OSX: HP printer tool program Security Vulnerability (HP Utility. app )?

Source: Internet
Author: User


If you have a new HP Uility model. for HP printers supported by the app, you can easily manage printer configurations from the HP Utility program. This feature is similar to the features provided by HP WebJet Admin, but has fewer features, it is not suitable for batch configuration and management of network environments. In network settings, you can easily set/change the network configurations of the printer, such as IP addresses.


This program is stored in the/Library/Printers/hp/Utilities directory and installed along with the HP printer driver installation package.


This function is very suitable for individual users, but it may cause problems in the company's network environment. Imagine that anyone can change the IP address at will, so others cannot print it! If the Administrator ignores this security risk, you are busy.


In fact, the HP Utility program depends on SNMPv1/v2 to communicate with the printer, so you can disable it or set it to read-only, can prevent clients from modifying printer configurations without permission (Networking-> Network Settings-> SNMP ).


However, it is not that simple, because managing HP printers in the network environment will not forget to use HP Web JetAdmin, which is the most useful and powerful tool for HP to manage network printers, by default, SNMPv1/v2 is used to find and manage network printers. If it is disabled, it cannot be found. If it is set to read-only, it cannot be managed. Enable SNMPv3 for management. Because v3 supports authentication and encrypted transmission, it is more secure.


In addition, almost all printers now support configuration management on the Web interface and are the basic means. Therefore, the initial printer configuration management password is indispensable and convenient, for example, HP uses Newtorking-> Security-> Authorization to set the admin password. Some also support ACL, which are security enhancement technologies.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.