Printers are spontaneously printing odd "SQL" strings
discussions.apple.com
discussions.apple.com
My printer has a dumb little print server running an embedded flavor of Linux and a publicly known hard-coded (!) root password. While mine is going to the slag heap sooner or later for that and several other fundamental problems, you can guess that many many more of them are out there just waiting to be taken for a ride.
These dumb little boxes may be underpowered, but once you get inside and set them up to forward packets for you, their raw CPU speed becomes less of an issue. You can run all of the fun attacks from a "real" machine and just let it bounce you to the inside world.
Hypothetically speaking, of course.
[0]: http://events.ccc.de/congress/2011/Fahrplan/events/4871.en.h...
[1]: http://events.ccc.de/congress/2011/Fahrplan/events/4780.en.h...
So yeah, printers at least were a big gaping hole in the late 90s and early 00s.
This is exactly the opposite of what many security experts recommend: ideally all devices should be secure regardless of whether the network they're on is secure or not. With more and more devices offering remote-Internet-access functionality every day, this principle of security is becoming ever more fundamental.
Bruce Schneier's personal WiFi network at home is fully open, because -- in his own words: "If I configure my computer to be secure regardless of the network it's on, then it simply doesn't matter. And if my computer isn't secure on a public network, securing my own network isn't going to reduce my risk very much."[1]
Like rachelbythebay, I'm also waiting for the great network printer security apocalypse.[2]
--
[1] http://www.schneier.com/blog/archives/2008/01/my_open_wirele...
[2] http://news.ycombinator.com/item?id=4412522
--
UPDATE: Just for the heck of it, I ran a fairly fast scan (nmap -T4 -A -v -PE [IP address]) on an HP all-in-one printer accessible over my LAN, and there were a LOT of open ports -- see pasted results below. I then pointed my browser to port 9100 on the printer, which instantly printed the HTTP headers without complaint. The printer's configuration page reports that it is "secured" by an administrative password.
PORT STATE SERVICE VERSION
80/tcp open http HP PhotoSmart/Deskjet printer http config (Virata embedded httpd 6_0_1)
139/tcp open netbios-ssn?
6839/tcp open tcpwrapped
7435/tcp open tcpwrapped
8089/tcp open tcpwrapped
9100/tcp open jetdirect?
9101/tcp open jetdirect?
9102/tcp open jetdirect?
9110/tcp open unknown
9220/tcp open hp-gsg HP Generic Scan Gateway 1.0
9290/tcp open hp-gsg IEEE 1284.4 scan peripheral gateway
9500/tcp open unknown --allports (Don't exclude any ports from version detection) .
By default, Nmap version detection skips TCP port 9100 because some
printers simply print anything sent to that port, leading to dozens
of pages of HTTP GET requests, binary SSL session requests, etc.
This behavior can be changed by modifying or removing the Exclude
directive in nmap-service-probes, or you can specify --allports to
scan all ports regardless of any Exclude directive.
PS I think the "-A" and "-T4" is redendant. I think aggressive mode sets the timing to 4 among other things.PS. No, I was not trying to replicate what happened -- just trying to get a quick sense of how many ports are open. Sorry for the misunderstanding.
When you posted the nmap scan report I thought you were trying to replicate what had happened. Otherwise its not really news that print devices have a lot of ports open.
In order to not waste paper you can just have one or two sheets in the tray...
This is because every device acts confused, hangs or produces cryptic errors when facing denied access; restricted resources prevent you from understanding why the access was denied and how to open it; changes in network topology lead to problems that only stumbled over much later; and it's extremelly hostile on guests who spend half a hour trying to configure.
It's untractable.
Most of user crypto has same set of problems btw.
This sounds somewhat similar.
My thinking is router manufacturers will probably not do this. Because if you don't have a firewall and expose all your computers to the Internet via IPv6, Everything Just Works (assuming the rest of the world uses IPv6, which will be a close approximation to the truth in the future world we're talking about). Which means those insecure routers will have a better user experience for the vast majority people in the market, who don't have a clue about networking and would rather gouge their eyes out than learn about it.
Routers currently don't do this for IPv4 for a good and simple reason: When you're assigned a single public IP by your ISP, there's no way to automagically tell which host is supposed to receive an inbound connection.
