{"id":15010,"date":"2009-11-20T17:32:36","date_gmt":"2009-11-20T21:32:36","guid":{"rendered":"http:\/\/www.bu.edu\/tech\/?page_id=15010"},"modified":"2021-07-21T13:36:43","modified_gmt":"2021-07-21T17:36:43","slug":"printers","status":"publish","type":"page","link":"https:\/\/www.bu.edu\/tech\/about\/security-resources\/bestpractice\/printers\/","title":{"rendered":"Securing Printers"},"content":{"rendered":"<p>Most modern printers come with support for either wired or wireless network connectivity (or both!) to enable easy printing from all your networked devices.\u00a0 The products are designed to be easy to use: Just plug them in, put a CD into a computer, run the setup utility, and you&#8217;ll be good to go!<\/p>\n<p>Unfortunately, this ease of use is provided at the expense of the security of the devices.\u00a0 Information Security has been diligent in telling systems administrators to turn off services on their servers, but printers have gone largely unnoticed.\u00a0 Many printers now run ftp servers, web servers, nfs and smb file shares, snmp, telnet, and dozens of other unnecessary services.\u00a0 These services put the device at risk.<\/p>\n<h3>What is the risk?<\/h3>\n<p>When asked, people often think that the consequences of an unsecured network printer might be &#8220;spam&#8221; in the form of unwanted printouts, or perhaps a &#8220;cute&#8221; message on the printer&#8217;s LCD screen.\u00a0 A more malicious attacker might reconfigure the printer&#8217;s network address to have it conflict with another address that is in use.\u00a0 The risks go deeper than these nuisances, however.\u00a0 In some cases it is possible for Internet users in remote locations to retrieve print jobs that are in progress, or even those that are already complete!\u00a0 Imagine the surprise of finding that your budget proposal, student grades, or salary review being read by someone in another country!<\/p>\n<p>On May 21, 2007 the Incident Response Team issued <a href=\"http:\/\/www.bu.edu\/security\/advisories\/bu-adv-2007\/BU-2007.01.html\">a security advisory<\/a> that discusses privacy and security issues involving printers.<\/p>\n<h3>Addressing the risk<\/h3>\n<p><strong>Step 1: Secure your printer.<\/strong><\/p>\n<p>All printer vendors offer some sort of advice on how to secure the printer you just bought.\u00a0 See the vendor section below for a place to get started.<\/p>\n<ul>\n<li>Use Network Access Control Lists (ACLs) or Printer Firewall Rules to only accept network traffic from the <a href=\"https:\/\/www.bu.edu\/tech\/services\/security\/network\/firewall\/campus\/ipspace\/\">BU Campus IP Address Space <\/a>. Check the product manual for settings.<\/li>\n<li>Disable protocols that aren&#8217;t need for printing such as SMB, SSH, FTP.\u00a0 Typically only DIPRINT\/JetDirect\/RAW, IPP, LPR are required for printing<\/li>\n<li>Set SNMP to read only to prevent device setting modification<\/li>\n<li>Change default password of administrator account<\/li>\n<li>\n<div>Disable IPv6, as some printer firewall\/ACLs don&#8217;t block this traffic<\/div>\n<\/li>\n<li>Update device Firmware<\/li>\n<\/ul>\n<p><strong>Step 2: Move your printer to non-routable addresses<\/strong><\/p>\n<p>Printers, as well as file servers, can be protected by putting them on IP Addresses that cannot be routed over the Internet.\u00a0 These addresses, often called &#8220;10-net addresses&#8221; because they are of the form 10.x.y.z, can be established for all departments on the Charles River Campus and can be made accessible from anywhere on campus, including via our VPN services, but are always inaccessible from off-campus.\u00a0 This can be a huge win for security.<\/p>\n<p><strong>Step 3: Request an Audit!<\/strong><\/p>\n<p>We have the ability to remotely audit your printer and see what services are running that might be exploited.\u00a0 Doing so requires some coordination as we may cause your printer to print garbage or even hang it so that it requires a power cycle to be used again.\u00a0 In the end, however, we can give you a good impression of how secure, or not secure, your device is.<\/p>\n<p><strong>Step 4: Tell us about your experiences!<\/strong><\/p>\n<p>There are so many printers out there we can&#8217;t possible write a guide for all of them.\u00a0 However, if you have a printer and have figured out how to lock it down, let us know!\u00a0 We&#8217;d be happy to help you share your procedures.<\/p>\n<h3>Vendor Resources<\/h3>\n<table style=\"width: 75%;\" border=\"1\">\n<tbody>\n<tr>\n<td width=\"40%\"><strong>Manufacturer<\/strong><\/td>\n<td width=\"60%\"><strong>Web Site<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Canon<\/td>\n<td><a href=\"http:\/\/www.usa.canon.com\/\">http:\/\/www.usa.canon.com<\/a><\/td>\n<\/tr>\n<tr>\n<td>Epson<\/td>\n<td><a href=\"http:\/\/www.epson.com\/\">http:\/\/www.epson.com<\/a><\/td>\n<\/tr>\n<tr>\n<td>Hewlett-Packard<\/td>\n<td><a href=\"http:\/\/www.hp.com\/\">http:\/\/www.hp.com<\/a><\/td>\n<\/tr>\n<tr>\n<td>Ricoh<\/td>\n<td><a href=\"https:\/\/www.ricoh-usa.com\/en\/products\/printer-security\">https:\/\/www.ricoh-usa.com\/en\/products\/printer-security<\/a><\/td>\n<\/tr>\n<tr>\n<td>Toshiba<\/td>\n<td><a href=\"http:\/\/toshiba.com\/\">http:\/\/toshiba.com<\/a><\/td>\n<\/tr>\n<tr>\n<td>Xerox<\/td>\n<td><a href=\"http:\/\/www.xerox.com\/\">http:\/\/www.xerox.com<\/a><br \/>\n<a href=\"http:\/\/www.xerox.com\/information-security\/product\/enus.html\">Xerox Product Security Guidance<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Most modern printers come with support for either wired or wireless network connectivity (or both!) to enable easy printing from all your networked devices.\u00a0 The products are designed to be easy to use: Just plug them in, put a CD into a computer, run the setup utility, and you&#8217;ll be good to go! Unfortunately, this&#8230;<\/p>\n","protected":false},"author":2620,"featured_media":0,"parent":6549,"menu_order":7,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/15010"}],"collection":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/users\/2620"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/comments?post=15010"}],"version-history":[{"count":10,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/15010\/revisions"}],"predecessor-version":[{"id":136267,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/15010\/revisions\/136267"}],"up":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/6549"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/media?parent=15010"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}