Educause Security Discussion mailing list archives

Re: " ...colleges and universities all over the United States found that their network printers were spilling out Auernheimer’s flyer."


From: Matthew Trump <M.Trump () KENT AC UK>
Date: Tue, 29 Mar 2016 13:55:33 +0000

What justification was provided for connecting printers to the internet at these institutions?

-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Shawn 
Merdinger
Sent: 28 March 2016 15:14
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] " ...colleges and universities all over the United States found that their network printers were 
spilling out Auernheimer’s flyer."

Lock down your printers, lest Weev (and now countless others) will troll you with racist print jobs.

http://motherboard.vice.com/en_ca/read/hacker-weev-made-thousands-of-internet-connected-printers-spit-out-racist-flyers

https://storify.com/weev/a-small-experiment-in

Fwiw, I've a couple slides in a 2014 Educause preso detailing this vector exactly...down to the shell script...and one 
slide in particular that will most certainly get you the backing from C-level execs to remove your printers from public 
IP (child pr0n, hostile work environment lawsuits, every public IP printer now a state/federal crime scene).

http://www.educause.edu/sites/default/files/library/presentations/SEC14/SESS08/shodan_for_edu_educause_security_conference_2014_public_version_shawn_merdinger.pdf

Cheers,
--scm

Current thread: