23 ms·
Google has indexed thousands of publicly accessible HP printers
- penguat 14y agoSo, next question is how much malware is hanging around for those printers? Are all / mostly / some / none compromised?
- jhdevos 14y agoShould we now all print documents to those printers with warnings saying that they are publicly accessible?
- codesuela 14y agoEither that or freak people out by printing messages from ghosts stuck in their printer.
- dspillett 14y agoI'm assuming that it is just the setup/status/diagnostics control panel so you'll not be able to print anything arbitrary (shame, it could be a fun game!). If you are of a mind to wind someone up you might be able to kick out a pile of test pages and reconfigure the thing so it is no use until someone does a factory reset. A similar but worse case was some years ago when a range of consumer router+firewall boxes had a fault which made them present their control interface on the WAN interface and had no password set by default. A large number of those somehow got into a search index (it may have also been Google, I can't rightly remember), and from there you can probably do more harm than you can from a printer.
- Permit 14y agoI've looked at two and both had the option to print a file that you uploaded. Of course I didn't actually try to print anything, but it looks like you probably could.
- pliu 14y agoI may or may not have just printed out some random messages for people to find. There is something strangely compelling about sending thoughts out into the ether with no chance of feedback. Fax pranks are before my time, but I totally get it. I hope I made somebody smile today.
- draxofavalon 14y agoI already tried and printed PDF file, it works.
- SoftwareMaven 14y agoAnd risk five years in prison for unauthorized access of a computer? I think not.
- pbhjpbhj 14y agoWhy do you think it is unauthorised? The other question, which would be fascinating to see raised in court I feel, is whether a printer is a "computer" within the terms of the law (CFAA, CMA(UK) or whatever). You'd probably be able to question the meaning of access too - for example if you find an IP on Google and simply send data to port 9100 that's not really access, accessing a computer is 2 ways. If the law judged spamming port 91 as "access" then sending faxes or texting someone would come under the such legal acts .. that can't be within the intent of the law surely. If other laws are used - "you sent them a message they didn't want" - then that's the end of [legal] unsolicited mail [yay!].
- mrj 14y agoWorse than printing somewhere remote, many of those are probably also scanners. If the original is left on the glass (I forget it all the time), an attacker could scan it remotely.
- ihsw 14y agoThat's a very bad idea, you should call your lawyer/a law firm to prepare for the impending deluge of threatening letters and lawsuits filed against you.
- mrj 14y agoI only pointed out that there is more danger for people with publicly available printers than just getting random junk printed. You are jumping to conclusions.
- pbhjpbhj 14y agoThese sorts of interfaces are often connected to fileshares, so there's probably a route in there for a cracker. Also it may be possible to upload firmware - either corrupted firmware that bricks the printer or firmware that sends copies of all printed docs to a file store.
- kenbellows 14y agoSome scanners (and printers, for that matter) store cached copies of recently scanned/printed items. Probably you could grab those if you knew what you were doing.
- VMG 14y agoSo is the secret service going to knock on my door if I click a link? I can't tell anymore.
- KMag 14y agoThe secret service is going to knock for some reason or another anyway, so stop living in fear and live your life.
- aw3c2 14y agoDirect link on Google.com: https://www.google.com/search?q=inurl%3Ahp%2Fdevice%2Fthis.LCDispatcher https://www.google.com/search?q=inurl%3Ahp%2Fdevice%2Fthis.L...
- joering2 14y agoIdea for startup. 1. write a script to scrap google links to HP admin panel 2. filter out the IPs that are from US (given you want to work on US market) 3. assemble the list of printer types and current toner levels. 4. write a script that will print to each of those printers a one single page, stating your company "Cheapo Suppliers Inc" was notified that "your printer is low on toner. Call xxxxxx to re-fill. Lowest prices quaranteed within one day delivery!". You can add link to your shop page that already redirects user to specific type of printer they have, some type of one-click order (based on which toners are low). 5. daily rinse repeat. 6. sell your business to HP (at least try to).
- rorrr 14y agoThat's probably illegal not only in the US.
- deleted 14y ago[deleted]
- fishbacon 14y agoBetter yet, print a QR code, they can just scan it with their iPhone.
- kenbellows 14y agoWhat a great way to distribute malware. Host it on a server somewhere, encode the URL in a QR code, and print just the code, blown up large, with no descriptors to printers everywhere. People will be so intrigued they'll just scan it. Aaaaaaaaand infected.
- _quasimodo 14y agotalking about hp printers and malware: http://www.youtube.com/watch?v=njVv7J2azY8 http://www.youtube.com/watch?v=njVv7J2azY8
- deleted 14y ago[deleted]
- bintery 14y agoThat's really nothing compared to searching for Canon ImageRunner admin pages (google lets you search for a URL by content/markers/text in the page info/name) - over on those imagerunner tech forums, people were able to bring up previous scans going back however far, and in minutes be looking at passports, medical records, college information, etc... Maybe more disturbing is that as these things are decommissioned they are just 'junked'. Meaning sent over seas as is to be 'disposed' - anything ever copied, scanned, or sent on that thing is in there somewhere and some foreign nation is in control of MFDs that were in hospitals, law firms, architect/contractor office, police stations, and on and on and on. The holes have been largely fixed through encryption and other techniques but only very recently - which I've been able to work around myself with forensic tools. I won't provide the link here, but if you google around you can find discussion on this topic pretty easily.
- glhaynes 14y agoanything ever copied, scanned, or sent on that thing is in there somewhere I wouldn't be terribly surprised to find out my MFD has more persisted and recoverable in it than my first guess of how much it has (nothing), but it certainly doesn't have every page that's ever gone in or out of it.
- cs702 14y agoI've written about this before.[1] Many network-connected printers simply assume that the local network they connect to will be securely protected from external threats, so they're not configured to withstand even the simplest of attacks. This is exactly the opposite of what many security experts recommend: devices should be secure regardless of whether the network they're on is secure or not. Bruce Schneier's personal WiFi network at home is fully open, because -- in his own words: "If I configure my computer to be secure regardless of the network it's on, then it simply doesn't matter. And if my computer isn't secure on a public network, securing my own network isn't going to reduce my risk very much."[2] I'm waiting for the great network printer security apocalypse... -- I ran a quick nmap command (nmap -T4 -A -v -PE [IP address]) on a few of the many printers indexed by Google, and here's a typical result, showing tons of open ports and passwordless login options (I've deleted the hostname and IP address to protect the innocent): Starting Nmap 5.21 ( http://nmap.org ) at 2013-01-25 12:15 EST NSE: Loaded 36 scripts for scanning. Initiating Ping Scan at 12:15 Scanning XXX.XXX.XXX.XXX [1 port] Completed Ping Scan at 12:15, 0.10s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 12:15 Completed Parallel DNS resolution of 1 host. at 12:15, 0.14s elapsed Initiating Connect Scan at 12:15 Scanning [HOSTNAME] (XXX.XXX.XXX.XXX) [1000 ports] Discovered open port 23/tcp on XXX.XXX.XXX.XXX Discovered open port 21/tcp on XXX.XXX.XXX.XXX Discovered open port 443/tcp on XXX.XXX.XXX.XXX Discovered open port 80/tcp on XXX.XXX.XXX.XXX Increasing send delay for XXX.XXX.XXX.XXX from 0 to 5 due to max_successful_tryno increase to 5 Increasing send delay for XXX.XXX.XXX.XXX from 5 to 10 due to max_successful_tryno increase to 6 Warning: XXX.XXX.XXX.XXX giving up on port because retransmission cap hit (6). Discovered open port 14000/tcp on XXX.XXX.XXX.XXX Discovered open port 631/tcp on XXX.XXX.XXX.XXX Discovered open port 280/tcp on XXX.XXX.XXX.XXX Completed Connect Scan at 12:15, 37.26s elapsed (1000 total ports) Initiating Service scan at 12:15 Scanning 7 services on [HOSTNAME] (XXX.XXX.XXX.XXX) Completed Service scan at 12:16, 13.09s elapsed (7 services on 1 host) NSE: Script scanning XXX.XXX.XXX.XXX. NSE: Starting runlevel 1 (of 1) scan. Initiating NSE at 12:16 Completed NSE at 12:16, 3.57s elapsed NSE: Script Scanning completed. Nmap scan report for [HOSTNAME] (XXX.XXX.XXX.XXX) Host is up (0.11s latency). Not shown: 978 closed ports PORT STATE SERVICE VERSION 21/tcp open ftp HP LaserJet P4014 printer ftpd |_ftp-anon: Anonymous FTP login allowed 23/tcp open telnet HP JetDirect telnetd 25/tcp filtered smtp 80/tcp open http HP-ChaiSOE 1.0 (HP LaserJet http config) | html-title: hp LaserJet 9050 |_Requested resource was http://XXX.XXX.XXX.XXX/hp/device/this.LCDispatcher 111/tcp filtered rpcbind 135/tcp filtered msrpc 139/tcp filtered netbios-ssn 280/tcp open http HP-ChaiSOE 1.0 (HP LaserJet http config) | html-title: hp LaserJet 9050 |_Requested resource was http://XXX.XXX.XXX.XXX/hp/device/this.LCDispatcher 443/tcp open ssl/http HP-ChaiSOE 1.0 (HP LaserJet http config) | html-title: hp LaserJet 9050 |_Requested resource was http://XXX.XXX.XXX.XXX/hp/device/this.LCDispatcher 445/tcp filtered microsoft-ds 515/tcp filtered printer 631/tcp open http HP-ChaiSOE 1.0 (HP LaserJet http config) | html-title: hp LaserJet 9050 |_Requested resource was http://XXX.XXX.XXX.XXX/hp/device/this.LCDispatcher 1433/tcp filtered ms-sql-s 1720/tcp filtered H.323/Q.931 3168/tcp filtered unknown 4550/tcp filtered unknown 6000/tcp filtered X11 6112/tcp filtered dtspc 8654/tcp filtered unknown 9100/tcp filtered jetdirect 14000/tcp open tcpwrapped 19315/tcp filtered unknown Service Info: Device: printer -- [1] http://news.ycombinator.com/item?id=4412714 http://news.ycombinator.com/item?id=4412714 [2] http://www.schneier.com/blog/archives/2008/01/my_open_wireles.html http://www.schneier.com/blog/archives/2008/01/my_open_wirele...
- KwanEsq 14y agoInterestingly, if you try to browse far into the results, Google decided it actually only has 73 to display (after telling it to include ommitted similar results).
- chanux 14y agoI think Google is cleaning it up. (shows only 13 results for me)
- raphman 14y agoadd a number to the search term, e.g. "123"...
- eli 14y agoGoogle makes only a rough estimate of the total number of results. Try it on any query that returns a relatively small number of results.
- jrochkind1 14y ago86000 is certainly a _rough_ estimate of, um, 17.
- josh2600 14y agoSo... Where's Ang Cui at? In case you guys haven't seen it, Ang Cui is the guy who did the Cisco hack last month and he's also the guy with the coolest resume on the planet. He actually found a way to compromise printers during the print process, so by printing his resume, he pwns your printer. This seems like a bull in the china shop situation for that code.
- kefs 14y agoThis is what you're talking about. And for those that haven't seen it.. do yourself a favour and sit through the entire hour-long video; you won't regret it. http://arstechnica.com/security/2013/01/hack-turns-the-cisco-phone-on-your-desk-into-a-remote-bugging-device/ http://arstechnica.com/security/2013/01/hack-turns-the-cisco...
- FollowSteph3 14y agoI'd hate to be at the top of that google search result!!
- pbhjpbhj 14y agoI've a vague recollection that Google stepped in to prevent such searches working in the past?
- modernerd 14y agoSome of the IPs are registered to large US universities, who list abuse/tech support email addresses in their records. I've already emailed several with a headsup and had a couple of "thank you!"s in reply.
- smallegan 14y agoThose poor IT Support guys that get a call because their small business clients network is going down due to everyone hitting their printer(s) at once because they show up on the first page :-\
- jagermo 14y agoAs far as I know this problem has been around for years. If you want to dive deeper into this, i recommend you visit Shodan (http://www.shodanhq.com/ http://www.shodanhq.com/)
- kabdib 14y agoI wrote a scriptable "chooser" when I was at Apple -- it let you programmatically find and select a printer to print to. I enumerated every printer on campus (about 900 of them at the time, I think), and came /this close/ to printing a snarky page -- a fake version of the "Five Star News" internal company news -- on each one of them. Decided not to; probably a good career move that I resisted that urge.
