Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×
Google HP Printer Security Technology

Thousands of Publicly Accessible Printers Searchable On Google 192

Jeremiah Cornelius writes "Blogger Adam Howard at Port3000 has a post about Google's exposure of thousands of publicly accessible printers. 'A quick, well crafted Google search returns "About 86,800 results" for publicly accessible HP printers.' He continues, 'There's something interesting about being able to print to a random location around the world, with no idea of the consequence.' He also warns about these printers as a possible beachhead for deeper network intrusion and exploitation. With many of the HP printers in question containing a web listener and a highly vulnerable and unpatched JVM, I agree that this is not an exotic idea. In the meanwhile? I have an important memo for all Starbucks employees."
This discussion has been archived. No new comments can be posted.

Thousands of Publicly Accessible Printers Searchable On Google

Comments Filter:
  • by fluffy99 ( 870997 ) on Friday January 25, 2013 @05:06PM (#42695357)

    I wonder if any of them are the older HP LaserJets where you could change the display to read funny things like "Insert Cheese" or "Low on Mayo"?
    http://community.spiceworks.com/scripts/show/1184-change-a-networked-hp-laserjet-ready-message [spiceworks.com]
    http://miscellany.kovaya.com/2007/10/insert-coin.html [kovaya.com]

  • Very useful (Score:5, Funny)

    by scotts13 ( 1371443 ) on Friday January 25, 2013 @05:09PM (#42695389)

    (GRIN) At one time, I had dial-in access to the Apple corporate network; back then AppleTalk and PAP were still supported. When I was having trouble getting an employee to answer his email, I'd just print the message to the printer in his office. That would usually get his or her attention.

  • by Anonymous Coward on Friday January 25, 2013 @05:09PM (#42695399)

    I saw a story not too long ago about someone accessing their neighbor's printer to print out messages to the neighbor, pretending the printer was somehow alive; starting with some gibberish it became words and then paragraphs of text.

    But you wouldn't do that to any of these printers because (pulls down microphone hidden in lamp suspended from ceiling) that would be wrong!

  • by Splab ( 574204 ) on Friday January 25, 2013 @05:16PM (#42695495)

    Since you are abusing their equipment, you are probably going to be up for all sorts of fun unlawful computer acts.

    And if you are going to prank them, send the "You're fired" from back to the future...

  • by jfdavis668 ( 1414919 ) on Friday January 25, 2013 @05:18PM (#42695541)
    I pity the people who's printers show up on the first page of Google results.
  • by Fallingcow ( 213461 ) on Friday January 25, 2013 @05:19PM (#42695557) Homepage

    "lp0 on fire"

  • by Charliemopps ( 1157495 ) on Friday January 25, 2013 @05:40PM (#42695799)

    Jimmy: So hows the new real estate agency dad said you started?
    Uncle Jim: The whole office is a mess. We've got a bunch of computers, and we got one of those box things to connect them all together at walmart... But it only has 10 plugins and now we've got this new printer...
    Jimmy: Uh... I think we can just get a bunch of old network cards, put them in that computer in the basement and install linux on it...
    Uncle Jim: Is Linux secure?
    Jimmy: It's the best. I think Nasa uses it.
    Uncle Jim: Wow, this is great that was going to cost me Twenty...er... hey I'll give you $10 an hour to do it.
    Jimmy:Really? Awsome... *starts doing wikipedia searches for linux*

  • by Laebshade ( 643478 ) <laebshade@gmail.com> on Friday January 25, 2013 @05:43PM (#42695825)


    % cd projects/pevil
    % cat pevil
    #!/usr/bin/perl

    use warnings;
    use strict;
    use 5.014;
    use Printer::HP::Display;

    my $printer_ip = "172.30.20.129";
    my $printer = Printer::HP::Display->new($printer_ip);

    my ($text) = @ARGV;
    my $message = "I'm sorry Dave, I can't print that.";
    $message = $text if defined $text;

    $printer->set_display($message);
    say $printer->get_display;

  • by Nimey ( 114278 ) on Friday January 25, 2013 @05:44PM (#42695831) Homepage Journal

    I did that to my old department head's printer a few years ago. I think it was asking for $0.25 to be inserted for a few weeks before he asked me to fix it.

  • by Lehk228 ( 705449 ) on Friday January 25, 2013 @06:03PM (#42696033) Journal
    i would love to do that, but the knuckleheads i work with would end up jamming quarters into the vents on the printer
  • by Anonymous Coward on Friday January 25, 2013 @06:45PM (#42696421)

    You Sir are a knave; a rascal; an eater of broken meats; base, proud, shallow, beggarly, three-suited, hundred-pound, filthy, worsted-stocking knave; a lily-livered, action-taking knave, a whoreson, glass-gazing, super-serviceable finical rogue; one-trunk-inheriting slave; one that wouldst be a bawd, in way of good service, and art nothing but the composition of a knave, beggar, coward, pandar, and the son and heir of a mongrel bitch: one whom I will beat into clamorous whining, if thou deniest the least syllable of thy addition.

  • by Scarletdown ( 886459 ) on Friday January 25, 2013 @08:23PM (#42697281) Journal

    Balls do not pay the rent.

    I suppose that depends on what you do for a living.

  • by arglebargle_xiv ( 2212710 ) on Saturday January 26, 2013 @08:15AM (#42699807)

    What I loved were the printers at all three of the colleges I went to all had complicated systems set up so that they could charge you to print on the printers. However, open up wireshark and in less than a second, you would receive a couple hundred packets from printers advertizing themselves. And it wasn't just student printers either; the very printers they were charging us to print from availible for free and letting everybody know.

    It's even worse than that, given that university regulations require that all software of this kind is developed in-house by underpaid student interns, the accounting software is usually as sucky as you can get. When I was a student you could set the page count in your postscript jobs to a negative value and it'd credit your account every time you printed something. I paid off my student loan that way.

If you think the system is working, ask someone who's waiting for a prompt.

Working...