Re: [IPP] FYI - IPP exposure to open internet

Michael Sweet via ipp <ipp@pwg.org> Wed, 24 June 2020 12:53 UTC

Return-Path: <ipp-bounces@pwg.org>
X-Original-To: ietfarch-ipp-archive@ietfa.amsl.com
Delivered-To: ietfarch-ipp-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5FCB73A0DBC for <ietfarch-ipp-archive@ietfa.amsl.com>; Wed, 24 Jun 2020 05:53:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.899
X-Spam-Level:
X-Spam-Status: No, score=-2.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MAILING_LIST_MULTI=-1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JrcFaXwUWr8B for <ietfarch-ipp-archive@ietfa.amsl.com>; Wed, 24 Jun 2020 05:53:32 -0700 (PDT)
Received: from mail.pwg.org (mail.pwg.org [50.116.7.199]) by ietfa.amsl.com (Postfix) with ESMTP id 128433A0DBA for <ipp-archive2@ietf.org>; Wed, 24 Jun 2020 05:53:31 -0700 (PDT)
Received: by mail.pwg.org (Postfix, from userid 1002) id 768FA11B24; Wed, 24 Jun 2020 12:53:31 +0000 (UTC)
Received: from mail.pwg.org (localhost [IPv6:::1]) by mail.pwg.org (Postfix) with ESMTP id DBEF43592; Wed, 24 Jun 2020 12:53:28 +0000 (UTC)
X-Original-To: ipp@pwg.org
Delivered-To: ipp@pwg.org
Received: by mail.pwg.org (Postfix, from userid 1002) id A332C3A6B; Wed, 24 Jun 2020 12:53:27 +0000 (UTC)
Received: from mail.msweet.org (mail.msweet.org [173.255.209.91]) by mail.pwg.org (Postfix) with ESMTP id 91DA21C9F for <ipp@pwg.org>; Wed, 24 Jun 2020 12:53:26 +0000 (UTC)
Received: from [172.20.10.8] (unknown [67.69.69.139]) by mail.msweet.org (Postfix) with ESMTPSA id C58A6820E8; Wed, 24 Jun 2020 12:53:25 +0000 (UTC)
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.80.23.2.2\))
In-Reply-To: <80A64FE5-826C-48D2-968A-73BD7CD0605A@xerox.com>
Date: Wed, 24 Jun 2020 08:53:23 -0400
Message-Id: <3D96A4F9-07BE-46B1-AE06-59845F527FA8@msweet.org>
References: <80A64FE5-826C-48D2-968A-73BD7CD0605A@xerox.com>
To: "Rizzo, Christopher" <Christopher.Rizzo@xerox.com>
X-Mailer: Apple Mail (2.3608.80.23.2.2)
Cc: PWG IPP Workgroup <ipp@pwg.org>
Subject: Re: [IPP] FYI - IPP exposure to open internet
X-BeenThere: ipp@pwg.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: ISTO-PWG Internet Printing Protocol workgroup discussion forum <ipp.pwg.org>
List-Unsubscribe: <https://www.pwg.org/mailman/options/ipp>, <mailto:ipp-request@pwg.org?subject=unsubscribe>
List-Archive: <http://www.pwg.org/pipermail/ipp/>
List-Post: <mailto:ipp@pwg.org>
List-Help: <mailto:ipp-request@pwg.org?subject=help>
List-Subscribe: <https://www.pwg.org/mailman/listinfo/ipp>, <mailto:ipp-request@pwg.org?subject=subscribe>
From: Michael Sweet via ipp <ipp@pwg.org>
Reply-To: Michael Sweet <msweet@msweet.org>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: ipp-bounces@pwg.org
Sender: ipp <ipp-bounces@pwg.org>

Chris,

Thanks for forwarding this!

Looks like the bulk of the open "devices" are CUPS servers, which would have needed to be explicitly configured to allow remote access - the default is localhost-only, then local subnets (for regular printer sharing), then whole-internet (if you want things wide open...)


> On Jun 24, 2020, at 12:09 AM, Rizzo, Christopher via ipp <ipp@pwg.org> wrote:
> 
> Maybe you have already seen this.  Forwarding in case it needs discussion
>  
> https://www.shadowserver.org/news/open-ipp-report-exposed-printer-devices-on-the-internet/
>  
>  
> Chris
>  
> Christopher Rizzo
> Xerox Corporation
> GDG/Discovery/Advance Technology
> 26600 SW Parkway Ave.
> Wilsonville, OR 97070-9251
> Phone: (585) 314-6936
> Email: Christopher.Rizzo@xerox.com
>  
> "The realization came over me with full force that a good part of the remainder of my life was going to be spent in finding errors in my own programs."
> -Maurice Wilkes, Memoirs of a Computer Pioneer
> _______________________________________________
> ipp mailing list
> ipp@pwg.org
> https://www.pwg.org/mailman/listinfo/ipp

________________________
Michael Sweet



_______________________________________________
ipp mailing list
ipp@pwg.org
https://www.pwg.org/mailman/listinfo/ipp