[Micronet] Printer Spam Widespread?

classic Classic list List threaded Threaded
4 messages Options
Reply | Threaded
Open this post in threaded view
|

[Micronet] Printer Spam Widespread?

John McChesney-Young
This morning our office printer (an HP LaserJet) had a printout in the
hopper beginning, "Hi! This is an advertisement of really cool
software cracking service." They offer their services for $500
(usually), payable only by Bitcoin, they're only reachable via
BitMessage, and the details were followed by 5 1/2 pages of
already-cracked software, none of which I'd ever heard of - although
given my level of knowledge that counts for very little. (Amusingly,
one entry was for "Microwave Office 4.0.")

When I got back from lunch I found a co-worker had brought up two
copies of the same ad that had been sent to the color printer
downstairs.

Have other people on campus seen or heard of this happening? It's a
first for us in the almost three years I've been here.

John

--
John McChesney-Young, Administrative Assistant
History of Art Department, 416 Doe MC6020
U. C. Berkeley, Berkeley CA 94720-6020
[hidden email] // voice 1-510-642-5511 // fax 1-510-643-2185

 
-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.
Reply | Threaded
Open this post in threaded view
|

Re: [Micronet] Printer Spam Widespread?

Beth Muramoto
John,

I got the exact same thing on a printer in one of our units. So far only the one printer was affected, but it was brought to my attention this morning and I have been meaning to post to Micronet to poll if others had received it.

It was worrisome. All of our administrative printers have static IPs assigned to them and faculty do print remotely using them so we have given the IPs to them to accommodate, but I wondered if maybe we'd have to change the IPs to prevent this which would be really inconvenient.

Thanks for asking.

Beth

On Thu, Oct 9, 2014 at 3:21 PM, John McChesney-Young <[hidden email]> wrote:
This morning our office printer (an HP LaserJet) had a printout in the
hopper beginning, "Hi! This is an advertisement of really cool
software cracking service." They offer their services for $500
(usually), payable only by Bitcoin, they're only reachable via
BitMessage, and the details were followed by 5 1/2 pages of
already-cracked software, none of which I'd ever heard of - although
given my level of knowledge that counts for very little. (Amusingly,
one entry was for "Microwave Office 4.0.")

When I got back from lunch I found a co-worker had brought up two
copies of the same ad that had been sent to the color printer
downstairs.

Have other people on campus seen or heard of this happening? It's a
first for us in the almost three years I've been here.

John

--
John McChesney-Young, Administrative Assistant
History of Art Department, 416 Doe MC6020
U. C. Berkeley, Berkeley CA 94720-6020
[hidden email] // voice 1-510-642-5511 // fax 1-510-643-2185


-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.



--
***********************************************
Beth Muramoto
Computer Resource Specialist
Graduate School of Education
University of California, Berkeley
1650 Tolman Hall
Berkeley, CA 94720
Email:  mailto:[hidden email]
Phone:  (510) 643-0203 
Fax:  (510) 643-6239

“Finish each day and be done with it. You have done what you could. Some blunders and absurdities have crept in – forget them as soon as you can. Tomorrow is a new day. You shall begin it serenely and with too high a spirit to be encumbered with your old nonsense.”
                            -Emerson

This is the essence of forgiveness. You can't change what happened but you can make sure it doesn't have the power to prevent you from being happy tomorrow.
                           
                             -Paul Boese

“Kind words do not cost much yet they accomplish much.” 

                            -Blaise Pascal


***********************************************


 
-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.
Reply | Threaded
Open this post in threaded view
|

Re: [Micronet] Printer Spam Widespread?

Keenan Parmelee
In reply to this post by John McChesney-Young
Hi John,

Most printers have the ability to prevent administration and printing from IPs outside specified network(s).  I would definitely suggest configuring your printers to allow printing only from campus IPs.  To address Beth's concern about printing from off campus, my suggestion is to ask those users to connect via VPN first if this is a requirement.

Changing IPs won't do much, as these are likely the result of automated network scans.  You should also ensure that your printers are using passwords other than default and allow remote administration from only your local subnet.  How to do this varies from model to model, but is pretty straightforward once you're in the admin interface.


On Thu, Oct 9, 2014 at 3:21 PM, John McChesney-Young <[hidden email]> wrote:
This morning our office printer (an HP LaserJet) had a printout in the
hopper beginning, "Hi! This is an advertisement of really cool
software cracking service." They offer their services for $500
(usually), payable only by Bitcoin, they're only reachable via
BitMessage, and the details were followed by 5 1/2 pages of
already-cracked software, none of which I'd ever heard of - although
given my level of knowledge that counts for very little. (Amusingly,
one entry was for "Microwave Office 4.0.")

When I got back from lunch I found a co-worker had brought up two
copies of the same ad that had been sent to the color printer
downstairs.

Have other people on campus seen or heard of this happening? It's a
first for us in the almost three years I've been here.

John

--
John McChesney-Young, Administrative Assistant
History of Art Department, 416 Doe MC6020
U. C. Berkeley, Berkeley CA 94720-6020
[hidden email] // voice 1-510-642-5511 // fax 1-510-643-2185


-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.


 
-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.
Reply | Threaded
Open this post in threaded view
|

Re: [Micronet] Printer Spam Widespread?

Jon Johnsen
If you don't give the printer a default gateway, it can't be accessed from outside its subnet. (At least that's how I remember it.)

On Thu, Oct 9, 2014 at 3:37 PM, Keenan Parmelee <[hidden email]> wrote:
Hi John,

Most printers have the ability to prevent administration and printing from IPs outside specified network(s).  I would definitely suggest configuring your printers to allow printing only from campus IPs.  To address Beth's concern about printing from off campus, my suggestion is to ask those users to connect via VPN first if this is a requirement.

Changing IPs won't do much, as these are likely the result of automated network scans.  You should also ensure that your printers are using passwords other than default and allow remote administration from only your local subnet.  How to do this varies from model to model, but is pretty straightforward once you're in the admin interface.


On Thu, Oct 9, 2014 at 3:21 PM, John McChesney-Young <[hidden email]> wrote:
This morning our office printer (an HP LaserJet) had a printout in the
hopper beginning, "Hi! This is an advertisement of really cool
software cracking service." They offer their services for $500
(usually), payable only by Bitcoin, they're only reachable via
BitMessage, and the details were followed by 5 1/2 pages of
already-cracked software, none of which I'd ever heard of - although
given my level of knowledge that counts for very little. (Amusingly,
one entry was for "Microwave Office 4.0.")

When I got back from lunch I found a co-worker had brought up two
copies of the same ad that had been sent to the color printer
downstairs.

Have other people on campus seen or heard of this happening? It's a
first for us in the almost three years I've been here.

John

--
John McChesney-Young, Administrative Assistant
History of Art Department, 416 Doe MC6020
U. C. Berkeley, Berkeley CA 94720-6020
[hidden email] // voice 1-510-642-5511 // fax 1-510-643-2185


-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.



-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.



 
-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.