Hackers use Google to access photocopiers

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Hackers are using search engines to watch what people photocopy.

Using Google hacks -- requests typed into the search engine that bring up cached information on networks -- hackers are discovering and using login details for networked photocopiers so they can watch what is being copied.

"You don't have to be a genius to do this," said Jason Hart, security director at Whitehat UK. "You can see what people are photocopying on your monitor. You just have to search for online devices on Google."

Google stores billions of Web URLs and information sent from Web servers. Some Web servers, if configured incorrectly or left to default, can accidentally broadcast network information, such as IP addresses, login details and device information. Google, like many other search engines, stores this information, which can be recalled at any time.

"Essentially Google caches everything on the Web," said Hart. "By inputting commands into Google you can extract information and use it as a reverse-engineering tool."

Hackers have been using Google hacks for some time -- exploiting photocopiers is only a recent example of compromising online devices. Hackers also use the search engine to view logged conversations on the Google computer groups list. In these, techies often share network information, such as logins, and their company domain name when they post their email address with a message.

Hart added: "If you look at a firm's domain you can see all their security questions which means you can see their network infrastructure. [Hackers] wait for people to come along and say: 'I've been put in charge of security but don’t know much. Can you help me?' The hacker helps out and gets their trust until they get the passwords to the firewalls."

Hart advised that security staff should regularly check Google for cached information on their firms' domain names. He said that if using public forums to solve problems, participants should sign in using an anonymous e-address.

"You can ask Google to take certain information off its site," said Hart. "It's always worth taking a look at. It's a simple check, but worthwhile."

Talkback

Absolute rubbish, you can open a web page but not the documents.
Prove it otherwise.

via Facebook 28 September, 2004 03:07
Reply

My boss saw this article and now he's asking me to find out if our products are vulnerable (we make printers/photocopiers), but there is not really much detail in the article.
What commands would have to be entered from Google? Where are the photocopies being stored prior to being accessed by "hackers"?
If you are willing to tell we where you got this information, it would make my job a lot easier.

Thanks,
Ryan W. Paul

via Facebook 28 September, 2004 10:16
Reply

Don't we have enough real security concerns in the world without articles like this? The information in this article is misleading, at best, and the implications it makes are simply false.

The implication is that one can simply "search for online devices" and "what what people photocopy" is entirely unfounded.

Yes, one can obtain user credentials from web servers that are not properly secured--but doing so is not trivial. And using those credentials to get some amount information about photocopied jobs is theoretically possible--if the photocopier is available on the network, improperly secured and improbably designed--all of which are *large* IFs.

There's enough confusion and concern over security and technology in the world. ZDNet's choice to publish bunk like this and fan the flames of confusion is unfortunate.

via Facebook 28 September, 2004 10:59
Reply

This article made very little sense. I was unable to understand the connection between photocopiers and google.

via Facebook 28 September, 2004 21:26
Reply

Go read *this* ZDNet article if you want specifics. I tried it and oh my are there are lot of IIS servers not protected.

As for what kind of photocopiers, they're talking about multifunction or all-in-one devices that are connected to a network which is connected to the Internet OR they contain a fax option and have a modem installed.

via Facebook 29 September, 2004 17:41
Reply

Please provide link for the referenced article. Thanks!

via Facebook 30 September, 2004 15:10
Reply

The comments are a cause for concern since it shows that many people responsible for system maintenance do not understand some of the fundamental aspects of systems and networks. A few comments for them to consider

As networks become more intergrated and exposed to the Internet at large. Hackers using Google can locate systems that are online and have not been correctly configured or slack processes have revealed sufficient information for their system to be exposed to the Internet in the public domain.

Most systems these days manage objects these may be files, printers, scannerrs etc. This includes printers. Networked printers may be limited in their use by users but have you protected the spool space. Here is where much sensitive information may reside and lack suitable protection.

I think the object of the item was to suggest that administrators occassionally search google for reference to their domain name. There may be a nasty shock for you if your system is not correcty configured if so find an consultant experienced in securing systems starting with a firewall and then how you system manages logon processes

via Facebook 4 October, 2004 06:44
Reply

I found it by searching for "photocopier" on zdnet, but it seems to be identical.

via Facebook 4 October, 2004 15:32
Reply

It is POSSIBLE that a hacker gets user credentials from a not fully
secured web server, but only a few of those credentials lead to
useful information specialy about photocopiers, there are alot of
elements starting from design ending at security that all take
action in such a matter.
Yes "THEORETICALLY" it is "POSSIBLE", but "IN ACTION" it is
"ALMOST IMPOSSIBLE" and it doesn't even worth trying searching
such a huge load of data.

via Facebook 20 October, 2004 00:46
Reply

I can only talk for Canon photocopiers who my company Digipro supply but this simply is not possible as you cannot scan and copy at the same time.

http://www.digipro.co.uk

via Facebook 28 October, 2004 23:40
Reply

dude, copiers now have ethernet cards in them. they work as networked office printers. they can also scan documents too. they have document management services such as put a document on the glass, press the button, scan it, it saves it to a hard drive inside the copier, and then go to your desk, browse to the copier's ip and retrieved the scanned document so that you can file it, attach it to email, paste it in word, whatever. If a company's net is open, google will spider their internal network and find the stuff and cache it on google's search engine and you can see it in google's cache. understand??

via Facebook 31 October, 2004 09:45
Reply

http://tstokke.eerc.und.nodak.edu/parser.cgi?index2.html

Try that idiot!

via Facebook 27 November, 2004 11:24
Reply

OK lets try and put this one to bed and by the way I am only speaking on behalf of Canon Photocopier Machines my company Digipro sells (did I mention that already).

A fully featured canon digital copier has the facility to copy print scan fax and email a document. The user chooses what he wants to do with a document. If they choose to copy, the canon copier prints the image. That's is why the article is incorrect with Canon as there can never be a vulnerability whilst photocopying because the own users network doesn't even have access whilst photocopying.

If the user chooses to scan it will scan and dependent on which model canon you have it will either send directly over your network "push scanning" or you can retrieve the document from the copier from your pc "pull scanning".

If user chooses to email or fax the document will be sent accordingly.

On any files emailed or scanned a user should take normal security precautions on there network. I use Zone alarm.

In response to post to Fiery website. Fiery is a print server renowned world wide and capable of handling large graphic files. Again its not used at all when photocopying.
In the present canon market fiery is only used for colour printing and very high volume black and white printing, they have also introduced a scan facility.

Regards

Greg
http://www.digipro.co.uk

via Facebook 2 December, 2004 00:36
Reply

It is possible to extract sensitive information from photocopiers, but it depends on how they were installed onto your network and the make of the photocopier.

via Facebook 20 June, 2005 14:17
Reply

Human stupidity and social engineering is the greatest flaw. Hacking? Pfft. Any techie can do simple hacking. Only flaw I see here is human stupidity in trusting others with sensitive information.

via Facebook 4 July, 2005 23:37
Reply

I think that you cannot access photocopiers from a search engine without having network permissions. who would want to see the details (not images) of files that have been printed to a photocopier.

I sell copiers and have never heard anything like this from over 1000 clients.

Jon Tribe
http://www.falconcopiers.co.uk

via Facebook 3 July, 2006 10:00
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

2 hours ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

3 hours ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

3 hours ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

8 hours ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store
Aigars Mahinovs

It has been shown time after time that if there is an author store that sells the songs at even 1$ per song and gives you a high-quality digital...

9 hours ago by Aigars Mahinovs via Facebook on Copyright isn't working, says European Commission
awbMaven

""As a result of Butyka's alleged conduct, researchers were unable to use the computers for more than two months while NASA removed the malicious...

12 hours ago by awbMaven on US indicts Romanian over NASA climate change hack
subhorup

It simultaneously worries me and uplifts me that a self-proclaimed group of internet activists name themselves after Indian mythical figures....

20 hours ago by subhorup on Anonymous activists release PCAnywhere source code
naviathan

It's actually far easier to work anonymously on the internet than you think. With tools like Tor bouncing your traffic around the world before...

23 hours ago by naviathan on Anonymous activists release PCAnywhere source code
Agnostic_OS

1000272134 and bluedalmatian with you both there but then I'm still in 10.04 land (and happy with it)

23 hours ago by Agnostic_OS on Ten factors that make Ubuntu 11.10 a hit
apexwm

Interesting article and definitely see your points on the products mentioned. One of the top products for our Help Desk (approximately 20% of all...

1 day ago by apexwm on Ten flawed products that derail productivity
Paul Hutchinson

Absolutely - this should obviously not be handled my isp - but handled by their hosting operator. What's been suggested here is that my isp police...

1 day ago by Paul Hutchinson via Facebook on MPs urge ISPs to take down terrorist material
Techs UK

Looks like a great phone. I don't notice any deficiencies in WP7. used IOS before, that's pretty good. I don't spend much time in Apps, all i need...

1 day ago by Techs UK on Nokia pins US 're-entry' hopes on Lumia 900
Larry Bloggy

Now with the help of these apps you are always synced with MS outlook while on the move. Just download apps like xobni or outlookreflex and get...

1 day ago by Larry Bloggy via Facebook on Outlook Social Connector beta 2 and the LinkedIn connector
mike40g123

Your details are wrong. The version currently being made is the one with 2 USB ports, 256MB RAM and a network port. This is the Model B. The...

2 days ago by mike40g123 on Raspberry Pi boards set to go on sale
Moley

The thing that has been puzzling me for quite a while is how Anonymous can remain anonymous whilst not only being active on the Internet but also...

2 days ago by Moley on Anonymous activists release PCAnywhere source code
Don Dilly

If what Semantec is saying is rue, that is even worse and shows a complete disregard for thier users. If what Anonymous claims is true and the...

2 days ago by Don Dilly via Facebook on Anonymous activists release PCAnywhere source code
MattChurchy

Didn't seem particularly biased to me either. Oh though you might have mentioned some other competitors with free search and email services...

2 days ago by MattChurchy on Time for an evil umpire: Google, Microsoft & privacy
Simon Bisson and Mary Branscombe

James - exactly as much as anyone paid you for your comment; I don't feel that I need to say that I'm independant and unbiased, but just for you...

2 days ago by Simon Bisson and Mary Branscombe on Time for an evil umpire: Google, Microsoft & privacy
Carl White

Once they realise symantec are willing to pay real money, they will simply keep extorting, unless of course symantec/authorities can use the...

3 days ago by Carl White via Facebook on Symantec offered hackers $50k in source code sting
Jonathan Hassell

You can find more information on BS 8878 by Jonathan Hassell its lead-author at http://www.hassellinclusion.com/bs8878/ The page includes a...

3 days ago by Jonathan Hassell on BSI publishes first British web accessibility standard