Independent MFP security research
Where the paper path becomes an attack path.
Independent security research into multifunction printers and the software that connects them to enterprise networks. Print, scan, and document workflows.
01 / The findings
Published disclosures
Security findings across the MFP ecosystem. Reported to the vendor first, with the impact, timeline, and available fixes documented.
A loopback-only authorization gate is satisfied by a forged HTTP header, exposing privileged internal operations
An unauthenticated device-synchronisation operation writes and deletes .xml files at an attacker-chosen path as SYSTEM
02 / Behind the research
The workstation is secure.
The paper is in your hands.
What happened in between?
A confidential document leaves a managed workstation. You authenticate at the MFP, collect the pages, and walk away. It feels like a closed loop.
Depending on the setup, that job may have passed through a spooler, a print server, a release queue, and storage on the device. A scan can take another route through email, network shares, or a cloud connector. Each step brings its own software, permissions, and trust.
Holding the printout does not prove that no copy remains elsewhere. A successful scan does not tell you who else could reach the workflow. A flaw along that path can expose documents or turn a service account into access beyond the MFP.
Print Overrun investigates those gaps: where documents go, what the services can do, and whether the controls hold up when someone asks the wrong questions.
About the researcher