We hacked 28,000 unsecured printers to raise awareness of printer security issue
cybernews.com
cybernews.com
I was kind of expecting they were selecting on device location to make sure the recipient can understand the message.
Right. I think the word "hacked" feels more aggressive and even scary than something like "This printer is vulnerable. We are security researchers but it could be real hackers. Here is how to secure it..."
It definitely draws attention, but in a very uncomfortable way.
It's even worse for people who do not speak English. As a Russian, I guess "hacker/hacked" is recognizable in a lot of non-English speaking societies, but other parts of the printed page are less so. So it definitely can unnecessarily spook some of those people until they find a way to understand the entire message.
I mean, “hacking a printer” is surely illegal, so what if you sent a “Free Weekly Security Newsletter“ with some news headlines and the footer saying “To unsubscribe, secure your printer” for couple weeks?
Thought the HN crowd would love diving in to the rights and wrongs of it. It reminded me of the 'old days' of fax spamming via uhmmm '2600' approved means and methods.
With that said - Would I rather read some pages printed off for 'some weird reason' (and got p*offed at the waste of paper etc) vs. inadvertantly becoming part of a possible future bot-net?
I mean - How do you alert the owner of a 'Write Only' (pun intended) device? And also hopefully at the same time kick up enough of 'Facebook/Twitter/XYZ' storm that Joe/Sue Q. Public notices?
That's a tough one.
Does the answer change if you were notified of a misconfiguration that could allow this?
Depending on jurisdiction, sometimes.
> Does the answer change if you were notified of a misconfiguration that could allow this?
Depending on jurisdiction, often. Not quite always, as it may fall back on the manufacturer for not releasing a "reasonable" way to secure the machine without loss of function. But generally speaking, if you have been notified, you're on the hook.
Hacking printers just to promote your blog is kinda scummy. If you do it to help people secure their networks, then at least show how much you've managed to help by publishing the numbers. Anyone can use Shodan and submit a PDF with a script.
Phenoelit also have a few "fun" tools around to mess with printers: http://www.phenoelit.org/hp/docu.html
I can't recall when exactly this was (around the 2000s), i think there was a talk or paper by FX of Phenoelit who wrote a proxy for HP printers.
So you'd go Internet <-> Printer <-> internal Network - now, that should send a few shivers up peoples spines but apparently not.
"I went around and scratched the paint on 28,000 ICE cars to raise awareness on climate change issues"
1. - https://www.forbes.com/sites/thomasbrewster/2018/12/03/a-hac...