<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:s="http://www.techrepublic.com/search" xmlns:dc="http://purl.org/dc/elements/1.1/"  xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
    <title><![CDATA[Discussion on HP Officejet All-in-One: An unlikely spy tool ]]></title>
    <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662]]></link>
    <atom:link rel="hub" type="application/rss+xml" href="http://pubsubhubbub.appspot.com/" />
    <atom:link rel="self" type="application/rss+xml" href="http://www.techrepublic.com/forum/discussions/102-335662/rss" />

    <description><![CDATA[]]></description>
    <language>en-us</language>
    <lastBuildDate>2013-06-19T13:44:46-07:00</lastBuildDate>
             

    <item>
        <title><![CDATA[tax time]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3503569]]></link>
        <description><![CDATA[That remote scan feature will net the bad guys lots of hits right around tax time when everyone is making copies of their tax forms.   I have an HP wireless printer, but I only turn it on briefly when I need to print something.  The rest of the time it is off.   But now that I know it can be a problem, I plan on adding a password and if I can figure it out, I will change the firewall settings on my wireless router to stop any external queries to the printer.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3503569]]></guid>
        <dc:creator><![CDATA[Al_nyc]]></dc:creator>
        <pubDate>Wed, 28 Sep 2011 11:16:28 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[If I weren't so lazy...]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3358092]]></link>
        <description><![CDATA[I'd configure my gateway on that. However, I do take a chance on a UPnP transaction occasionally to test my defenses and try a new application once and a while. After all it is a &quot;honey pot&quot;!This way, I also know what kind of environment my clients are coming from; so I know exactly what happened to them before I even get there. I never see most of them but once, so they are all on a new situation. They don't come back, after I've configured their PC and network, and given them a prep course on web-safety.Some would say I'm screwing myself out of a lot of money, but I'm just too lazy to let people fall on their own swords. I like to work smarter instead of harder. It gives me great satisfaction that the criminals have lost the battle too! ]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3358092]]></guid>
        <dc:creator><![CDATA[JCitizen]]></dc:creator>
        <pubDate>Tue, 14 Sep 2010 21:14:49 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[I make them beg.]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357491]]></link>
        <description><![CDATA[You want through the router or local firewall, you have to ask. No UPnP. No auto-trust.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357491]]></guid>
        <dc:creator><![CDATA[seanferd]]></dc:creator>
        <pubDate>Mon, 13 Sep 2010 21:03:56 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Thanks again]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357476]]></link>
        <description><![CDATA[Attending to it now.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357476]]></guid>
        <dc:creator><![CDATA[santeewelding]]></dc:creator>
        <pubDate>Mon, 13 Sep 2010 20:07:49 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Be sure ...]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357475]]></link>
        <description><![CDATA[to click on the common ports and all services ports. Doing both helps get a clearer picture of what is going on.Some ISPs issue firewall enabled modems though, so you may see a crappy firewall result, when your hardware firewall is working fine. I really hate ISPs that do this. But at least if you have a services gateway, you can tell who is knocking on the leaky front door in the monthly service reports.Kiwi Syslog has a really good utility that can watch firewall reports real time. I'm sure there are several free ones out there, but I've been around Kiwi so long, I feel comfortable with it.I just don't have the bucks yet for the pro version, but I'm happy with this one for now. You simply set your firewall with the interior IP that you want the reports sent to, and it will capture them in a data base form that can be interpreted pretty easily by code reference. I don't remember where I got the code list from; I think they are pretty standard.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357475]]></guid>
        <dc:creator><![CDATA[JCitizen]]></dc:creator>
        <pubDate>Mon, 13 Sep 2010 20:02:21 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Ooh -- GRC]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357472]]></link>
        <description><![CDATA[I've been checking in with that place forever.Never thought to do what you just said.Thanks, JC.Maybe it will tell me what I don't want to know.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357472]]></guid>
        <dc:creator><![CDATA[santeewelding]]></dc:creator>
        <pubDate>Mon, 13 Sep 2010 19:46:15 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Glad that didn't happen to me...]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357470]]></link>
        <description><![CDATA[it was bad enough when some junior &quot;Gee&quot; man lost a 500 item order with the new Oracle data base we had just acquired.I took particular pride in keeping all PLCs running smoothly in my area.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357470]]></guid>
        <dc:creator><![CDATA[JCitizen]]></dc:creator>
        <pubDate>Mon, 13 Sep 2010 19:38:44 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[I've learned...]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357449]]></link>
        <description><![CDATA[to do a GRC Shields UP! scan every time I add ANY software of hardware to any of my PCs. You never know when a driver is going to open up a port on the perimeter gateway device!Using Comodo as an interior software firewall has prevented this, but I still check anyway!]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3357449]]></guid>
        <dc:creator><![CDATA[JCitizen]]></dc:creator>
        <pubDate>Mon, 13 Sep 2010 19:35:07 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[One place I wasworking at the boss]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3356791]]></link>
        <description><![CDATA[ran the find a printer bit, just after we'd joined up to the main network.It took out 22 PLCs and stopped five manufacturing plants....We spent a good deal of time looking for malware, before we realised it was him.To th PLC's the probe reqest apperaded to be a maliciously crafted packet.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3356791]]></guid>
        <dc:creator><![CDATA[Tony Hopkinson]]></dc:creator>
        <pubDate>Sun, 12 Sep 2010 10:47:03 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[I agree, the thing is though]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3356719]]></link>
        <description><![CDATA[There is no default password. That would be better than the way HP does it now.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3356719]]></guid>
        <dc:creator><![CDATA[Michael Kassner]]></dc:creator>
        <pubDate>Sun, 12 Sep 2010 07:16:28 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[A router's SPI firewall]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3356710]]></link>
        <description><![CDATA[should stop any inbound traffic that is not destined for an active connection on the destination port, such as HTTP on port 80 (but please keep reading).It is possible that installing the HP hardware opens a port through any firewall, too, perhaps one on the gateway router to the Internet.  I am not an expert, but that seems tantamount to establishing a static connection, and an SPI firewall will pass any traffic destined to it.  If a printer is running a &quot;web server&quot;, then it might open a port in a gateway router's firewall as well as in the firewall, if any, that is on its own server.  (It seems unlikely that the printer's server has a firewall.)The open port permits Google web crawlers to collect (and index) the content from the HTML pages in the printer, which is, as you have reported, running a &quot;web server&quot;. So it seems that the password probably just prevents someone from tinkering with the printer's configuration (unless and until they break the password, and I would guess that their little ol' utility to do that has an unlimited number of attempts).  As another contributor reported previously, he can still read data from the printer's configuration after changing the default  password.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3356710]]></guid>
        <dc:creator><![CDATA[Ocie3]]></dc:creator>
        <pubDate>Sun, 12 Sep 2010 01:00:34 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Worse, the population continues to grow. :-)  -nt]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3356708]]></link>
        <description><![CDATA[]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3356708]]></guid>
        <dc:creator><![CDATA[Ocie3]]></dc:creator>
        <pubDate>Sun, 12 Sep 2010 00:39:11 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Which bit?]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355406]]></link>
        <description><![CDATA[Never mind. Applies to all. All the little bits of it.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355406]]></guid>
        <dc:creator><![CDATA[seanferd]]></dc:creator>
        <pubDate>Wed, 08 Sep 2010 23:45:44 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[When]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355367]]></link>
        <description><![CDATA[In all of recorded history has this not been so?]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355367]]></guid>
        <dc:creator><![CDATA[santeewelding]]></dc:creator>
        <pubDate>Wed, 08 Sep 2010 21:40:37 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[&quot;It seems that many home and company networks aren't setup properly.&quot;]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355363]]></link>
        <description><![CDATA[Understatement of the century.OK, I don't even have to consider this from an efficiency, best practices, or security standpoint - there seem to be loads of business and home networks that aren't even set up so that the network owner gets what he wants. This constantly amazes me.Edited for title field converting the copied/quoted ' to ?.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355363]]></guid>
        <dc:creator><![CDATA[seanferd]]></dc:creator>
        <pubDate>Wed, 08 Sep 2010 20:56:09 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[I should have known better...]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355325]]></link>
        <description><![CDATA[that is generally the case with me too! Thanks for the article! =D]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355325]]></guid>
        <dc:creator><![CDATA[JCitizen]]></dc:creator>
        <pubDate>Wed, 08 Sep 2010 20:26:39 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Straight Social Engineering]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355265]]></link>
        <description><![CDATA[I know of a place that got a phone call to an internal number (that can be called from outside) and the person that answered apparently gave out information about a local printer.  A couple of weeks later two toner cartridges show up with an invoice.  They ended up paying for the toner cartridges that they had never ordered.Pretty effective.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355265]]></guid>
        <dc:creator><![CDATA[kama410@...]]></dc:creator>
        <pubDate>Wed, 08 Sep 2010 16:13:31 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Not nice]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355241]]></link>
        <description><![CDATA[Glad you figured it out. I never use the install disks. Nine times out of ten, they are out-of-date.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355241]]></guid>
        <dc:creator><![CDATA[Michael Kassner]]></dc:creator>
        <pubDate>Wed, 08 Sep 2010 16:02:51 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[It seems...]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355207]]></link>
        <description><![CDATA[that if you order straight from HP and buy the warranted protection, they bend over backwards to get you a better product and service. However, with my recent experiences, I got to admit, they must be junk anyway. Problem is, Canon doesn't have one of the most important features I need in the US. I really like Canon printers, but they don't do color DVD printing in the US.[yet]]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355207]]></guid>
        <dc:creator><![CDATA[JCitizen]]></dc:creator>
        <pubDate>Wed, 08 Sep 2010 15:06:54 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[I get a LOT of false positives...]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355206]]></link>
        <description><![CDATA[from HP crapware and drivers! However, they might as well be true malware, with the way they act, and no more than I trust printer manufactures lately! ]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-335662-3355206]]></guid>
        <dc:creator><![CDATA[JCitizen]]></dc:creator>
        <pubDate>Wed, 08 Sep 2010 15:01:48 -0700</pubDate>
    </item>
    </channel>
</rss>

