Over the past weekend, numerous users on the web shared images of a strange message that appeared on their printers. Apparently, a certain “Stackoverflowin” used a script to scan for open ports on connected printers and issue print commands. The first message was quite original, and even comical from some perspectives, but imitators quickly emerged demanding bitcoins. The good news is that the problem has a solution. The bad news is that it reminds us of that security catastrophe called the “Internet of Things”.

Your Printer Is Part of a Botnet: Printer Security Exposed
Printers

The Security Problem with the Internet of Things

Even the best intentions can lead to a security conflict, and if we need a striking example, we need look no further than the “Internet of Things”. Connecting everything to the web is supposed to be a good thing, allowing us to remotely manage various accessories and appliances (cameras, air conditioners, coffee makers, washing machines... the list goes on), as well as update their firmware, provided the manufacturer offers it. However, in the vast majority of cases, these manufacturers completely ignore basic security aspects, leaving their products exposed from end to end, waiting for someone with enough skill to find them. The rest depends on the level of access. A camera might enable its video feed, but there are many printers out there with port 9100 more open than the Arc de Triomphe, and this weekend their owners received a message...

Your Printer Is Part of a Botnet: Printer Security Exposed
Please close this port

The Attack: 150,000 Printers Exposed

“Your printer is part of a botnet” is not the best phrase we would like to see printed. Honestly, anything that comes out of the printer without our direct authorization is worrying. HP, Epson, Samsung, Oki, Brother, Canon, Lexmark, Aficio (Ricoh) and Konica Minolta are some of the affected brands, but beyond the message, no permanent damage has been reported, apart from one or two sheets of paper consumed. The mastermind behind the attack, operating under the pseudonym “Stackoverflowin”, explained that the whole job was reduced to writing an automatic script whose goal was to discover printers and send his message for 24 hours. Stackoverflowin estimates that he reached just over 150,000 printers, ranging from simple receipt-printing units to high-end models very popular in offices.

Your Printer Is Part of a Botnet: Printer Security Exposed
More than 150,000 exposed printers received instructions from the script to print the message

What You Should Do

In the end, the truth is that there is no botnet, and Stackoverflowin sent the message as a joke, but at the same time he asks affected users to close the ports, either on their printers or at the router level. It is logical to conclude that this will not be possible in all environments, because sending print jobs to port 9100 has some utility, but if the message is a surprise, then port 9100 should be closed, blocked, or disabled. Unfortunately, the differences between models do not allow a universal guide. Some provide the option through their software, while others require a telnet session. Why is it important to do this now? Because imitators have already appeared demanding bitcoins in exchange for “freeing” the printers.

Source: