Generated by All in One SEO Pro v5.0.1, this is an llms-full.txt file, used by LLMs to index the site. # IT Service Works | IT Services and Support Professional without being impersonal. Personal without being unprofessional. ## Posts ### [News](https://www.itserviceworks.com/news/) **Published:** February 12, 2016 **Author:** Scott Kuhn --- ### [Examples of the Xerox Communication Issues](https://www.itserviceworks.com/examples-of-the-xerox-communication-issues/) **Published:** October 19, 2022 **Author:** Scott Kuhn **Content:** In the post about the [discovered Xerox MFC configuration security issue](https://www.itserviceworks.com/multifunction-printer-scanner-security-issue-discovered/), I alluded to frustrations with communicating with the company. Wanted to shed some light on that. **Example 1**: at the local (WA office) level, seemed like there was very little concern by the VP (who CC’d in the service manager, though there was no correspondence from him), and suspected they hadn’t alerted anyone higher up the chain. On Sept 13th, after previously going through the details of what I was seeing on the incoming emails, as well as what I’d seen on my client’s MFC, received an email from the VP that said: “This has been resolved and how would we go about getting the domain back?” My reply: “I think the easiest route is to make me a reasonable offer based on the value of the domain, time and value in alerting the company to the issues with the configuration, the potential effects of the issue with regulatory compliance for some of those clients, and I assume the taking down of the post detailing the issue. Willing to also do an NDA if requested.” Him, and what led me to believe higher-ups hadn’t been notified of the issue: “I don’t have access to funds more than petty cash, I am not sure what you want or think is reasonable.” So I replied: “I’ve received six scans since your email, so it does not appear the issue is resolved. As for the domain, I would have assumed given the potential risk and security concerns that this issue would have been taken up the chain of command. I would highly suggest that be done. Discuss with your associates and let me know your offer. “ Which then led to me receiving a call two days later from an SVP in CA. **Example 2:** that SVP, while we had a cordial conversation and an offer for the domain was made, the follow up email was titled: *Domain registration issue.* The issue, if you go back to the original post, really wasn’t about the domain at all–that only allowed the discovery of the issue. But could have been worse, I suppose. **Example 3:** …and it was worse. Another email from the SVP signaled that he got approval for the offer, and asked me to send an invoice, but the NDA wasn’t ready. Replied, basically and nicely, that if the NDA was a part of the discussion, there is no way I could send the invoice without seeing and reading that NDA. **Example 4:** Speaking of the NDA, I finally received it Oct 5th. But the terms…just not acceptable. First, the agreement wanted me to start actions on the domain, wait until the registration lock was over in November, and then wait up to another 20 days before receiving payment. Minor-ish issue, but no way I’d take actions without payment received. But the bigger issue: there was nothing in the agreement, aside from me deleting all mentions of the issue and the emails received, to actually deal with the issue. I ended my explanation of that with: “Selling the domain name back without the concerns being addressed would, in some sense, have me complicit in the ignoring or covering up of those concerns (especially with removal of the post about the concerns). I can’t be a party to that.” The NDA was NOT like this [one](https://www.itserviceworks.com/wp-content/uploads/2022/10/312991436_10228848824634472_1004057776925592464_n.jpeg). **Example 5**: Now we get to a series of doozies. My reply to the NDA then led to me receiving an email on Oct 10th from the Deputy Director of Xerox corporate security, CC:ing in some other folks, and stating that he would now be my single point of contact going forward. And then this: “While I believe I have an understanding of the facts, I would like to propose a meeting to review those facts and determine appropriate next steps. I will send you some availability windows in a separate email shortly.” Straightforward. But…not so much. That email came on a Thurs morning. Didn’t hear anything back, so emailed on the following Monday afternoon “Wanted to check back in–hadn’t received that follow up email with the availability windows.” Did I get an email? No. I got, on Tues afternoon, and without consult, discussion, or explanation, a calendar invite for a Zoom meeting the next morning at 8:30am. Oh, and he included in that Zoom meeting Xerox legal counsel…despite him explaining he’d be the single point of contact. I didn’t respond. But at 8:05am that morning, he sent a cancellation. Then that afternoon, also without consult, discussion, or explanation, sent another calendar invite for a Zoom meeting the next morning at 8am. By Friday I was done, and decided to just walk away from the table, so to speak: “My intent on reaching out to Xerox, from the time of the discovery until now, has been to notify the company about the issue, because I saw the potential severity of it both to Xerox and the companies affected. I presented the information in good faith. To be completely frank, from the beginning the reaction to the issue and the communication (or non-communication) from the various Xerox contacts has been bewildering. I still believe that the issue is a major one, and that it does not meet the Xerox ***Safeguarding and Using Customer Information*** section of the [Xerox Code of Business Conduct](https://www.xerox.com/downloads/world/e/ethics_Code_of_Conduct_English.pdf). But I also realize ultimately that is Xerox‘s call, and that I’ve spent far too much time and energy on this for it to be worth continuing. With that being said, I leave you with the information about the issue and walk away from the table, not demanding or requesting anything.” There was a response that essentially ignored the email, but then seemed to try to position himself by using the phrases “I had made several attempts” and “any of this week’s invitation”. By that point, I was just ***done***, and on Saturday replied: “This appears to be another example of the communication with Xerox that I called bewildering. Even if it wasn’t with intent, it falls in line with much of the other communication from the company. To review: 1. Your initial email stated you would be sending “some availability windows in a separate email shortly.” That didn’t happen. 2. You replied, mentioning “several attempts without success” and “any of this week’s invitation.” 3. In looking at the filtered calendar invites: a. you sent one on Tues afternoon at 2:48pm titled **ITServiceWorks Follow up** for a Zoom meeting scheduled for Wed morning at 8:30am b. you sent a cancellation for it Wed morning at 8:05am. c. you sent another Wed afternoon at 12:15pm titled **Xerox IT Issue – Follow up** for Thur morning at 8:00am 4\. Two invites does not equate to “several attempts”, or the multiple implied in “any of this week’s invitations”, and it certainly doesn’t meet the expectation you set in your original email with “some availability windows in a separate email shortly.” 5. Regardless of those important details, sending calendar invites without discussion is itself bewildering, tantamount to an order or demand. As I am not an employee or agent of Xerox, that doesn’t sit well. You may very well think these things are minor. But from my perspective, they continue a pattern of communication that has eroded trust. So I stand by what I wrote Friday morning: I still believe that the issue is a major one, and that it does not meet the Xerox ***Safeguarding and Using Customer Information*** section of the Xerox Code of Business Conduct. But I also realize ultimately that is Xerox‘s call, and that I’ve spent far too much time and energy on this for it to be worth continuing. With that being said, I leave you with the information about the issue and walk away from the table, not demanding or requesting anything.” **Edit 10/21: Example 6**…rather unexpected, but have been getting quite a few visits in short periods of time from Xerox offices around the country. If only this amount of time and attention were paid to the issue at hand. **Edit 11/3:** Details on Example 6 above. Xerox uses, as many businesses do, Microsoft 365 for email. One thing that 365 does is that when you send emails with links, in the background it visits that link to “check” it. Those visits show up like this: ![](https://www.itserviceworks.com/wp-content/uploads/2022/10/Screen-Shot-2022-11-03-at-115240-AM-300x39.png "Screen Shot 2022-11-03 at 11.52.40 AM | IT Service Works | IT Services and Support") So it’s really interesting to see those continue to pop up, followed by visits from different Xerox locales across the country…when the contacts spent far less time and energy on the issue when I brought it to their attention. What’s even more interesting is some feedback I got from a former Xerox employee that they aren’t the least bit surprised by the ways they’ve communicated…seems it’s an unofficial corporate standard. ![author avatar](https://secure.gravatar.com/avatar/344a853d6b4d80734886026b533555ffd00d4fc7920915bb384a340d3fdb76b2?s=300&d=mm&r=g) Scott Kuhn [See Full Bio](https://www.itserviceworks.com/author/admin/) [ ](https://www.itserviceworks.com/author/admin/) **Categories:** Security, Xerox --- ### [Multifunction Printer/Scanner Security Issue Discovered](https://www.itserviceworks.com/multifunction-printer-scanner-security-issue-discovered/) **Published:** September 8, 2022 **Author:** Scott Kuhn **Content:** On September 7th, 2022, a client notified me that they were getting a new multifunction printer/scanner/copier the next day. I remoted into their network to check the SMTP settings for Scan-to-Email function, and discovered the previous copier company had set it up using a third-party service SendGrid (which in and of itself isn’t an issue). But I didn’t recognize the email domain used, so looked it up. The domain expired in May, and seeing that it could be a useful one in the future, I purchased the domain, set it up as an alias domain of mine (this one), and set up email in the same way, but added a filter so that all email to that domain would go to a folder and skip the inbox. Within a couple of hours I discovered the issue, because that folder began receiving a significant amount of email: copiers set up in the way that the copier company set them up was not only sending the Scan-to-Email scans to their intended recipients, **but also to the email address they used in conjunction with the set up.** *Any Reply-to-All responses also were received.* Why is this a concern? It means that for as long as the copier company used that way of setting up SMTP, they’ve potentially been receiving copies of everything your organization has sent up until the domain expired, as I now am. I’ve reached out to the copier company. From a security perspective, those scans should ideally be sending via your own email system, or if having to use a third-party service, should be through one of your own so that your organization maintains control over those scans. Screenshots showing the settings and emails used on client’s multifunction (click to enlarge) ![](https://www.itserviceworks.com/wp-content/uploads/2022/09/Screen-Shot-2022-09-08-at-7.56.49-AM-e1662651189232-300x186.png "Screen Shot 2022-09-08 at 7.56.49 AM | IT Service Works | IT Services and Support") ![](https://www.itserviceworks.com/wp-content/uploads/2022/09/Screen-Shot-2022-09-08-at-7.57.18-AM-300x235.png "Screen Shot 2022-09-08 at 7.57.18 AM | IT Service Works | IT Services and Support") If you have a multifunction printer, PLEASE have your IT provider check the SMTP settings. To know if this affects you, when you do a Scan-toEmail, does the email address of the scan come across as \[something\]@nwghelpdesk.com? If it does, this applies to you. I can be contacted at xeroxissue@itserviceworks.com **Edit, 10/17:** Due to lack of candor and/or willingness to address the security issue discovery that I brought to Xerox in good faith without request or demand, the domain has been sold to another entity. To be abundantly clear: **the domain itself was never the security concern: it only allowed the discovery.** The issue is the SMTP configuration used by QBSI and CTX on some of the MFCs that allows for scans from those machines to be sent outside of the purview and control of the sender and recipient. Considering some of those MFCs are scanning and sending protected health information or potentially confidential or sensitive information, this is a major concern. But even more fundamentally, it betrays the trust users of those MFCs have that the scans they send are received by the person or organization they send to, and no others. Xerox’s own Code of Business Conduct (published [here](https://www.xerox.com/downloads/world/e/ethics_Code_of_Conduct_English.pdf)), under the section Safeguarding and Using Customer Information, states: > We respect and are committed to safeguarding the confidentiality, data privacy, and security of information that our customers have entrusted to us, including confidential information, personally identifiable information, proprietary information, and trade secrets. We exercise appropriate care at all times to prevent unauthorized disclosure and use of