Category Archives: Printer Security

SNMP: the next DDoS Attack Vector

Good article.  Funny thing I wrote about this as part of my Thesis Project in 2004. https://isc.sans.edu/diary/SNMP%3A+The+next+big+thing+in+DDoS+Attacks%3F/18089

Posted in Printer Security, Security | Comments Off on SNMP: the next DDoS Attack Vector

Xerox in the security doghouse again

Looks like Xerox’s addition of Mcafee to its systems is exposing a few security problems. http://labs.opendns.com/2014/05/01/xerox-printer-beacons/

Posted in Printer Security, Security, Xerox | Comments Off on Xerox in the security doghouse again

Dangerous Prototypes » Blog Archive » 30C3 Video: Hardware attacks, advanced ARM exploitation, and Android hacking

Interesting video on hardware hacking an ARM system running Linux/Android.  Why is this a printer issue?  Well you would be surprised that allot of printers are embedded ARM based…and many run a favor of Linux, or other POSIX based OS. … Continue reading

Posted in android, Printer Security, Security | Comments Off on Dangerous Prototypes » Blog Archive » 30C3 Video: Hardware attacks, advanced ARM exploitation, and Android hacking

Linux.Darlloz Worm Targets x86 Linux PCs & Embedded Devices

Interesting article, the author seems more concerned about linux based routers but printers and MFD’s would fit this profile as well. http://www.darknet.org.uk/2013/12/linux-darlloz-worm-targets-x86-linux-pcs-embedded-devices/

Posted in Printer Security, Security | Comments Off on Linux.Darlloz Worm Targets x86 Linux PCs & Embedded Devices

Another Phishing attempt with Xerox Scanners in the name

The crackers are at it again, trying to see if folks will open a “scanned document” that says its from a Xerox scanner when it reality, its not.  The document of course has a payload to crack your box open. … Continue reading

Posted in Printer Security, Xerox | Comments Off on Another Phishing attempt with Xerox Scanners in the name

Xerox rolling patches out for scanner bug

Started yesterday.  So let the printer patching begin. http://feeds.gawker.com/~r/gizmodo/full/~3/gYXtrfOeNWE/xerox-is-finally-rolling-out-an-update-for-those-rogue-1187385352

Posted in Printer Security, Xerox | Comments Off on Xerox rolling patches out for scanner bug

HP fixes admin password stored in plaintext

Basically the password that would go across in http for a user or the admin was in HEX…not encrypted.  Sigh… http://www.theregister.co.uk/2013/08/08/hp_plug_password_leaking_printer_vuln/

Posted in Printer Security | Comments Off on HP fixes admin password stored in plaintext

Xerox Office Scanners could cause mis-scans of numbers

Interesting paper, basically the author found that if scanning with jpeg (JBIG) the compression could mess up a number or two so a 6 turns into an 8.  Solution, scan to PDF. http://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres_are_switching_written_numbers_when_scanning&2  

Posted in Printer Security, Xerox | Comments Off on Xerox Office Scanners could cause mis-scans of numbers

H.D. Moore voices issues about Embedded Systems

OK like duh.  Embedded Systems are full of security issues, and til it causes real harm to someone, nothing will happen. http://www.theregister.co.uk/2013/05/22/unpatched_embedded_system_threats/

Posted in Printer Security, Security | Comments Off on H.D. Moore voices issues about Embedded Systems

Whoops, sounds like HP left telnet open on its printers

Apparently no one audits HP’s product line for security issues before they go out the door. Sounds like development or CM forgot to take out the telnet debug port before the product was shipped and well…someone found it and must … Continue reading

Posted in Printer Security | Comments Off on Whoops, sounds like HP left telnet open on its printers