Remote printer spam made easy

By Robert Vamosi on 10 January 2008

Tags: network | printer | remote | security | spam

Security researcher Aaron Weaver claims visiting a random Web site could send unwanted print requests to your nearest office printer.

In a paper published in November (PDF), and cited on Wednesday in a blog by Jeremiah Grossman of White Hat Security, Weaver demonstrates the code necessary for sending a formatted page to a remote network printer, and, in an another example, to an intranet addressable fax machine. Since most network printers are behind the corporate firewall and therefore don't have security enabled, Weaver says that a simple iframe added to an Internet Web site could cause an internal network printer to start printing remotely.

The attack is derived from techniques employed within a project called hacking network printers by Adrian "Irongeek" Crenshaw. Weaver notes that most network printers listen on port 9100 and that you can telnet to port 9100, type text, and, once you disconnect, the text will print remotely. That's fine, but he ventures further that network printers also accept PostScript and Printer Control language (PCL) code as well, which creates more interesting printouts.

Weaver writes "within the last year there have been new discoveries on attacking the intranet from the Internet. This involves setting an image tag or script tag to an internally addressable IP address and then the browser will request the 'image' resource. Several attacks can be accomplished; port scanning, fingerprinting devices, and changing internal router settings."

Add to that list, printer spam. "The attack could be initiated by creating a hidden iframe, and then creating a form and submitting the contents to the printer. Since the connection will not close, a setTimeout could be used to cancel the request so that the printer would print the request."

As a demonstration, Weaver shows how to send an ASCII-drawn advertisement for frogs, and later, using PCL, a message in 20-point Courier: "Your printer is mine!"

One positive use for this would be for the IT or HR department to send a persistent banner reminding employees about the company's printer use policies. A negative use would be to remotely spam all the printers on the local intranet.

At the end of the short paper, Weaver offers some remediation. "First always have an administrator password set on your printer. Secondly look at restricting access to the printer so that it only accepts print jobs from a centralised print server."

Like this article? Click below to send it to your mobile for free!

Be the first to comment on this article!

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • HP Photosmart C6380

  • Australia's giant e-waste recycling centre: Photos

  • Lexmark X7675

  • Epson Stylus CX5500

  • HP Photosmart C5380

  • Compact 3D printer lets you create your own toys

  • Lexmark's new printers turn green

  • Epson Stylus Photo TX700W

  • Dell V305w All In One

More articles »

Find the right printer

Brand
  • Multiple options can be selected

    • HP Photosmart C6380

      HP Photosmart C6380

      An excellent all-in-one printer for the home and small office, the C6380 pairs great photo printouts with an easy to use interface.

    • Lexmark X7675

      Lexmark X7675

      The Lexmark X7675 is a network-ready multifunction printer that promises much, but delivers little with its average print quality and frustrating setup process.

    • Epson Stylus CX5500

      Epson Stylus CX5500

      This affordable multifunction printer is suitable for light users and students, offering print, scan and copy capabilities for under $100.

    • HP Photosmart C5380

      HP Photosmart C5380

      Affordable all-in-one printers are a dime a dozen these days, but from the looks of it the C5380 may just be one of the best.

    • Epson Stylus Photo TX700W

      Epson Stylus Photo TX700W

      We know they can design cars, but can the Italians do printers? An industrial design team in Milan has turned its hand to Epson's latest Stylus Photo TX range.

    More reviews »

    Membership benefits

    Contact community members

    Contact community members

    Add friends or tech gurus to you contacts and send them messages. Sign up for a free CNET Australia membership now!