Live data from Hacker News

Google has indexed thousands of publicly accessible HP printers

port3000.co.uk

121–130 of 149 posts

Re: Google has indexed thousands of publicly accessible HP printers

#121

Idea for startup. 1. write a script to scrap google links to HP admin panel 2. filter out the IPs that are from US (given you want to work on US market) 3. assemble the list of printer types and current toner levels. 4. write a script that will print to each of those printers a one single page, stating your company "Cheapo Suppliers Inc" was notified that "your printer is low on toner. Call xxxxxx to re-fill. Lowest…

Nostalgia Scam Time: Back in the late 90s there was a common scam run against big-ish offices. A caller would call asking to talk to the person in charge of printers, typically either IT or Facilities. Once connected they would say that they are sending out the recipients free gift, which was some lame piece of electronics - often a small television. They would get the work address and confirmation to ship the free g…

[deleted]

Re: Google has indexed thousands of publicly accessible HP printers

#122
post #79
post #13

I've written about this before.[1] Many network-connected printers simply assume that the local network they connect to will be securely protected from external threats, so they're not configured to withstand even the simplest of attacks. This is exactly the opposite of what many security experts recommend: devices should be secure regardless of whether the network they're on is secure or not. Bruce Schneier's person…

The same goes for smart tvs. Most of them you can push stuff to via dnla without a password. Much amusement to be had.

I think the Sony TV's offer an onscreen pop-up before accepting commands from unregistered DLNA controllers although maybe that can be faked (and maybe there is a flaw, I've never explored it deeply).

Re: Google has indexed thousands of publicly accessible HP printers

#123
post #55

Earlier quoted context omitted.

Lets not overreact here. The printers are on public wire. You had not done any crime by using Google to find them. You obtained access to their open HP admin panel via public link with no password or credentials you had to pass. You haven't stole any information and, furthermore, there is NO confidential information even to be stolen to start with. On the top of that, you cannot even determine who they are (name, com…

> The printers are on public wire. > You had not done any crime by using Google to find them. > You obtained access to their open HP admin panel via public link with no password or credentials you had to pass. There's even less barrier to sending a junk fax, and that can get you fined and potentially jailed.

I will argue. Junk fax is a message send to a number for no reason. In my example I would only send messages (print) on the printers that would be low with toner. I would NOT print on every single printer just because I can. Huge difference.

Re: Google has indexed thousands of publicly accessible HP printers

#124
post #79

Earlier quoted context omitted.

The same goes for smart tvs. Most of them you can push stuff to via dnla without a password. Much amusement to be had.

I think the Sony TV's offer an onscreen pop-up before accepting commands from unregistered DLNA controllers although maybe that can be faked (and maybe there is a flaw, I've never explored it deeply).

This is correct, though you could cause a flood of requests that block input from the real user (each has to be dismissed in order).

Re: Google has indexed thousands of publicly accessible HP printers

#126
post #76

And again - so many wasted IPv4s...

yes why would a printer need to be externally addressable - the problem will only get worse if ipv6 (aka ipv4 with rivets as the sainted verity stobb calls it) takes off.

I used to do it so I could print stuff for consumption or filling out when I got home from the field... also, because I could (a good reason for anything). Now I use IPP for the same purpose, less security risk.

Re: Google has indexed thousands of publicly accessible HP printers

#127
post #26

Earlier quoted context omitted.

I think Google is cleaning it up. (shows only 13 results for me)

That's with similar entries omitted. You need to go to the second page and have it repeat the search with those entries included.

ah my bad. Thanks for pointing out.

Re: Google has indexed thousands of publicly accessible HP printers

#128
post #104

Earlier quoted context omitted.

But we didn't change anything here; is just a website that says: "Select the file you want to print" and that's it.

And you think the owners of the printers really enjoy others using them like that? That all those IPs are set up like this on purpose?

Is there a fact we can examine to answer that/those questions?

Re: Google has indexed thousands of publicly accessible HP printers

#129

Earlier quoted context omitted.

But you are not AUTHORISED to access said resources, so you would be in violation of the Computer Fraud and Abuse Act.

Who says I am not authorised? I can claim that public access is an implicit authorization, like any website! And there is no warning or message in the public control panels.

If I leave my keys in the car, leave the car turned on with the door opened, are you authorized to drive my car?

Re: Google has indexed thousands of publicly accessible HP printers

#130
One million trees just died. The problem with some of the earlier HP printers was that they would accept unsigned firmware updates, you could literally reflash the thing with an update instruction in postscript.

Some work was done at Columbia University with developing trojanised firmware, i recall a firmware that could transmit CC# over tcp when it saw then in the print stream.

Extreme care must be taken if connecting printers to the Internet. It's at best a horrible idea and I'd say that most of these are unknown to their owners. Hopefully this gets some MSM coverage and people address the connected printer problem forever. (not likely)

Post reply on HN