- paulhauggis 14y agoSomeone did just this in my high school. They nearly got expelled.
- _casperc 14y agoAsking from ignorance here, is there a common protocol in use to communicate with printers e.g. find, interact with (print) and query (ask for toner level for instance) them? Seems it would make a valuable tool for managing a larger number of printers, to know when to switch the toner for instance.
- achillean 14y agoThis is actually one of the earliest searches that was used on the Shodan search engine! Shodan specializes in finding all devices connected to the Internet (including Telnet, SSH, FTP, SNMP etc.): http://www.shodanhq.com/search?q=hp+jetdirect http://www.shodanhq.com/search?q=hp+jetdirect http://www.shodanhq.com/search?q=laserjet http://www.shodanhq.com/search?q=laserjet http://www.shodanhq.com/search?q=HP-ChaiSOE http://www.shodanhq.com/search?q=HP-ChaiSOE
- deleted 14y ago[deleted]
- tlrobinson 14y agoWebcams too: https://news.ycombinator.com/item?id=5116676 https://news.ycombinator.com/item?id=5116676
- humanspecies 14y agoThis is truly an old hack, from the days of Altavista, you can find all sorts of open devices and even file folders(I think they've censored those results now) on the internet.
- hippich 14y agoAnd again - so many wasted IPv4s...
- walshemj 14y agoyes why would a printer need to be externally addressable - the problem will only get worse if ipv6 (aka ipv4 with rivets as the sainted verity stobb calls it) takes off.
- Aloha 14y agoI used to do it so I could print stuff for consumption or filling out when I got home from the field... also, because I could (a good reason for anything). Now I use IPP for the same purpose, less security risk.
- rbchv 14y agoUse this only to test your own printers. http://cdn.memegenerator.net/instances/400x/33855503.jpg http://cdn.memegenerator.net/instances/400x/33855503.jpg
- feefie 14y agoHow can I tell if my home printer is securely protected? Is there a good web page or text book anyone can recommend that will teach me more details about this? Thanks.
- andreasvc 14y agoIn a home network you typically have a router that separates your LAN (local area network) from the internet and shares one public IP among the devices in your network; in that case you have little to worry about. You can tell by the kinds of IP addresses your devices have: if it starts with 192.168.x.y, 172.x.y.z, or 10.x.y.z, then it's not reachable from the internet. The problem with these printers is that on their network there's no such separation and they are listening on a publicly routed IP address, but they've been designed with the tacit assumption that they will be used on a secured network.
- X-Istence 14y agoUnless you have IPv6 turned on ... in which case many of these printers will automatically grab an IPv6 and be publicly accessible.
- ingenium 14y agoDepends. Some builds of Tomato (Toastman's for sure) put a firewall up on IPv6 by default. Asus's firmware does NOT firewall IPv6 at all. If you have shell access to your router, I suggest putting up a firewall on IPv6. The following should work (change br0 to the bridged LAN interface and eth0 to the WAN interface, sometimes it's a vlan): ip6tables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT ip6tables -A FORWARD -i eth0 -o br0 -p all -j DROP ip6tables -A FORWARD -i br0 -j ACCEPT ip6tables -A FORWARD -o br0 -j ACCEPT ip6tables -A FORWARD -j DROP Of course insert whatever open ports you want after the first line.
- GBond 14y agoIf you recall from the early days of google, there are plenty of indexed dark data that Google actively scrubs out of the public results. For example it was trivial at one point to find credit card numbers and social security numbers.
- kristopolous 14y agoAnd bam, junk fax companies are back in business.
- mhurron 14y agoThey never were out of business.
- mentat 14y agoA friendly thing to do would be develop a script that took the google results, checked with whois for abuse address and sent emails. Of course that could also end up with one being sent to jail for a long time.
- plumeria 14y agoWhy would anyone go to jail for this?
