Coffee drinkers in peril after espresso overspill attack

A geeky risk advisory manager from global accountancy firm BDO has hacked into a leading coffee machine, causing it to pour scalding water onto unsuspecting espresso lovers

An Australian man has exploited security vulnerabilities in a leading coffee machine which could lead to an overflow of scalding water being poured into unexpecting users' coffee cups.

Craig Wright, a risk advisory services manager with accountancy giant BDO, said he could use an internet connection to meddle with the coffee machine to cause it to release too much hot water or too much coffee powder.

Writing on security mailing list BugTraq, he said he could also break the machine by tweaking its settings.

The attack is possible because two models of the machine, the Jura Impressa F90 and Jura Impressa F9, have internet connectivity.

Switzerland-based Jura manufactures glorified coffee makers that retail for over £1000.

Jura introduced internet connectivity to the machines so they can be mended remotely by engineers. It's believed to be the first espresso maker with that capability.

Wright said he thought the flaw could not be patched.

"Best yet, the software allows a remote attacker to gain access to the Windows XP system it is running on, at the level of the user," he said.

Wright added that he has now installed his machine behind a firewall.

Jura could offer no comment at the time of writing.


See original article on scmagazineus.com
Copyright © SC Magazine, US edition
Related

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read