customer information. We take our responsibilities for customer confidentiality, data privacy, and security seriously and implement appropriate safeguards for the use and handling of this information in accordance with our information security and privacy policies, and in accordance with all applicable laws. The configurations discovered clearly violate that section, and perhaps even more importantly, the lack of willingness to address the issue once it was made known, violates it even further. **Edit, 10/21**: posted about the examples of communication issues with Xerox [here](https://www.itserviceworks.com/examples-of-the-xerox-communication-issues/ "Examples of the Xerox Communication Issues"). ![author avatar](https://secure.gravatar.com/avatar/344a853d6b4d80734886026b533555ffd00d4fc7920915bb384a340d3fdb76b2?s=300&d=mm&r=g) Scott Kuhn [See Full Bio](https://www.itserviceworks.com/author/admin/) [ ](https://www.itserviceworks.com/author/admin/) **Categories:** Security, Xerox --- ### [Moving shares between servers, maintain security](https://www.itserviceworks.com/moving-shares-between-servers-maintain-security/) **Published:** February 18, 2019 **Author:** Scott Kuhn **Content:** 1\. On the the source server: START > RUN > REGEDT32 2\. Go to the key: HKEY\_LOCAL\_MACHINE/SYSTEM/CurrentControlSet/Services/LanmanServer/Shares 3\. From the Registry menu, select Export Registry file. 4\. Copy the file to the target server 5\. On the target server: START > RUN > Name of the exported registry file> OK 6\. Reboot the target server. 7\. Go into your target server’s share management, and edit the share to point to the target server’s location for the individual shares. ![author avatar](https://secure.gravatar.com/avatar/344a853d6b4d80734886026b533555ffd00d4fc7920915bb384a340d3fdb76b2?s=300&d=mm&r=g) Scott Kuhn [See Full Bio](https://www.itserviceworks.com/author/admin/) [ ](https://www.itserviceworks.com/author/admin/) **Categories:** Uncategorized --- ## Pages ### [Home](https://www.itserviceworks.com/) **Published:** February 12, 2016 **Author:** Scott Kuhn **Content:** https://www.itserviceworks.com/wp-admin/admin.php?page=aioseo --- ### [Gallery](https://www.itserviceworks.com/gallery/) **Published:** October 5, 2016 **Author:** Scott Kuhn **Content:** [![](https://www.itserviceworks.com/wp-content/uploads/2016/10/pexels-photo-171292-150x150.jpeg "pexels-photo-171292 | IT Service Works | IT Services and Support")](https://www.itserviceworks.com/gallery/pexels-photo-171292/) [![](https://www.itserviceworks.com/wp-content/uploads/2016/02/blog1-150x150.jpg "blog1 | IT Service Works | IT Services and Support")](https://www.itserviceworks.com/blog1/) [![](https://www.itserviceworks.com/wp-content/uploads/2016/02/blog4-150x150.jpg "blog4 | IT Service Works | IT Services and Support")](https://www.itserviceworks.com/blog4/) [![](https://www.itserviceworks.com/wp-content/uploads/2016/02/blog2-150x150.jpg "blog2 | IT Service Works | IT Services and Support")](https://www.itserviceworks.com/blog2/) [![](https://www.itserviceworks.com/wp-content/uploads/2016/02/business1-150x150.jpg "business1 | IT Service Works | IT Services and Support")](https://www.itserviceworks.com/business1/) [![](https://www.itserviceworks.com/wp-content/uploads/2016/10/pexels-photo-186077-150x150.jpeg "pexels-photo-186077 | IT Service Works | IT Services and Support")](https://www.itserviceworks.com/gallery/pexels-photo-186077/) [![](https://www.itserviceworks.com/wp-content/uploads/2016/10/pexels-photo-66463-150x150.jpeg "pexels-photo-66463 | IT Service Works | IT Services and Support")](https://www.itserviceworks.com/gallery/pexels-photo-66463/) [![](https://www.itserviceworks.com/wp-content/uploads/2016/10/pexels-photo-106344-150x150.jpeg "pexels-photo-106344 | IT Service Works | IT Services and Support")](https://www.itserviceworks.com/gallery/pexels-photo-106344/) [![](https://www.itserviceworks.com/wp-content/uploads/2016/02/hero4-150x150.jpg "hero4 | IT Service Works | IT Services and Support")](https://www.itserviceworks.com/hero4/) [![](https://www.itserviceworks.com/wp-content/uploads/2016/10/macbook-laptop-ipad-apple-38519-150x150.jpeg "macbook-laptop-ipad-apple-38519 | IT Service Works | IT Services and Support")](https://www.itserviceworks.com/gallery/macbook-laptop-ipad-apple-38519/) --- ## Categories ### [Uncategorized](https://www.itserviceworks.com/category/uncategorized/) --- ### [Security](https://www.itserviceworks.com/category/security/) --- ### [Xerox](https://www.itserviceworks.com/category/xerox/) ---