Bitcoin Forum
November 08, 2024, 01:44:40 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: WARNING: MFP printers pose a security hazard!!!  (Read 862 times)
Tugbit (OP)
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
August 31, 2014, 05:02:28 PM
 #1

I found this video: https://www.youtube.com/watch?v=TCKr5WgVVN8

The same applies for MFP printers, I checked mine : http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay?javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken&javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%253Demr_na-c02738751-1%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&ac.admitted=1409502745239.876444892.199480143

I pulled the HD from my mfp and docked it to my computer, I was able to retrieve EVERY DOCUMENT EVER PRINTED, COPIED or FAXED ON THIS MACHINE INCLUDING MY PAPER WALLETS !!!!!!
2112
Legendary
*
Offline Offline

Activity: 2128
Merit: 1073



View Profile
August 31, 2014, 06:48:36 PM
 #2

What is the file system that HP uses in their MF devices nowadays? I do remember that in the past (when disks had about 100MB) their devices used some sort of proprietary file system that was nontrivial to reverse engineer.

Please comment, critique, criticize or ridicule BIP 2112: https://bitcointalk.org/index.php?topic=54382.0
Long-term mining prognosis: https://bitcointalk.org/index.php?topic=91101.0
Tugbit (OP)
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
August 31, 2014, 06:59:50 PM
 #3

I think it would be unwise to write a tutorial on how to retrieve the data on those disks. I'm not even a computer expert but i managed to find retrieval software on a HP support site...
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1540


No I dont escrow anymore.


View Profile
August 31, 2014, 07:15:16 PM
 #4

I think it would be unwise to write a tutorial on how to retrieve the data on those disks. I'm not even a computer expert but i managed to find retrieval software on a HP support site...

Ofc its wise. It should be common knowledge that you can not trust these printers. If only a few know about these vulnerabilities the majority will not be aware of the risks and the few knowledgeable can exploit that. Btw you can print an encrypted paperwallet that is useless witout a code that will not be printed. E.g. Mycelium wallet backup uses this to backup the private key(s).

Im not really here, its just your imagination.
2112
Legendary
*
Offline Offline

Activity: 2128
Merit: 1073



View Profile
August 31, 2014, 07:42:34 PM
 #5

I think it would be unwise to write a tutorial on how to retrieve the data on those disks. I'm not even a computer expert but i managed to find retrieval software on a HP support site...
Then post the link to the software you used. HP site is huge and messy, you'll save us some time.

Please comment, critique, criticize or ridicule BIP 2112: https://bitcointalk.org/index.php?topic=54382.0
Long-term mining prognosis: https://bitcointalk.org/index.php?topic=91101.0
Dfrost
Member
**
Offline Offline

Activity: 81
Merit: 10


View Profile
September 01, 2014, 06:01:20 AM
 #6

Serves you right for trying to print money  Grin
Gogreen
Sr. Member
****
Offline Offline

Activity: 392
Merit: 250



View Profile
September 01, 2014, 06:20:49 AM
 #7

Serves you right for trying to print money  Grin
lol

Bitcoin mining Antminer s7 4.7 TH Used in Good Condition Best Offer Prices @ ebay seller order directly here https://goo.gl/uaoh1r. Bitcoin payment optional.
BitCoinNutJob
Legendary
*
Offline Offline

Activity: 1316
Merit: 1000


View Profile
September 01, 2014, 06:51:36 AM
 #8


Well i wont be selling any used printers anymore thank for this.
Kluge
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1015



View Profile
September 01, 2014, 07:02:59 AM
 #9

Alan from Armory brought this up months ago, incidentally. The biggest concern I'd have is with a company - more likely, individual within company - having its software/drivers phone home (... or worse) with this information. -So everything you scanned in for the AML/KYC crap.... and printing wallets, too, of course.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!