial undertaking and requires the researchers to root the Samsung phone and install Debian Linux on the handset. They then use python to write an app to emulate an HP6830 wireless printer after they reverse engineered the software from the actual printer. They also need to be within a 26-meter radius of the network, making it likely a drone would be spotted hovering outside an office building.

Though it may be challenging to use as an attack vector, the drone system is effective for scanning and detecting open networks. Users only need to install the Cybersecurity Patrol app on a phone and send it upwards via a drone. It also can be attached to a robotic vacuum cleaner, which will scan for vulnerable networks while it cleans a company’s floors.

Kelly Hodgkins
Kelly's been writing online for ten years, working at Gizmodo, TUAW, and BGR among others. Living near the White Mountains of…
Chinese startup claims its brain implant takes just 10 minutes to place, no skull surgery required
StairMed Technology's vein-based BCI could beat Neuralink's roughly two-hour surgery on speed, but the device still hasn't undergone human trials.
Art, Plate, Crystal

Brain implants, like the ones made by Elon Musk's Neuralink, typically involve open-skull surgery. But a Chinese startup says it can skip that step entirely, threading its device into the brain through a vein in a procedure that reportedly takes as little as ten minutes. According to the South China Morning Post, Shanghai-based StairMed Technology is one of several companies pursuing this approach, as the country pushes to expand its homegrown brain-computer interface (BCI) industry.

Faster than Neuralink, on paper

Read more
This bizarre email flaw is leaking corporate secrets to anyone who buys the right domain
Security researchers discovered companies are accidentally sending sensitive emails to domains that outsiders can register.
Maill app icon notifications

You don't always need to hack into a company's systems to get its secrets. Sometimes, the company will simply email them to you. A new report by WIRED's Matt Burgess has uncovered a bizarre email security problem in which companies are inadvertently sending sensitive information to domains that can be registered and controlled by outsiders. Security researchers Cory Solovevich and Mike Sheward discovered that seemingly harmless addresses such as noreply and deleteduser can become unexpected gateways to corporate information when the domains behind them aren't properly controlled.

The "hack" is buying the right domain

Read more
I found 3 ChatGPT features that turned out to be way more useful than I expected
ChatGPT on iPhone

I use ChatGPT pretty much every day, but somewhere along the way, I’ve also developed a habit of poking around and looking for features I haven’t tried yet. Some discoveries are genuinely useful, while others are the kind I’ll probably remember once every six months.

Every once in a while, though, I stumble across something that actually changes how I use ChatGPT. That happened recently with three features I’d somehow been overlooking. I’ve started using all three regularly now, and if you spend a lot of time in ChatGPT too, I think you’re missing out by not giving them a shot.

Read more