Skip to main content

Canon mulls security concerns after hacker gets Doom running on a Pixma printer

hacker gets doom running canon printer
Image used with permission by copyright holder
White hat security researcher Michael Jordon has managed to get id Software’s genre-defining first-person shooter Doom running on a wireless Canon Pixma printer.  The project, which took four months to get up and running, was undertaken to demonstrate a security vulnerability in the printer’s web interface that is exemplary of problems that could potentially plague the emerging “Internet of Things” (via BBC News).

The Canon Pixma uses a Web interface so that owners can check on its status remotely. Mr. Jordon found that the interface does not require a username or password, so anyone could check on the device’s status once they found it. This did not seem like a problem until he realized that it is also possible to update the device’s firmware through the remote Web interface. Although the firmware is encrypted, Mr. Jordon was able to crack it and thus convince the printer to accept his own, re-written firmware.

That’s when he got the idea to run Doom, which has become a de facto “Hello, World!” program for hackers to demonstrate mastery over a given device. Doom has been implemented on everything from ATMs to graphic calculators. “Running Doom, that’s real proof you control the thing,” Jordon told the BBC.

Related: The return of Doom will be teased in an upcoming beta

Although the printer’s 32-bit ARM processor and 10MB of memory was more than sufficient in terms of raw power, the lack of a conventional operating system meant that it took months of coding and experimentation so the game could deal with the printer’s idiosyncrasies. The color palette is off, but the game works sufficiently to prove Mr. Jordon’s point, and he has no plans to further optimize it.

In response to Mr. Jordon’s work, Canon has promised “to provide a fix as quickly as is feasible,” adding a username and password to all future Pixma printers and providing an update for all models launched from the second half of 2013 onward. A quick search on the Shodan search engine reveals that there are thousands of unsecured printers out there on the Web, though Mr. Jordon has found no evidence of anyone abusing the loophole.

For a more technically in-depth explanation of how Jordon hacked the printers’s encryption, check out his blog post over at the site of his employer, Context Information Security.

Will Fulton
Former Digital Trends Contributor
Will Fulton is a New York-based writer and theater-maker. In 2011 he co-founded mythic theater company AntiMatter Collective…
Volgarr the Viking 2 will take you back to your Ghosts ‘n Goblins days
A viking slashes a tree in Volgarr the Viking 2.

Developer Digital Eclipse is working on a surprising project: Volgarr the Viking 2. The 2D retro sequel will launch on August 6 for PlayStation 4, PS5, Xbox One, Xbox Series X/S, Nintendo Switch, and PC.

The news is an out of left field reveal. The first Volgarr the Viking game released in 2013 and was made as an ode to 1080s classics like Ghosts 'n Goblins. Despite being a small release, it sold over 1 million copies over the past decade. As revealed during today's Guerrilla Collective stream, the series is coming back with a new sequel by Digital Eclipse, the team behind this year's Llamasoft: The Jeff Minter Story.

Read more
3 Days of Play PS Plus games to try this weekend (June 7-9)
Key art for Streets of Rage 4.

June 2024 is shaping up to be a pretty great month for PlayStation players. Not only are we coming off an entertaining State of Play showcase, but a new Days of Play initiative surrounding all the video game showcases this month is bringing a lot of new PS Plus additions with it. Many of those games hit PS Plus this week, and three in particular stand out to us.

For owners of Sony's oft-neglected PlayStation VR2, the first game is one of its rare exclusives that take full advantage of the headset's eye-tracking by seeing how often players blink. The next is a new PS Plus Essential game that's a revival of Sega's classic beat-'em-up series for the modern gaming era. Finally, the last title is an atmospheric and eerie fishing game that should entice fans of Lovecraftian horror.
Before Your Eyes

Read more
3 first-party Xbox Game Pass games to try this weekend (June 7-9)
Gears 5 Kait Hero Close Up

Microsoft will hold an Xbox Games Showcase and Call of Duty: Black Ops 6 Direct. this Sunday. These shows will provide a much better idea of what to expect from Xbox over the course of the next year or two. That's really needed right now, as Microsoft has struggled to keep online discussions around Xbox positive as it went multiplatform with some games, laid off thousands of developers, and outright shut down the developers of Hi-Fi Rush and Redfall. Based on leaks and my personal expectations for the showcase, there are three games you can play on Xbox Game Pass this weekend to prepare for the event.

The first is the latest first-person shooter in a long-running series by id Software that might be getting a medieval-set spinoff. After that, we have the fifth entry in a sci-fi Xbox series that still looks fantastic on Xbox Series X/S even though it came out in 2019. Finally, you can prepare for Avowed with the latest RPG from Obsidian Entertainment, a satirical sci-fi game where player choice is critical.
Doom Eternal

Read more