- csense 14y agoThe nail that sticks up gets hammered. If someone else later does something bad with the publicly accessible printer and there's a witch hunt for the responsible party, and the only lead they have is that you emailed them about the possibility in advance...then they'll go after you, even though you were just trying to do a good thing. And if you're expecting the victim / police / legal system to understand that, technically speaking, it could have literally been anyone with an Internet connection...Or if you think that your good intentions and lack of criminal record mean that the most you'll get is a slap on the wrist even if they think your email "proves" that you did it...you're quite naive, especially given all the recent coverage of Aaron Swartz.
- TranceMan 14y ago> The nail that sticks up gets hammered. Thank you.
- rayiner 14y agoI should note that this isn't unique to computers, by the way. You should also never leave a note on an unlocked car saying "hey, noticed your car was unlocked --signed XYZ".
- plumeria 14y agoOk, but IP logs would throw down their assumptions. They wouldn't be able to prove a thing.
- 14y ago
- ancat 14y agoWhy did Google Dorks become all the rage again? People have been doing this for over 5 years now.
- bitwize 14y agoYou did this from your house? What are you, stoned or stupid?
- TranceMan 14y ago>What happened to you today? My printer got slashdotted :( > Eh?
- tmosleyIII 14y agoYou can find a lot of open machines and sensitive information using Google, this one for the HP printers was submitted to the Google Hacking Database[1] in 2004. [1] http://www.exploit-db.com/google-dorks/ http://www.exploit-db.com/google-dorks/
- meaty 14y agoSo within 24 hours, lots of people are going to find out what a goatse is I reckon. Even better, a lot of people in the UK have Thomson routers which have an easily calculable WPA default password. Most of these also have smart tvs these days too which will allow anything to be pushed to them.
- pbhjpbhj 14y ago>Even better, a lot of people in the UK have Thomson routers which have an easily calculable WPA default password. // That rather looks to oversteps the legal line.
- meaty 14y agoProbably yes, but there is no excuse for incompetence on the part of the ISPs when they ship routers to the customers.
- daralthus 14y agoMake sure to watch Ang Cui's demonstration on printer malware at 28c3. http://www.youtube.com/watch?v=njVv7J2azY8 http://www.youtube.com/watch?v=njVv7J2azY8
- dfamorato 14y agoThere is actually a crawler for "Machines and Devices", such as routers, IP Phones, WebCams, Dell Dracs, HP ILO , VMWARE ESX and so on. http://www.shodanhq.com/browse http://www.shodanhq.com/browse Also, check your server ip on Shodan to see if your firewall rules are not exposing a little to much
- sandycheeks 14y agoThe first thing I thought of was a course that I took decades ago that discussed using printers for covert channels to get data out of secure networks. I wonder if any of those are honeypots. It may be interesting to see if any visitors do something clever or unexpected.
- afita 14y agoI'm surprised nobody mentioned PrintFS in this thread: http://www.remote-exploit.org/articles/printfs/index.html http://www.remote-exploit.org/articles/printfs/index.html
- kunai 14y agoI did the Google search, and while the first page does indeed show 86K results, as soon as I navigate to the second, the number drops to 13... Am I the only one with this problem, or did Google really not index "thousands of publicly accessible HP printers"?
- deadairspace 14y agoWow. There is at least one printer on there in a US governmental department, and on one of the settings pages is a huge list of emails of employees. And now I'm probably on some kind of list.
- hn-miw-i 14y agoOne million trees just died. The problem with some of the earlier HP printers was that they would accept unsigned firmware updates, you could literally reflash the thing with an update instruction in postscript. Some work was done at Columbia University with developing trojanised firmware, i recall a firmware that could transmit CC# over tcp when it saw then in the print stream. Extreme care must be taken if connecting printers to the Internet. It's at best a horrible idea and I'd say that most of these are unknown to their owners. Hopefully this gets some MSM coverage and people address the connected printer problem forever. (not likely)
- fnordfnordfnord 14y agoTime for fun. Insert Coin, PC Load Letter, etc. Good times. http://miscellany.kovaya.com/2007/10/insert-coin.html http://miscellany.kovaya.com/2007/10/insert-coin.html