2 hours 52 minutes
Welcome back to Prince Security Intermediate Course. In this lesson, I'm going to talk about some general advice is, or best practices for printing device security.
what means best security practices there. Quite a lot of settings that exist in printing the wise, especially in the modern network printers that are there for us, various reasons. For example, there is quite a lot off,
uh, capabilities of a printer that there they represent legacy
printing capabilities to recharge, still used by some customers on some systems. For example, if they're using the well or if they're using some older methods of printing If they're using, for example, mainframe printers of stuff like that,
then there is quite a lot of things that are still left in and device that you actually don't meet.
So first thing to do is go to close unused ports and protocols.
That means ah ah, if you're using, for example, there is one thing on some printers. It's just called 9100 printing, which is using I P Port 9100.
Some other vendors Ah, some vendors are using other port rather than 19 100. But these things air there for legacy reasons.
And they should be disabled because modern printing through Windows Server and when those 10 operating systems doesn't need it.
Also, you can disable Acela slp config, And I'm not going to explain what of these things are. I'm just going to say their legacy or they're not needing in environment in which you have servers and, uh,
in those operating systems.
The other thing is LPD printing. Then tell net. Uh, most of the printing network printers can still be accessed from a commend prompting windows using telnet command.
And if you were, Rex is the printer. By telling it, you can do quite a lot off nasty stuff, so you should disable it.
And one off along these things go into category. Be smart. So read the standard,
practices for the securing your device and do it every time you put it on the network. Regardless, if that is the old device that has been in storage, or it's a new device that has just been purchased or it is the older wise that has Bean
repaired them in the service deep or on the location. Maybe something was changed. Maybe something was reset during the service procedure.
Do it every time you put new device on a network or every time you put the device printing device on the network. So you have to disable FTP printing accepted. You should disable I p access be X,
the Elsie Elsie as well. And then, of course, disabled people talking to ensure so apple Talking about jurors is used if you're using apple devices in peer to peer environment, if you're not printing through the server.
So if you're even if you have Apple devices on the network, sometimes if you disabled, they will still be able to print,
but not directly from the device toe printer.
So if you're using some of these things, then you should. If you're
business cases such that you have to use them off course, you don't disable them. But then you have to be extra careful toe watch about the things that can be done in terms of printing, hacking, using some of these
Let's continue about the minimal measures, so you have to lock toe the access to device settings from control panel.
On most of devices, you can simply remove the the icon or the option to do the seconds. This is not something that the user should do. If you look at the labs about HPV object, that mean you will see that you can do these things remotely from administrators. Computer core console
and nobody else should be able to change these things. You have to set in bed Web server passwords that this is a must.
Every time you connect their wives to a network, you should do it.
You should disable controls such as job, cancel button and the go button or whatever. They're called
with different manufacturers, because these things have to be,
uh, simply, they can do a damage to a device. If nothing else, than somebody can cancel somebody else's printing job. And then that person will reprint the entire job. It's 100 or 200 pages. Print job.
You print more. It's not going to do security risk, but it's going to increase the cost off business.
You have to configure job time out so that if somebody is running some very complex print heck job,
Um, and it's not printing, but doing something on a printer for a couple of minutes. It should printers should be able just to kill that
Um, you have to prevent physical access to removable harder, like HD and boards. You should lock it, live it something like a Kensington lock or something.
And my recommendation is to use static I p addresses for printing devices so that if somebody recent device it won't pick up the ah new I P address from the network or the new address it picks up from the network
should be not in a list off printing devices that comes with the other things that you should do in terms of security, like set the list of I P addresses for printers. And it's something on that I dress shows up on the network, which is not a printer.
It should automatically pop up in some kind of administrative council
so that you can take action and then you know that something is wrong with the device.
You should also, if you knew not using ecstatic I p addresses or even if you're using them, you should set on your routers the HDP restrictions for printers so that, um
if they're trying to pick the address, which is outside the range off i p the I P address that is not for printer. It shouldn't
So at the end of this lesson, let's go and just check do a learning check. And the question is what is not the standard security mirror for printers. So the possible answers are disabled down that
the Civil PCL printing
or disable i PXs BX And the correct answer is
you should not disable PCL printing. The PCO is the most common driver that is used them
in printing today, the or PD l and most of the office bringing is done by using PCL. Most of the printers cannot disable PCL printing, so you definitely shouldn't do that.
In this video. You have learned
some of the general best practices for, ah, securing your printing device. And in the next video, I'm going to continue talking about the same topic.