Microsoft Issues Emergency Patch for Windows Flaw
krebsonsecurity.com
krebsonsecurity.com
Microsoft like a lot of big techs needs to start rewarding people for maintaining/updating legacy stuff, rather than promoting/rewarding people for new shinies while the technical debt grows out of control. The printer stack which has barely received an update since Windows XP is a perfect example.
In all probability, probably even Microsoft is contemplating such move but breaking a lot of stuff is reputationally damaging to them, even if it's not really their fault in this case. Removing SafeROM is easier because it's just grumbling gamers who can probably patch up Windows 7, but imagine the support calls when the print spooler, a critical component, is moved. Even when a rational mind would put the blame on HP (et al., it's not just HP designing "weird" drivers), the problem will appear due to a Microsoft change and therefore Microsoft gets the blame.
Also, put your preferred paper size in /etc/papersize if you are not letter size inclined.
... OK I've just tested that against my home HP MFP and 9100/tcp shows in the results.
If lpd does it for you on Xerox printers, then fine: use that. I was discussing HPLIP ie getting rid of a Hewlett Packard thing!
Printer drivers haven't run in the kernel since NT 4.0.
I wish that's true, and the APIs are there (and should be used!), but except for incompetence I don't know how some drivers still have that kernel-side code (unless DRM? And if it is, why?)
I even thought that the 64-bit and Vista driver reset have banished kernel-level drivers, but in the past 6 months I still see printer drivers with kernel-level components. I just scratch my head why?
(Some of them are for PCI (yes, not a typo) connector, which is reasonable but weird for a printer. Others are running to printer port and USB but the kernel-level components are still there, active according to Device Manager).
"Hey we should upgrade to the latest standards!"
"Why?"
"Because they are safer!"
"Yeah, but it might break things"
"But it's safer!"
"Yeah, but the current shit is working. Don't mess with a working thing".
It's practically a religion there. I interned there years ago, it was a momentous task getting internal people to move from IE 7 to firefox, chrome, or IE8. What I'd done was improve one of their internal tools with an updated javascript library. However, it ran like ass on IE 7 and perfectly fine on pretty much everything else.
Windows does all kind of random things at SYSTEM scope and maybe for most of it, it is a terrible idea; yet they think that somehow VBS will save the world, and do not give a shit about the obvious existing shortcomings of their stack... At one point a virus could exploit a bug in the MS Defender AV engine and ironically execute under SYSTEM by just being scanned (!!) and they reacted by introducing MP_FORCE_USE_SANDBOX, however it seems that instead of quickly extending the usage of that sandbox to every user they... now just spawn the worker process (if the env var is there) but it does not do anything anymore :/
I get that engineers are attracted to working on new shinny things, but at one point not maintaining the old stuff (or even just properly removing!) under the excuse that the new unfinished one is more important is just lack of vaguely competent project management, and overall lack of professionalism. Even maybe of individual contributors: if you do not push strongly to get the shit cleaned-up in priority, you are as guilty as the people directing you to work on other (likely soon to be deprecated and unmaintained too) things.
KPI forever indeed. I never expected as a sysadmin I’d be creating excel reports to measure the performance of others.
In the future, applications might be able to communicate directly with a network printer via TCP/HTTP. The printer itself does spooling, queueing, management, etc. The OS doesn't need to be involved at all. "Legacy Printer" support can be disabled by default.
If you need to change ink cartridges you either do it on the screen of the printer, or install the manufacturers tool which also just communicates over TCP/HTTP and doesn't use any special interfaces.
https://www.microsoft.com/en-ww/microsoft-365/windows/univer...
The big change was the shift to XPS based drivers in Vista (which was back ported to XP). The trouble is the printer manufacturers have largely ignored this and continued to produce GDI based drivers. I sometimes wonder if Windows has too much backwards compatibility.
Appearances are they tried to break printer driver compatibility again in Windows 8 (which had some smart ideas on how to modernize the print stack but never got off the ground with them because no drivers adapted to the new stack; and then Windows 10 dropped most of what made the new stack special including not just moving everything into user space but moving everything into app sandboxes; no more annoying printer "background app" notifications and ads would have been amazing) and got worse pushback from the entrenched interests.
Also, in terms of naming and shaming specific manufacturers, HP/HPE alone has already been known to hold entire industries hostage to old (unsupported) versions of Windows or the various whims of their AIX/HP-UX Unix-based OS efforts rather than support up-to-date drivers on Windows for printers and plotters (and medical equipment and other electronics). It really is easy to imagine them telling the same bad infosec advice to consumers if Microsoft were to break compatibility in their printer drivers. No one wants the chaos of supporting their family members trying to stick on an ancient unsupported Windows XP version simply because their reliable old inkjet printer told them to. Sure everyone thinks they want the Year of Linux on the Desktop, but no one actually wants to help a friend dual boot into HP-UX, and debug cups dump output for them, just to print something twice a year.
