Live data from Hacker News

Printers are spontaneously printing odd "SQL" strings

discussions.apple.com

111–120 of 150 posts

Re: Printers are spontaneously printing odd "SQL" strings

#111

I'm waiting for the great network printer security apocalypse. A bunch of these things are in a great position to turn around and launch attacks on the "chewy on the inside" networks of so many companies. Maybe this has already happened. My printer has a dumb little print server running an embedded flavor of Linux and a publicly known hard-coded (!) root password. While mine is going to the slag heap sooner or later…

My very first criminal act of hacking as a teenager was gaining access to a printer somewhere in Spain, by which I had limited access to the rest of the network but I was too dumb to understand what to do.

So yeah, printers at least were a big gaping hole in the late 90s and early 00s.

Re: Printers are spontaneously printing odd "SQL" strings

#112
post #104

Earlier quoted context omitted.

It isn't an "appearance" of protection. NAT is the best thing to happen to security for home networks since their inception. The push to remove it with IPv6 and to force home users who don't care about these things to put their entire home network directly on the Internet is going to wreak havoc.

The security comes from the stateful firewall, not from the NAT. In all likelihood, IPv6-supporting home routers will ship with a stateful firewall enabled by default.

The stateful firewall is there because it is necessary for NAT. If it weren't necessary for NAT, consumers would not bother with it. Customers buy the router with the firewall to hook up multiple computers, they don't care about the security. You could argue that they should hire a security consultant to educate them on the need for a stateful firewall when setting up their home network, but you would be smoking crack.

Re: Printers are spontaneously printing odd "SQL" strings

#113
post #62

Earlier quoted context omitted.

it's worth noting, I think, that Schneier is pretty out of touch when it comes to the whole "open wireless" thing, because he leaves himself open to a bunch of local-only attacks. he's correct that your computer should be able to withstand being on the 'open' internet, since it is every time you take it to work or a coffee shop or something, but, don't be an idiot, just turn WPA2 on at your house. many access points…

he leaves himself open to a bunch of local-only attacks What kind of attacks might those be? Consider the case of a computer connected to the network with no open ports (other than say, 25 for SSH), with a properly configured firewall, that connects to the Internet through a VPN and with an operating system that auto-updates itself. What could you do to it from inside the network?

OpenBSD's second remotely-exploitable hole relied on being on the same network segment (AIUI from a quick read it involved sending malformed IPv6 packets). Such vulnerabilities aren't particularly common, but you're always going to be exposing a somewhat wider attack surface to the local network than to the internet at large.

Re: Printers are spontaneously printing odd "SQL" strings

#114

Earlier quoted context omitted.

It's not 1994, no one "points" a browser at anything any more.

Look for the good in that post, don't nitpick the phrasing that was chosen.

The good in the post is obvious, someone has to stand up for taking out the bad parts too.

Re: Printers are spontaneously printing odd "SQL" strings

#116
post #9

I did a project in college where I scanned networks for IPP ports and would print agit prop to them The printer panopticon. Oh art school.

Heh... a similar "project" when I was in high school got me sent to the principal's office once :-)

Re: Printers are spontaneously printing odd "SQL" strings

#117
post #41

Many, perhaps most network-connected printers, NAS units, and other devices (e.g., home-automation hardware) simply assume that the local network they connect to will be securely protected from external attack, so they're not configured to withstand even the simplest of attacks. This is exactly the opposite of what many security experts recommend: ideally all devices should be secure regardless of whether the network…

Especially with the development of IPv6, internal routing becomes transparent and the appearance of protection offered by NAT is gone. Possibly these printers all have been assigned a public-reachable IPv6 addresses.

You can't be seriously claiming that someone is port scanning my /48 that I've had since the early 00s? Over a typical slow internet connection that would take rather a long time to find my printer. Lets say you slammed my couple megabit cablemodem with a million address probes per second (yes I'm well aware thats impossibly high). It would only take you 38 billion years of continuous scanning to find my printer. I'll even give you credit that most people are using just a couple (obvious) /64 inside their /48. Assuming my math is correct it would take a mere half a million years per /64, so figure a couple million years and you'll own my home lan...

Re: Printers are spontaneously printing odd "SQL" strings

#118

Earlier quoted context omitted.

Look for the good in that post, don't nitpick the phrasing that was chosen.

The good in the post is obvious, someone has to stand up for taking out the bad parts too.

Your stand is fairly unwarranted though. People know what "pointing your browser" means in this context as it is still a commonly used turn of phrase, even though it may date back into the long forgotten antiquity of almost 20 years ago.

Re: Printers are spontaneously printing odd "SQL" strings

#119

No need to worry, all Mac's are virus, malware and attack proof and so (by the law of distortion of reality) are any devices or networks attached to a Mac. Go about your business and forget about that pesky "security" thing everyone else likes to talk about. Just etch a picture of Steve striking a thoughtful pose on the lid of your laptop and all your problems will be forgotten.

Thanks for injecting helpful -- not to mention hilariously witty -- points into this conversation. You left out the following points: * Apple's stuff is incredibly overpriced * Apple never invented anything, it's just good at marketing * Apple's lawsuits are all based on rounded rectangles * Xerox invented the GUI from scratch and it was perfect * Anyone who uses an Apple device is a hipster fanboi cultist

If Apple's stuff wasn't incredibly overpriced they wouldn't have $100B in the bank. Steve's ghost would be sad and they wouldn't be able to bankroll all their lawsuits (which would also make Steve's ghost sad).

Apple USED to be good at marketing. Have you seen those new ads? The ghost of Steve just barfed in his mouth a little bit. Quick! Someone call Justin Long and John Hodgman, that was working okay...

Rounded rectangles are the new lucite, and therefor not relevant in any way. Apple's lawsuits were based on Steve Jobs being a big baby about how well Android was selling. Now? Who knows how the Apple lawsuit of the day gets kicked off, but you can bet it involves Androids (and not the Star Trek variety).

Now you're just being thick, the first GUI was done by Doug Engelbart (Stanford Research) in '68. It was perfect. Any CS student who took an HCI knows that. Extra points if you know what HCI stands for and don't have to google Engelbart to verify, but I bet you do :)

Some people who use Apple devices just want some of the discretionary income that hipster, fanboi (and fangrl, you sexist) and cultists seem quite happy to part with. Will that be cash or credit?

Re: Printers are spontaneously printing odd "SQL" strings

#120
post #104

Earlier quoted context omitted.

The security comes from the stateful firewall, not from the NAT. In all likelihood, IPv6-supporting home routers will ship with a stateful firewall enabled by default.

The stateful firewall is there because it is necessary for NAT. If it weren't necessary for NAT, consumers would not bother with it. Customers buy the router with the firewall to hook up multiple computers, they don't care about the security. You could argue that they should hire a security consultant to educate them on the need for a stateful firewall when setting up their home network, but you would be smoking crac…

In all likelihood, IPv6-supporting home routers will ship with a stateful firewall enabled by default.
Post reply on HN