Ricoh Aficio SP C821DNT1 Design Guide - Page 70

WebDocBox MFP models only

Page 70 highlights

Print Controller Design Guide for Information Security Protection Against URL Buffer Overflows URL buffer overflow attacks occur when intentionally oversized URL strings are sent to a Web server with the intent of overflowing the buffer's storage capacity, causing the server to shut down. WebImageMonitor prevents such trouble by limiting the length of the URL strings it will accept, rejecting any requests that exceed this limit. In addition, authentication is performed before any settings can be changed, ensuring that malicious data cannot be introduced via illegal access. Protection Against Session Hijacks A "session hijack" refers to when the session ID stored in a cookie is obtained in order to illegally access or otherwise use a session for malicious purposes. WebImageMonitor employs the following countermeasures to minimize the threat of session hijacks: The session ID is randomized, which makes it very difficult for third parties to surmise Communication is protected by SSL, preventing theft of any data or messages exchanged The above-mentioned countermeasures for cross-site scripting prevent cookies from being illegally accessed Cookies created by WebImageMonitor do not contain any personal information. In addition, the session ID is given an expiration date, minimizing any potential threat to the MFP/LP in the unlikely event the session ID were somehow stolen: Protection Against the Setting of Illegal URLs The optional URL setting in WebImageMonitor can only be changed by users authenticated as Network Administrators. Concealment of Personal Data Even when User Authentication is disabled, it is possible to conceal the job history and other personal data from the view by changing the Service mode settings in the WebImageMonitor GUI. In such cases, the data can only be viewed by Administrators. 2-6-2 WebDocBox (MFP models only) Overview of WebDocBox Operations WebDocBox allows users to issue commands via a Web browser to view, capture, print, send (e-mail, FAX, forward) and delete Document Sever image files that were saved to the MFP HDD using the Copier, Printer, Scanner and FAX functions, as well as those that were restored to the MFP using Desk Top Editor For Production. It is also possible to view thumbnails of these images. Page 70 of 86

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86

Print Controller Design Guide for Information Security
Page 70 of 86
Protection Against URL Buffer Overflows
°
URL buffer overflow attacks occur when intentionally oversized URL strings are sent to a Web server
with the intent of overflowing the buffer’s storage capacity, causing the server to shut down.
WebImageMonitor prevents such trouble by limiting the length of the URL strings it will accept,
rejecting any requests that exceed this limit.
°
In addition, authentication is performed before any settings can be changed, ensuring that malicious
data cannot be introduced via illegal access.
Protection Against Session Hijacks
°
A “session hijack” refers to when the session ID stored in a cookie is obtained in order to illegally
access or otherwise use a session for malicious purposes.
°
WebImageMonitor employs the following countermeasures to minimize the threat of session hijacks:
±
The session ID is randomized, which makes it very difficult for third parties to surmise
±
Communication is protected by SSL, preventing theft of any data or messages exchanged
±
The above-mentioned countermeasures for cross-site scripting prevent cookies from being
illegally accessed
±
Cookies created by WebImageMonitor do not contain any personal information.
°
In addition, the session ID is given an expiration date, minimizing any potential threat to the MFP/LP in
the unlikely event the session ID were somehow stolen:
Protection Against the Setting of Illegal URLs
°
The optional URL setting in WebImageMonitor can only be changed by users authenticated as
Network Administrators.
Concealment of Personal Data
Even when User Authentication is disabled, it is possible to conceal the job history and other personal data
from the view by changing the Service mode settings in the WebImageMonitor GUI. In such cases, the data
can only be viewed by Administrators.
2-6-2 WebDocBox (MFP models only)
Overview of WebDocBox Operations
°
WebDocBox allows users to issue commands via a Web browser to view, capture, print, send (e-mail,
FAX, forward) and delete Document Sever image files that were saved to the MFP HDD using the
Copier, Printer, Scanner and FAX functions, as well as those that were restored to the MFP using Desk
Top Editor For Production. It is also possible to view thumbnails of these images.