Burn baby burn, plastic inferno! Infosec researchers turn 3D printers into self-immolating suicide machines

Inflammatory findings from deadly serious investigation

Some 3D printers can be flashed with firmware updates downloaded directly from the internet – and an infosec research firm says it has discovered a way to spoof those updates and potentially make the printer catch fire.

Research from the appropriately named Coalfire biz claimed printers from Chinese company Flashforge could be abused through crafted updates that bypass safety features built into the devices' firmware.

The latest breakthrough – causing a printer to start smoking and hanging out with the bad kids – comes a few months after Coalfire first started poking about with the devices' update processes.

Coalfire used NSA tool Ghidra to help it crack the printer and its firmware, though its technique for deploying modified firmware requires the malicious person to be connected to the same network as the target device. Less scary, perhaps, than randomly discovering one day that your 3D printer has become a pyromaniac.

"We wanted to do a project showing the real life physical dangers inherent in attaching all these home appliances to the internet," Coalfire senior researcher Dan McInerney told The Register. "It's fascinating to me that strokes on a keyboard can literally kill people in this day and age. As a side bonus, I can now threaten to flambé my 3D printer-owning friends."

As McInerney pointed out in a series of detailed blog posts (and incendiary video) for Coalfire, some models of Flashforge 3D printer allow downloading and installation of firmware updates over the internet. "The Flashforge Finder comes with port 8899 open with no authentication, which appears to be relatively common among IoT 3D printers," McInerney wrote. "This port takes G-Code commands for performing actions such as increasing the temperature, extruding plastic, and moving the heated extruder tip around."

Having man-in-the-middle'd a sample printer through ARP (Address Resolution Protocol) spoofing and obtained the firmware by tapping "update" on the device's own touchscreen, Coalfire set about rooting the device, eventually uncovering a password of "sz1234567" after following tips from a Reddit post.

Once the printer and its firmware were within Coalfire's control, researchers set about fiddling with variables to see whether they could achieve their goal: raising the temperature of the 3D printer head, which relies on melting plastic feedstock to form the printed item, to dangerously high levels.

While there was code preventing the printer head from exceeding 261°C (501.8°F), Coalfire claimed it was able to bypass it through close analysis of the firmware with Ghidra that helped them identify the key variable controlling the thermal cutoff temperature.

Most worryingly, the tampered firmware could be flashed to a new printer that would start overheating the printer head as soon as the device was powered on, Coalfire claimed.

"In the case of the FlashForge Finder II the temperature readings in the UI start going haywire with the modified firmware but this could easily be fixed with some more firmware tinkering," explained McInerney.

"The way it works in our modifications is you just turn the printer on and it immediately starts heating up without any way of cooling down unless you turn it off; you don't actually have to give the printer any instructions to heat up. You can still tell it to print things and it'll function normally besides the UI screen giving nonsense readings of the current temperature which makes it a little insidious."

Flashforge has been asked for comment.

McInerney suggested that manufacturers should look at signing their firmware.

A couple of years ago scientific researchers published a paper calling for more research into the effect of 3D printers on indoor air quality, saying that some devices increased dust and chemical emission levels to a point that caused them concern. Happier, more innocent days. ®

Other stories you might like

  • Israel plans ‘Cyber-Dome’ to defeat digital attacks from Iran and others
    Already has 'Iron Dome' – does it need another hero?

    The new head of Israel's National Cyber Directorate (INCD) has announced the nation intends to build a "Cyber-Dome" – a national defense system to fend off digital attacks.

    Gaby Portnoy, director general of INCD, revealed plans for Cyber-Dome on Tuesday, delivering his first public speech since his appointment to the role in February. Portnoy is a 31-year veteran of the Israeli Defense Forces, which he exited as a brigadier general after also serving as head of operations for the Intelligence Corps, and leading visual intelligence team Unit 9900.

    "The Cyber-Dome will elevate national cyber security by implementing new mechanisms in the national cyber perimeter, reducing the harm from cyber attacks at scale," Portnoy told a conference in Tel Aviv. "The Cyber-Dome will also provide tools and services to elevate the protection of the national assets as a whole. The Dome is a new big data, AI, overall approach to proactive defense. It will synchronize nation-level real-time detection, analysis, and mitigation of threats."

    Continue reading
  • Intel to sell Massachusetts R&D site, once home to its only New England fab
    End of another era as former DEC facility faces demolition

    As Intel gets ready to build fabs in Arizona and Ohio, the x86 giant is planning to offload a 149-acre historic research and development site in Massachusetts that was once home to the company's only chip manufacturing plant in New England.

