Earlier quoted context omitted.
There's some law against postal fraud that says whatever they send you though the post is yours (to avoid exactly this kind of scam) You can try not paying the invoice and see what happens.
Yeah and then they retaliate by sending you two pallets of crap toner cartridges, had enough? No? Still not going to pay? Ok here are five pallets of crap toner cartridges sitting in your mail room. Call up the dump, "What? Toner? That probably a toxic waste, you'll have to make an appointment and pay the extortionate hazardous waste fee." Then the toner guy calls back "You either pay us or next time it will be 10 pa…
Google has indexed thousands of publicly accessible HP printers
81–90 of 149 posts
Re: Google has indexed thousands of publicly accessible HP printers
#82And bam, junk fax companies are back in business.
Re: Google has indexed thousands of publicly accessible HP printers
#83Re: Google has indexed thousands of publicly accessible HP printers
#84http://www.shodanhq.com/browse
Also, check your server ip on Shodan to see if your firewall rules are not exposing a little to much
Re: Google has indexed thousands of publicly accessible HP printers
#85Earlier quoted context omitted.
In the US, this will get you arrested, you will have a huge fine and probation, and prison time is not off the table. I'll refer you to the CAN-SPAM Act of 2003, which does not just govern unsolicited e-mail, but all commercial mail which the law defines as electronic communication (bulk faxes, etc.)
Lets not overreact here. The printers are on public wire. You had not done any crime by using Google to find them. You obtained access to their open HP admin panel via public link with no password or credentials you had to pass. You haven't stole any information and, furthermore, there is NO confidential information even to be stolen to start with. On the top of that, you cannot even determine who they are (name, com…
Re: Google has indexed thousands of publicly accessible HP printers
#86Earlier quoted context omitted.
Nostalgia Scam Time: Back in the late 90s there was a common scam run against big-ish offices. A caller would call asking to talk to the person in charge of printers, typically either IT or Facilities. Once connected they would say that they are sending out the recipients free gift, which was some lame piece of electronics - often a small television. They would get the work address and confirmation to ship the free g…
I'm a little unclear as to how how exactly they planned to enforce payment for un-solicited toner. What am I missing?
They threaten, talk to A/P directly and demand payment (skipping over the original agent), all sorts of ways.
Re: Google has indexed thousands of publicly accessible HP printers
#87Earlier quoted context omitted.
Who says I am not authorised? I can claim that public access is an implicit authorization, like any website! And there is no warning or message in the public control panels.
Can you really argue in good faith that you are legally authorized to print something on their printer?
Re: Google has indexed thousands of publicly accessible HP printers
#88Earlier quoted context omitted.
Who says I am not authorised? I can claim that public access is an implicit authorization, like any website! And there is no warning or message in the public control panels.
Can you really argue in good faith that you are legally authorized to print something on their printer?
There have been case(s) I think (in USA) concerning websites where it was argued successfully that placing an non-password protected page available on the public internet was implied consent to access/use that service.
That seems the right way to do it. You can't then, for example, put up a website which enables printing and then claim that people who use it are financially liable for using that service.
That would be like putting a bench on a busy street and then popping up and charging people if they happened to sit on it - if they sit down, you can tell them they're not authorised to sit without payment, or you can advertise lack of authorisation (eg with a price list) but otherwise you're implying consent.
Re: Google has indexed thousands of publicly accessible HP printers
#89I've written about this before.[1] Many network-connected printers simply assume that the local network they connect to will be securely protected from external threats, so they're not configured to withstand even the simplest of attacks. This is exactly the opposite of what many security experts recommend: devices should be secure regardless of whether the network they're on is secure or not. Bruce Schneier's person…
More worryingly is that on many unpatched HP printers[1] it is entirely possible to push an unauthorised firmware update through port 9100.[2]
--
[1] Enabling OS updates is one thing but I wonder how many businesses actively update their printers to the latest firmware versions?
[2] http://h20000.www2.hp.com/bizsupport/TechSupport/Document.js...
Re: Google has indexed thousands of publicly accessible HP printers
#90Earlier quoted context omitted.
Who says I am not authorised? I can claim that public access is an implicit authorization, like any website! And there is no warning or message in the public control panels.
Can you really argue in good faith that you are legally authorized to print something on their printer?
I can see them getting you for spam, just as they can with unsolicited faxes I believe, but anything more than that? Seems a little silly.
To add to the printer/fax comparison, I have known people who used printers in different physical locations within an organization as a "fax machine" that was easier to use with a computer. Need to send some documents to the guys across the state? Print it to them.