• Contact
  • Home
Saturday, June 28, 2025
  • Login
No Result
View All Result
The Public
  • Home
  • Pakistan
  • World
  • Business
  • Sports
  • Entertainment
    Virtual anchors and hosts on the rise

    Virtual anchors and hosts on the rise

    Yango Continues to Create a Ripple Effect of Entrepreneurship in Pakistan

    Anant Ambani’s Pre-Wedding Ceremony, Hair Found in Famous Personality’s Food

    Anant Ambani’s Pre-Wedding Ceremony, Hair Found in Famous Personality’s Food

    Shweta Tiwari’s Earnings from the Famous Indian Drama ‘Kasautii Zindagii Kay’

    Shweta Tiwari’s Earnings from the Famous Indian Drama ‘Kasautii Zindagii Kay’

    New Discovery Regarding Migraines

    New Discovery Regarding Migraines

    Muzaffarabad: Passenger Jeep Falls into Neelum River, 13 Dead

    Muzaffarabad: Passenger Jeep Falls into Neelum River, 13 Dead

    “My Film Earnings Are Exhausted, Now I’m Working to Run My Household,” Vivek Oberoi

    “My Film Earnings Are Exhausted, Now I’m Working to Run My Household,” Vivek Oberoi

    Salman Khan Sent a Marriage Proposal to Which Bollywood Actress?

    Salman Khan Sent a Marriage Proposal to Which Bollywood Actress?

    Behroze Sabzwari Went Three or Four Times with Javed Sheikh to Find a Match for His Wife

    Behroze Sabzwari Went Three or Four Times with Javed Sheikh to Find a Match for His Wife

  • Technology
    This innovation team in China’s Qingdao sets 12 world records in automated port operations

    This innovation team in China’s Qingdao sets 12 world records in automated port operations

    Yango Ride Debuts Karachi’s first Electric Vehicle fleet in partnership with Captains Fleet and Volt

    Yango Ride Debuts Karachi’s first Electric Vehicle fleet in partnership with Captains Fleet and Volt

    China promotes ‘technological inclusiveness’ to advance global green transition

    China promotes ‘technological inclusiveness’ to advance global green transition

    AI technology boosts efficiency of government services in China

    AI technology boosts efficiency of government services in China

    China’s AI Ascent: User Momentum Fuels Innovation

    China’s AI Ascent: User Momentum Fuels Innovation

    China’s new chapter in global innovation

    China’s new chapter in global innovation

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Health
  • Editorial
    • Opinion
  • Web Sites
    • The Public Purview
    • The Green Post
  • Home
  • Pakistan
  • World
  • Business
  • Sports
  • Entertainment
    Virtual anchors and hosts on the rise

    Virtual anchors and hosts on the rise

    Yango Continues to Create a Ripple Effect of Entrepreneurship in Pakistan

    Anant Ambani’s Pre-Wedding Ceremony, Hair Found in Famous Personality’s Food

    Anant Ambani’s Pre-Wedding Ceremony, Hair Found in Famous Personality’s Food

    Shweta Tiwari’s Earnings from the Famous Indian Drama ‘Kasautii Zindagii Kay’

    Shweta Tiwari’s Earnings from the Famous Indian Drama ‘Kasautii Zindagii Kay’

    New Discovery Regarding Migraines

    New Discovery Regarding Migraines

    Muzaffarabad: Passenger Jeep Falls into Neelum River, 13 Dead

    Muzaffarabad: Passenger Jeep Falls into Neelum River, 13 Dead

    “My Film Earnings Are Exhausted, Now I’m Working to Run My Household,” Vivek Oberoi

    “My Film Earnings Are Exhausted, Now I’m Working to Run My Household,” Vivek Oberoi

    Salman Khan Sent a Marriage Proposal to Which Bollywood Actress?

    Salman Khan Sent a Marriage Proposal to Which Bollywood Actress?

    Behroze Sabzwari Went Three or Four Times with Javed Sheikh to Find a Match for His Wife

    Behroze Sabzwari Went Three or Four Times with Javed Sheikh to Find a Match for His Wife

  • Technology
    This innovation team in China’s Qingdao sets 12 world records in automated port operations

    This innovation team in China’s Qingdao sets 12 world records in automated port operations

    Yango Ride Debuts Karachi’s first Electric Vehicle fleet in partnership with Captains Fleet and Volt

    Yango Ride Debuts Karachi’s first Electric Vehicle fleet in partnership with Captains Fleet and Volt

    China promotes ‘technological inclusiveness’ to advance global green transition

    China promotes ‘technological inclusiveness’ to advance global green transition

    AI technology boosts efficiency of government services in China

    AI technology boosts efficiency of government services in China

    China’s AI Ascent: User Momentum Fuels Innovation

    China’s AI Ascent: User Momentum Fuels Innovation

    China’s new chapter in global innovation

    China’s new chapter in global innovation

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Health
  • Editorial
    • Opinion
  • Web Sites
    • The Public Purview
    • The Green Post
No Result
View All Result
The Public
No Result
View All Result
Home Tech

