• About Us
  • Contact Us
  • Privacy Policy
  • Term and Conditions
Tuesday, July 29, 2025
  • Login
No Result
View All Result
Green Post
  • Home
  • News
    • National
    • Sports
    • Business
  • Lifestyle
    • Travel and Tourism
    • Style and Fashion
    • Health and Fitness
    • Entertainment
      Farhan Akhtar’s Heartwarming Post on Daughter’s Birthday

      Farhan Akhtar’s Heartwarming Post on Daughter’s Birthday

      Hira Somroo expresses disappointment over not getting her desired role

      Actors Explaining Religion Yasra Rizvi Addresses Criticism

      “Actors Explaining Religion? Yasra Rizvi Addresses Criticism”

      Nia Sharma Admires Pakistani Actors

      Nia Sharma Admires Pakistani Actors, Calls Their Dramas Romantic and Captivating

      Hania Aamir Faces Severe Criticism Over Bold Photoshoot

      Hania Aamir Faces Severe Criticism Over Bold Photoshoot

      Obscene Question

      “Obscene Question” Controversy: Legal Pressure Mounts on Samay Raina and Ranveer Allahbadia

      What Gift Did the Hero of Mawra’s Film ‘Sanam Teri Kasam’

      What Gift Did the Hero of Mawra’s Film ‘Sanam Teri Kasam’ Give to the Actress on Her Wedding?

      Shocking Revelation Maryam Nafees’ Husband Turns Out

      Shocking Revelation: Maryam Nafees’ Husband Turns Out to Be Bushra Ansari’s Former Son-in-Law

      Sanam Teri Kasam 2 Announced Will Mawra Be Part of the Film

      Sanam Teri Kasam 2 Announced: Will Mawra Be Part of the Film?

  • Technology & Innovation
    Hackers Intensify Crypto Scams with 83% More Attacks detected in 2024: Kaspersky report

    Hackers Intensify Crypto Scams with 83% More Attacks detected in 2024: Kaspersky report

    89% of parents use gadgets to entertain and occupy their children

    89% of parents use gadgets to entertain and occupy their children

    Big News About the Launch of Apple's New Device!

    Big News About the Launch of Apple’s New Device!

    Planet Discovered Orbiting a Star Moving Faster Than Light

    Planet Discovered Orbiting a Star Moving Faster Than Light

    Apple Follows Google in Renaming Gulf of Mexico on Its Maps

    Apple Follows Google in Renaming Gulf of Mexico on Its Maps

    Method Discovered to Tackle Toxic 'Forever Chemicals'

    Method Discovered to Tackle Toxic ‘Forever Chemicals’

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Opinion & Blogs
  • Magazine
  • Today’s Newspaper
  • Our Principles
  • Home
  • News
    • National
    • Sports
    • Business
  • Lifestyle
    • Travel and Tourism
    • Style and Fashion
    • Health and Fitness
    • Entertainment
      Farhan Akhtar’s Heartwarming Post on Daughter’s Birthday

      Farhan Akhtar’s Heartwarming Post on Daughter’s Birthday

      Hira Somroo expresses disappointment over not getting her desired role

      Actors Explaining Religion Yasra Rizvi Addresses Criticism

      “Actors Explaining Religion? Yasra Rizvi Addresses Criticism”

      Nia Sharma Admires Pakistani Actors

      Nia Sharma Admires Pakistani Actors, Calls Their Dramas Romantic and Captivating

      Hania Aamir Faces Severe Criticism Over Bold Photoshoot

      Hania Aamir Faces Severe Criticism Over Bold Photoshoot

      Obscene Question

      “Obscene Question” Controversy: Legal Pressure Mounts on Samay Raina and Ranveer Allahbadia

      What Gift Did the Hero of Mawra’s Film ‘Sanam Teri Kasam’

      What Gift Did the Hero of Mawra’s Film ‘Sanam Teri Kasam’ Give to the Actress on Her Wedding?

      Shocking Revelation Maryam Nafees’ Husband Turns Out

      Shocking Revelation: Maryam Nafees’ Husband Turns Out to Be Bushra Ansari’s Former Son-in-Law

      Sanam Teri Kasam 2 Announced Will Mawra Be Part of the Film

      Sanam Teri Kasam 2 Announced: Will Mawra Be Part of the Film?

  • Technology & Innovation
    Hackers Intensify Crypto Scams with 83% More Attacks detected in 2024: Kaspersky report

    Hackers Intensify Crypto Scams with 83% More Attacks detected in 2024: Kaspersky report

    89% of parents use gadgets to entertain and occupy their children

    89% of parents use gadgets to entertain and occupy their children

    Big News About the Launch of Apple's New Device!

    Big News About the Launch of Apple’s New Device!