The "good" news (from a security standpoint) is that the most clueless will probably be using IPv4 for a long time to come, helped along in their foot-dragging by the eventual release of IPv4 space by early adopters of IPv6-only.
And for services running behind that router there'll probably be some kind of PNP port opening (so there can be "PLAY WITH FRIENDS EASILY" next to those other stickers)
Assuming your IP address will remain secret seems naive.
Also, this assumes your IP address within your /48 is randomly chosen. Common user choices (or router implementations) might not default to random choices, or the randomness might not actually be very random.
many access points (I think) now provide a feature where they can run multiple SSIDs. so if you're savvy, you can turn on a guest-only open wifi for when you have visitors, and turn it off when they leave. kind of like a guest key for your spare room!
he leaves himself open to a bunch of local-only attacks
What kind of attacks might those be?Consider the case of a computer connected to the network with no open ports (other than say, 25 for SSH), with a properly configured firewall, that connects to the Internet through a VPN and with an operating system that auto-updates itself.
What could you do to it from inside the network?
As a celebrity, he probably has some substantial de facto immunity against this. (One blog post, and "the Internet" will show up on his side.) The rest of us... not so much.
[Edit] This is the case in Germany. http://ratgeber-recht.welt.de/offene-wlan-hotspots-sind-zula... You may have your own hotspot but you may be liable for misuses.
Also, it's increasingly apparent that other jurisdictions will increasingly attempt -- or be used -- to ensnare people in more... "permissive" jurisdictions. Don't like the venue? Sue -- or prosecute -- them in another venue.
On the one hand, I feel sad that my response to this is to "close up" connectivity. On the other hand, I for one don't have the resources with which to liberally take such situations on.
man-in-the-middle the VPN
man-in-the-middle administration of the router / wireless access point, which frequently is done without ssl
That said, I tell people to point their browser all the time but maybe that's because I've been using browsers since 1994. :)
> "Both of our printers have public IP addresses"
It looks like the printer are publicly accessible, and some automated tool (nmap?) is just scanning them for vulnerabilities, open ports, or similar. Not too surprising really.
Don't expose your printers to the web without a strict firewall or VPN/reverse proxy!
--allports (Don't exclude any ports from version detection) .
By default, Nmap version detection skips TCP port 9100 because some
printers simply print anything sent to that port, leading to dozens
of pages of HTTP GET requests, binary SSL session requests, etc.
This behavior can be changed by modifying or removing the Exclude
directive in nmap-service-probes, or you can specify --allports to
scan all ports regardless of any Exclude directive.http://ids.cs.columbia.edu/sites/default/files/CuiPrintMeIfY...
1. telnet <printer> 9100
2. Type a hello world message.
3. Close the connection
4. The printer will print out whatever you typed. At least it did for me.
GET http://www.baidu.com/ HTTP/1.1
Host: www.baidu.com
Accept: /
Pragma: no-cache
User-Agent:
I contacted ITS about it (obviously, you shouldn't be able to print from outside the university) but they haven't really given it any work. It surely is a security hole, and a minor waste of ink & paper.
Confuses the heck out of your coworkers.
I think it was the first python script I wrote.
I'm certain you're correct. I've seen many SQL injection attacks, and not one of them has ever labelled itself as such.
I think this shows a defect in the blind voting we've had here for the last year or so. There's no way this off-hand comment is worth that much karma, but nobody can see that I'm being overcompensated for it.
(Sorry for the OT meta-post)
'; DO $$ BEGIN RAISE NOTICE 'Commencing SQLI.'; END $$; -- Use acronym "SQLI" for stealth reasonsEdit: That's probably what it is. A port scanner climbed through port 9100 and hit the JetDirect port on the printer, which prints whatever raw data it is given. Cool find!
Print Me If You Dare: http://www.youtube.com/watch?v=njVv7J2azY8
Hacking MFPs: http://www.youtube.com/watch?v=PqL5P46m_zQ
EDIT: Beaten by 4 hours. Oh well.
If you don't know the IP address of the printer, you can normally get them to print out a diagnostics page by fiddling with the buttons, and this page will contain that information. So far I have always succeeded at logging in with guest credentials.
To network admins who don't want people bypassing their queues: vlan your printers!