    An Intel spokesperson confirmed on Wednesday to The Register it plans to sell the property. The company expects to transfer the site to a new owner, a real-estate developer, next summer, whereupon it'll be torn down completely.

    The site is located at 75 Reed Rd in Hudson, Massachusetts, between Boston and Worcester. It has been home to more than 800 R&D employees, according to Intel. The spokesperson told us the US giant will move its Hudson employees to a facility it's leasing in Harvard, Massachusetts, about 13 miles away.

    Continue reading
  • Start using Modern Auth now for Exchange Online
    Before Microsoft shutters basic logins in a few months

    The US government is pushing federal agencies and private corporations to adopt the Modern Authentication method in Exchange Online before Microsoft starts shutting down Basic Authentication from the first day of October.

    In an advisory [PDF] this week, Uncle Sam's Cybersecurity and Infrastructure Security Agency (CISA) noted that while federal executive civilian branch (FCEB) agencies – which includes such organizations as the Federal Communications Commission, Federal Trade Commission, and such departments as Homeland Security, Justice, Treasury, and State – are required to make the change, all organizations should make the switch from Basic Authentication.

    "Federal agencies should determine their use of Basic Auth and migrate users and applications to Modern Auth," CISA wrote. "After completing the migration to Modern Auth, agencies should block Basic Auth."

    Continue reading
  • City-killing asteroid won't hit Earth in 2052 after all
    ESA ruins our day with some bad news

    An asteroid predicted to hit Earth in 2052 has, for now, been removed from the European Space Agency's list of rocks to be worried about.

    Asteroid 2021 QM1 was described by ESA as "the riskiest asteroid known to humankind," at least among asteroids discovered in the past year. QM1 was spotted in August 2021 by Arizona-based Mount Lemmon observatory, and additional observations only made its path appear more threatening.

    "We could see its future paths around the Sun, and in 2052 it could come dangerously close to Earth. The more the asteroid was observed, the greater that risk became," said ESA Head of Planetary Defense Richard Moissl. 

    Continue reading
  • Why Wi-Fi 6 and 6E will connect factories of the future
    Tech body pushes reliability, cost savings of next-gen wireless comms for IIoT – not a typo

    Wi-Fi 6 and 6E are being promoted as technologies for enabling industrial automation and the Industrial Internet of Things (IIoT) thanks to features that provide more reliable communications and reduced costs compared with wired network alternatives, at least according to the Wireless Broadband Alliance (WBA).

    The WBA’s Wi-Fi 6/6E for IIoT working group, led by Cisco, Deutsche Telekom, and Intel, has pulled together ideas on the future of networked devices in factories and written it all up in a “Wi-Fi 6/6E for Industrial IoT: Enabling Wi-Fi Determinism in an IoT World” manifesto.

    The detailed whitepaper makes the case that wireless communications has become the preferred way to network sensors as part of IIoT deployments because it's faster and cheaper than fiber or copper infrastructure. The alliance is a collection of technology companies and service providers that work together on developing standards, coming up with certifications and guidelines, advocating for stuff that they want, and so on.

    Continue reading
  • How can we make the VC world less pale and male, Congress wonders
    'Combating tech bro culture' on the agenda this week for US House committee

    A US congressional hearing on "combating tech bro culture" in the venture capital world is will take place this week, with some of the biggest names in startup funding under the spotlight.

    The House Financial Services Committee's Task Force on Financial Technology is scheduled to meet on Thursday. FSC majority staff said in a memo [PDF] the hearing will focus on how VCs have failed to invest in, say, fintech companies founded by women and people of color. 

    We're told Sallie Krawcheck, CEO and cofounder of Ellevest; Marceau Michel, founder of Black Founders Matter; Abbey Wemimo, cofounder and co-CEO of Esusu; and Maryam Haque, executive director of Venture Forward have at least been invited to speak at the meeting.

    Continue reading
  • DataStax launches streaming data platform with backward support for JMS
    Or move to Apache Pulsar for efficiency gains, says NoSQL vendor

    DataStax, the database company built around open-source wide-column Apache Cassandra, has launched a streaming platform as a service with backwards compatibility for messaging standards JMS, MQ, and Kafka.

    The fully managed messaging and event streaming service, based on open-source Apache Pulsar, is a streaming technology built for the requirements of high-scale, real-time applications.

    But DataStax wanted to help customers get data from their existing messaging platforms, as well as those who migrate to Pulsar, said Chris Latimer, vice president of product management.

    Continue reading

Biting the hand that feeds IT © 1998–2022