    Planet Discovered Orbiting a Star Moving Faster Than Light

    Planet Discovered Orbiting a Star Moving Faster Than Light

    Apple Follows Google in Renaming Gulf of Mexico on Its Maps

    Apple Follows Google in Renaming Gulf of Mexico on Its Maps

    Method Discovered to Tackle Toxic 'Forever Chemicals'

    Method Discovered to Tackle Toxic ‘Forever Chemicals’

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Opinion & Blogs
  • Magazine
  • Today’s Newspaper
  • Our Principles
No Result
View All Result
Green Post
No Result
View All Result
Home Technology and Innovation

Kaspersky finds vulnerabilities in Chinese biometric access systems

by Web Desk
June 13, 2024
in Technology and Innovation
0
Kaspersky finds vulnerabilities in Chinese biometric access systems
0
SHARES
33
VIEWS
Share on FacebookShare on Twitter

Islamabad : Kaspersky has identified numerous flaws in the hybrid biometric terminal produced by International Chinese manufacturer ZKTeco. By adding random user data to the database or using a fake QR code, a nefarious actor can easily bypass the verification process and gain unauthorized access. Attackers can also steal and leak biometric data, remotely manipulate devices, and deploy backdoors. High-security facilities worldwide are at risk if they use this vulnerable device.

The flaws were discovered in the course of Kaspersky Security Assessment experts’ research into the software and hardware of ZKTeco’s white-label devices. All findings were proactively shared with the manufacturer prior to public disclosure.

The biometric readers in question are widely used in areas across diverse sectors – from nuclear or chemical plants to offices and hospitals. These devices support face recognition and QR-code authentication, along with the capacity to store thousands of facial templates. However, the newly discovered vulnerabilities expose them to various attacks.
Attackers can inject specific data into the QR code used for accessing restricted areas. Consequently, they can gain unauthorized access to the terminal and physically access the restricted areas. When the terminal processes a request containing this type of malicious QR code, the database mistakenly identifies it as originating from the most recently authorized legitimate user.

“In addition to replacing the QR code, there is another intriguing physical attack vector. If someone with malicious intent gains access to the device’s database, they can exploit other vulnerabilities to download a legitimate user’s photo, print it, and use it to deceive the device’s camera to gain access to a secured area. This method, of course, has certain limitations. It requires a printed photo, and warmth detection must be turned off. However, it still poses a significant potential threat,” says Georgy Kiguradze, Senior Application Security Specialist at Kaspersky.

Exploiting these vulnerabilities grants a potential attacker access to any file on the system and enables them to extract it. This includes sensitive biometric user data and password hashes to further compromise the corporate credentials. Threat actors can not only access and steal but also remotely alter the database of a biometric reader. “The impact of the discovered vulnerabilities is alarmingly diverse.Attackers can sell stolen biometric data on the dark web, subjecting affected individuals to increased risks of deepfake and sophisticated social engineering attacks. Furthermore, the ability to alter the database weaponizes the original purpose of the access control devices, potentially granting access to restricted areas for nefarious actors, Georgy Kiguradze further elaborated, .

To thwart related cyberattacks, Kaspersky advises Isolating biometric reader usage into a separate network segment and employ robust administrator passwords, changing default ones. Consider enabling or adding temperature detection to avoid authorization using a random photo and minimize the use of QR-code functionality, if feasible and update firmware regularly.

Default Avatar

Web Desk

Next Post
Budget 2024-25: Govt must start constructive dialogue with business community to remove its real concerns: ICCI President

Budget 2024-25: Govt must start constructive dialogue with business community to remove its real concerns: ICCI President

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

shooting contest

Pakistan’s historic win at shooting contest with over dozen medals

11 months ago
Iffat Umar

Iffat Umar defends Khalil-ur-Rehman Qamar amid viral scandal

12 months ago

Popular News

    Connect with us

    Category

    • Amazing
    • Business
    • E-Paper
    • Entertainment
    • Health
    • Health and Fitness
    • Lifestyle
    • National
    • News
    • Opinion
    • Opinion & Blogs
    • Pakistan
    • Politics
    • Science
    • Sports
    • Style and Fashion
    • Technology and Innovation
    • Travel and Tourism
    • World

    Useful Links

    • About
    • Our Dream
    • Submission
    • Contact Us
    • Term and Conditions
    • Privacy Policy

    About Us

    Sometimes, businesses are afraid that in-depth explanations of their products aren’t interesting enough or will sound unappealing in writing.

    • Home
    • News
    • Lifestyle
    • Technology & Innovation
    • Opinion & Blogs
    • Magazine
    • Today’s Newspaper
    • Our Principles

    The Green Post © 2024. All Rights Reserved.

    No Result
    View All Result
    • Home
    • News
      • National
      • Sports
      • Business
    • Lifestyle
      • Travel and Tourism
      • Health and Fitness
      • Style and Fashion
      • Entertainment
    • Technology and Innovation
    • Opinion & Blogs
    • Our Dream
    • Contact Us
    • What We Are and What We Do?
    • Magazine
    • Our Principles
    • Privacy Policy
    • Term and Conditions
    • Submission
    • Copyright
    • Contact Us
    • Cookies
    • About Us

    The Green Post © 2024. All Rights Reserved.

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Create New Account!

    Fill the forms below to register

    All fields are required. Log In

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In