Chinese biometric access systems can be hacked, users data at risk: Kaspersky

by News Desk
June 13, 2024
in Tech
0
Kaspersky finds vulnerabilities in Chinese biometric access systems
0
SHARES
3
VIEWS
Share on FacebookShare on Twitter

Islamabad : Kaspersky has identified numerous flaws in the hybrid biometric terminal produced by International Chinese manufacturer ZKTeco. By adding random user data to the database or using a fake QR code, a nefarious actor can easily bypass the verification process and gain unauthorized access. Attackers can also steal and leak biometric data, remotely manipulate devices, and deploy backdoors. High-security facilities worldwide are at risk if they use this vulnerable device.

The flaws were discovered in the course of Kaspersky Security Assessment experts’ research into the software and hardware of ZKTeco’s white-label devices. All findings were proactively shared with the manufacturer prior to public disclosure.

The biometric readers in question are widely used in areas across diverse sectors – from nuclear or chemical plants to offices and hospitals. These devices support face recognition and QR-code authentication, along with the capacity to store thousands of facial templates. However, the newly discovered vulnerabilities expose them to various attacks.
Attackers can inject specific data into the QR code used for accessing restricted areas. Consequently, they can gain unauthorized access to the terminal and physically access the restricted areas. When the terminal processes a request containing this type of malicious QR code, the database mistakenly identifies it as originating from the most recently authorized legitimate user.

“In addition to replacing the QR code, there is another intriguing physical attack vector. If someone with malicious intent gains access to the device’s database, they can exploit other vulnerabilities to download a legitimate user’s photo, print it, and use it to deceive the device’s camera to gain access to a secured area. This method, of course, has certain limitations. It requires a printed photo, and warmth detection must be turned off. However, it still poses a significant potential threat,” says Georgy Kiguradze, Senior Application Security Specialist at Kaspersky.

Exploiting these vulnerabilities grants a potential attacker access to any file on the system and enables them to extract it. This includes sensitive biometric user data and password hashes to further compromise the corporate credentials. Threat actors can not only access and steal but also remotely alter the database of a biometric reader. “The impact of the discovered vulnerabilities is alarmingly diverse.Attackers can sell stolen biometric data on the dark web, subjecting affected individuals to increased risks of deepfake and sophisticated social engineering attacks. Furthermore, the ability to alter the database weaponizes the original purpose of the access control devices, potentially granting access to restricted areas for nefarious actors, Georgy Kiguradze further elaborated, .

To thwart related cyberattacks, Kaspersky advises Isolating biometric reader usage into a separate network segment and employ robust administrator passwords, changing default ones. Consider enabling or adding temperature detection to avoid authorization using a random photo and minimize the use of QR-code functionality, if feasible and update firmware regularly.

Tags: ASIF ZARDARIBILAWAL BHUTTOElection Commission of PakistanELECTIONS 20224GAZAISLAMABADISRAELKPKLAHORENAWAZ SHARIFPakistan Tehreek-e-InsafPALESTINEPMLNPPPPTIPUBLIC PURVIEWRAWALPINDI
News Desk

News Desk

Next Post
Budget 2024-25: Govt must start constructive dialogue with business community to remove its real concerns: ICCI President

Budget 2024-25: Govt must start constructive dialogue with business community to remove its real concerns: ICCI President

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

China

Popularity of Chinese-style products overseas mirrors new momentum of China’s foreign trade

11 months ago
Suggested headline: Pakistan Bleeds 300 Billion Annually from Illicit Cigarette Trade

Pakistan Bleeds 300 Billion Annually from Illicit Cigarette Trade

1 year ago

Popular News

    Connect with us

    Category

    • Blog
    • Business
    • Editorial
    • Entertainment
    • Health
    • Lifestyle
    • National
    • Opinion
    • Politics
    • Science
    • Sports
    • Tech
    • World

    Popular News

      About Us

      Sometimes, businesses are afraid that in-depth explanations of their products aren’t interesting enough or will sound unappealing in writing.

      • Contact
      • Home

      The Public © 2023. All Rights Reserved. Website Designed & Developed by AK Web Solutions

      No Result
      View All Result
      • Home
      • Politics
      • World
      • Business
      • Science
      • National
      • Entertainment
      • Sports
      • Lifestyle
      • Tech

      The Public © 2023. All Rights Reserved. Website Designed & Developed by AK Web Solutions

      Welcome Back!

      Login to your account below

      Forgotten Password?

      Create New Account!

      Fill the forms below to register

      All fields are required. Log In

      Retrieve your password

      Please enter your username or email address to reset your password.

      Log In