My experience working with printer manufacturers is most of them would love to not have the responsibility of writing printer drivers. If they could offload the work to MS they would be over the moon.
I also assume that if Microsoft had the ability to create more generic printer drivers they would. Given the huge amount of older legacy hardware that falls under any of the other Generic Class Drivers it kind of sticks out as a sore thumb how few printers have generic drivers. (IIRC, there's a Generic PostScript driver that works with early [Apple led era] laser printers back when PostScript was new and considered sufficient as the only language between the computer and the printer, and nothing recent.)
My understanding is that most inkjet printers especially speak OEM proprietary languages that's not just PostScript or PDF (or Microsoft's mostly failed dream of an open XML format with fewer patent hangups than PS/PDF they tried in XPS). You would assume some of those proprietary languages include commands at least ancillary to the cartridge DRM (initiating checks, validating DRM status codes and checksums, things like that) if not directly involved. DRM is the main reason to blame these proprietary languages for remaining proprietary and not well standardized across/between manufacturers (and thus don't leave us with enough generic OS printer drivers today), though it's probably not the sole reason for the proprietary languages. I'm sure the manufacturers also have other reasons for keeping their printers using proprietary languages such as not wanting to license PS/PDF or leak too many low level details of their hardware designs (beyond just possibly leaking DRM information) or patented "secret sauce" of their own languages they believe to be a competitive asset.
Microsoft's XPS push was one attempt to get them off proprietary languages and allow them to offload far more driver work to Windows directly. Seems a shame none of the printer manufacturers seemed to take them up on that.
Yes, finally, this will be the defining event that finally gets Microsoft to give a flying fuck about security or about code quality. /s
Anyone remember this stuff circa January 2002?
Gates Finally Discovers Security https://www.wired.com/2002/01/gates-finally-discovers-securi...
To quote from that: Bill Gates' directive that Microsoft emphasize security features in its product is a major strategy shift, but some experts wonder if there's anything behind the words.
Now, 19 1/2 years later, Bill's directive will finally be taken seriously? Maybe once we hit 1,000,000 "critical" security flaws in Microsoft products? How many more before we hit that number? Does anyone even bother to count?
https://www.reddit.com/r/sysadmin/comments/oflbny/windows_pr...
Furthermore, the MS patch doesn't work properly:
https://www.theregister.com/2021/07/07/printnightmare_fix_fa...
It's safe to disable Print Spooler on servers that aren't print servers, so I expect that to be a standing recommendation in the future. The other thing though is this vulnerability works against desktop PCs, which need the Print Spooler to print... However, you can set a group policy to disable remote printing to a desktop PC, which should block the flaw. Desktop PCs probably shouldn't be acting as print servers, so this is mostly a good idea to implement too.
So the available mitigations/attack surface reductions available here are plentiful... and honestly probably should just be best practice now.
Microsoft literally sells an entire line of Server products ("Server Essentials") that are designed to be a combined AD/Printer/File Share/DNS/DHCP/etc server.
Selling a product to a small business them jumping all over that small business for using it that way seems pretty wrong to me. Larger businesses can and likely should do better (e.g. isolate printers on their own VLAN?).
Ultimately blaming end users is rarely constructive. Frankly the Windows Printer Spooler is using 1990s security thinking in 2021, and that's on Microsoft.
WOW... Since when small business needs AD ?? :) DHCP, yes but DNS ? "Small business" so no DNS internaly needed so obviously Internet facing... And that do as file share and printer server ?? "Only in Microsoft" :>
Becouse MS OSes do not have real ability to install/uninstall basic system components like eg. printer spooler...
And how many times now MS spooler was RCE or admin rights source ??
As of this morning the darn hotfix isn't available from standard Windows Update app, and the out-of-band files are unique depending on Windows release, so this factors that in.
https://github.com/djcabrera/printNightmareUtility/blob/main...
Hope it helps.
If it's windows client the printing feature is most certainly enabled, so yes you're open to attack. You can think of the registry as a global config file. If a given section is missing, the program will just do whatever the default is. The same applies for windows. A section (path) missing doesn't mean the feature isn't enabled.
The best contender is ironically Google and Chromebooks, but I feel that they still need to improve their solution though.
If you can recommend a core banking ops solution and a loan origination software for banks under $1B in assets that doesn't require Windows I will gladly go around to all my clients and sell it. Something comparable to what Jack Henry, Fiserv, and Finastra are hawking.
Small businesses can get away with doing everything on websites and a gmail account. Large businesses can 'just' make their own stuff. Middle market businesses that aren't selling software are all trapped on Windows by the software they can buy.
I've heard anecdotal claims that Amazon has a large internal AD.