Earlier quoted context omitted.
Why would anyone go to jail for this?
The nail that sticks up gets hammered. If someone else later does something bad with the publicly accessible printer and there's a witch hunt for the responsible party, and the only lead they have is that you emailed them about the possibility in advance...then they'll go after you, even though you were just trying to do a good thing. And if you're expecting the victim / police / legal system to understand that, tech…
Google has indexed thousands of publicly accessible HP printers
91–100 of 149 posts
Re: Google has indexed thousands of publicly accessible HP printers
#92I wonder if any of those are honeypots. It may be interesting to see if any visitors do something clever or unexpected.
Re: Google has indexed thousands of publicly accessible HP printers
#93Earlier quoted context omitted.
Can you really argue in good faith that you are legally authorized to print something on their printer?
Yes, I think you can. There have been case(s) I think (in USA) concerning websites where it was argued successfully that placing an non-password protected page available on the public internet was implied consent to access/use that service. That seems the right way to do it. You can't then, for example, put up a website which enables printing and then claim that people who use it are financially liable for using that…
Re: Google has indexed thousands of publicly accessible HP printers
#94Earlier quoted context omitted.
Nostalgia Scam Time: Back in the late 90s there was a common scam run against big-ish offices. A caller would call asking to talk to the person in charge of printers, typically either IT or Facilities. Once connected they would say that they are sending out the recipients free gift, which was some lame piece of electronics - often a small television. They would get the work address and confirmation to ship the free g…
I'm a little unclear as to how how exactly they planned to enforce payment for un-solicited toner. What am I missing?
Re: Google has indexed thousands of publicly accessible HP printers
#95Earlier quoted context omitted.
I'm a little unclear as to how how exactly they planned to enforce payment for un-solicited toner. What am I missing?
http://business.ftc.gov/documents/bus24-avoiding-office-supp... They threaten, talk to A/P directly and demand payment (skipping over the original agent), all sorts of ways.
Re: Google has indexed thousands of publicly accessible HP printers
#96Re: Google has indexed thousands of publicly accessible HP printers
#97How can I tell if my home printer is securely protected? Is there a good web page or text book anyone can recommend that will teach me more details about this? Thanks.
Re: Google has indexed thousands of publicly accessible HP printers
#98I've written about this before.[1] Many network-connected printers simply assume that the local network they connect to will be securely protected from external threats, so they're not configured to withstand even the simplest of attacks. This is exactly the opposite of what many security experts recommend: devices should be secure regardless of whether the network they're on is secure or not. Bruce Schneier's person…
A few months ago I erroneously port scanned our office HP networked printers (I meant to scan our internal servers but a typo meant I selected the wrong IP range). As soon as nmap encountered the JetDirect ports every single printer spewed out a dozen pages of total gibberish. Put it this way - I bet the owners of the printers you just scanned are slightly puzzled why their printer kicked into life. More worryingly i…
--allports (Don't exclude any ports from version detection).
By default, Nmap version detection skips TCP port 9100 because some
printers simply print anything sent to that port, leading to dozens
of pages of HTTP GET requests, binary SSL session requests, etc.
This behavior can be changed by modifying or removing the Exclude
directive in nmap-service-probes, or you can specify --allports to
scan all ports regardless of any Exclude directive.Re: Google has indexed thousands of publicly accessible HP printers
#99Earlier quoted context omitted.
Can you really argue in good faith that you are legally authorized to print something on their printer?
Yes, I think you can. There have been case(s) I think (in USA) concerning websites where it was argued successfully that placing an non-password protected page available on the public internet was implied consent to access/use that service. That seems the right way to do it. You can't then, for example, put up a website which enables printing and then claim that people who use it are financially liable for using that…
Re: Google has indexed thousands of publicly accessible HP printers
#100Earlier quoted context omitted.
But you are not AUTHORISED to access said resources, so you would be in violation of the Computer Fraud and Abuse Act.
Who says I am not authorised? I can claim that public access is an implicit authorization, like any website! And there is no warning or message in the public control panels.