...so I set it up as a printer and printed a bunch of lolcats to it.. A few days later it wasn't accessible any more =)
Seriously?! Ignoring the fact that I can't remember when I last print something, who needs to print to their house from the internet? Can't they just print it when they get home?
I took the envelope and looked at it... It was a bunch of prints of gay porn and gay porn websites.
After a few minutes of digging, it was revealed to be one of the directors in the company had printed them late the night before. Checking the badge system he wasn't in the building. Checked VPN logs and he was logged in at the time.
He was mistakenly on VPN from his house and printed stuff that went to his default printer which happened to be the one in the office.
He was previously thought to be a married straight guy.
Not sure why this is relevant. Are you saying Lockheed has/had a don't-ask-don't-tell policy?
- They have expensive software on a computer in one place that does not have a printer, and a printer at home without the software - A couple that works from home likes to collaborate while one of them is one the road, with one printing stuff directly to home after meeting with clients - They like to print stuff from work while things are on their mind (itineraries, boarding passes, etc.) so that they don't have to think about logistics once they're home with family - etc.
Beware the sentence that starts with "Can't they just..."
From the email:
"....However, I've noticed a problem now that I've put this into production. When it scans a network printer, the printer spews out garbage, I have a couple wads of paper on my desk with one or two lines of garbage at the top of each page."
If you throw ascii at a jetdirect printer, it will generally just print it out for you. I've used this to debug printers before, as well as to goof around with my coworkers a bit.
I don't know if they just hit it by luck or if they were actively looking for/testing/saving open VNC servers.
My home servers get SLAMMED on a daily basis by a whole wonderful plethora of bots. Most recently has been Muieblackcat. Going on the whole salary analogy: I'd make my current salary plus a bit if I had a penny for ever scan on the box in my living room. I keep the Ukrainian IP's off my blacklist just for fun. Nothing sensitive on the server, just my web playpen. I kind of hope that one of these exploits works one day so I can see where I've slipped up.
Anyway, there's a reason to travel with your own locked-down router and to never connect through anyone else's connection directly, especially if you're running Windows. Even that's not foolproof, but at least you've got an Angry Bouncer protecting the Windows Club. Windows Update connections totally feel like spotlights and booming bass.
I'm guessing that Windows Firewall (included in SP2) buys you some time, but I can't see unpatched system lasting very long.
Many printers will simply print whatever data comes into certain ports. Have seen similar behavior many times when running web scanning against a printer accidentally instead of a webserver.
The printer panopticon. Oh art school.
Oh "BBrother" what an ironic comment this is .. /takes off paranoid hat
Most probably it comes from someone running penetration testing tools against the printer on the network
http://www.symantec.com/connect/blogs/trojanmilicenso-paper-... http://www.symantec.com/docs/TECH190982 http://isc.sans.edu/diary.html?storyid=13519
Although this mostly looks like scans.
https://play.google.com/store/apps/details?id=com.angryhacke...
* Apple's stuff is incredibly overpriced
* Apple never invented anything, it's just good at marketing
* Apple's lawsuits are all based on rounded rectangles
* Xerox invented the GUI from scratch and it was perfect
* Anyone who uses an Apple device is a hipster fanboi cultist
Also: sarcasm is like violence -- any problem it can't solve just requires more sarcasm.
Apple USED to be good at marketing. Have you seen those new ads? The ghost of Steve just barfed in his mouth a little bit. Quick! Someone call Justin Long and John Hodgman, that was working okay...
Rounded rectangles are the new lucite, and therefor not relevant in any way. Apple's lawsuits were based on Steve Jobs being a big baby about how well Android was selling. Now? Who knows how the Apple lawsuit of the day gets kicked off, but you can bet it involves Androids (and not the Star Trek variety).
Now you're just being thick, the first GUI was done by Doug Engelbart (Stanford Research) in '68. It was perfect. Any CS student who took an HCI knows that. Extra points if you know what HCI stands for and don't have to google Engelbart to verify, but I bet you do :)
Some people who use Apple devices just want some of the discretionary income that hipster, fanboi (and fangrl, you sexist) and cultists seem quite happy to part with. Will that be cash or credit?
Apple has made bad ads before and will make bad ads again. I do think the celebrity/Siri and genius ads are disappointing, but I'm not convinced Apple is no longer any good at marketing because it produced some bad ads.