The best way to secure SMB scans??

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • JR2ALTA
    Service Manager

    Site Contributor
    1,000+ Posts
    • Feb 2010
    • 2028

    #1

    The best way to secure SMB scans??

    This question is nothing new, but recently I've had customers very upset that their folders must be shared with SMB.

    First I was using the sharename$ trick to hide the folder on the network, then I remembered the Path will show up on the copiers address book.


    Now, I've told them that move sensitive docs to an unshared folder.

    Looking for any other ideas.


    Thanks
  • zed255
    How'd ya manage that?

    1,000+ Posts
    • Dec 2009
    • 1024

    #2
    How do the clients think their scans are going to get into the folder if it isn't shared? They can assign different permissions to the folders based on user and group. For instance, John Doe scans to a folder only he has full permissions for, all other users are denied any access, even listing contents. If the folder is properly secured what's the issue with seeing the path? Even if somebody knows the path they would need John Doe's credentials to access the folder.

    IMHO, this is something for the client's IT to work out.

    Comment

    • Vulkor
      Senior Tech

      500+ Posts
      • Jun 2009
      • 942

      #3
      Just don't use Simple File Sharing. Share the Folder only to that username/pass per pc and each smb scan destination on copier would need that user/pass. That way only copier and The person can only get in their pc's shared files.

      Comment

      • Morlock49
        Trusted Tech
        100+ Posts
        • Mar 2009
        • 166

        #4
        There is another way. if the customer does not want to share folders out , then use network twain and a program like paperport and have the user pull the scan from the copier, and store the scanned image in a secure folder. not elegant but if security is paramount.
        Sorry folks, reputation removed by Just Manuals, because he's a sad little wanker

        Comment

        • Mr Spock
          Vulcan Inventor of Death

          1,000+ Posts
          • Aug 2006
          • 2064

          #5
          use the advanced sharing option (turn off simple file sharing)
          set up the folder like this
          users\docs\scanned\bob
          users\docs\scanned\mary
          users\docs\scanned\larry
          etc.

          setup a user copier password copier (password cannot expire)
          go to the properties of the scanned folder then security tab. add copier to the list with full permissions
          in each of the user folders just make sure only that user has full permissions and no one else is listed.
          set up one touches for each folder using the copier as the login id
          The folder will accept the scan from the machine but only the individual user can access the file (and the copier account but don't tell them).
          And Star Trek was just a tv show...yeah right!

          Comment

          • Vulkor
            Senior Tech

            500+ Posts
            • Jun 2009
            • 942

            #6
            Of course most IT guys don't like their being a blanket user account named Copier on every pc. Especially if someone knows the password. But yeah I've done it that way before

            Comment

            • JR2ALTA
              Service Manager

              Site Contributor
              1,000+ Posts
              • Feb 2010
              • 2028

              #7
              So, if I am understanding correctly....You don't really need "allow all permissions" like i've been taught? Do I uncheck "Everyone" ?

              The problem I have is allowing all permission makes it visible in My Network Places and //hostname through the Run command.

              Can all this be done without Active Directory?

              I feel dumb, but I can't wait to try this stuff out! Thanks guys

              Comment

              • Stirton.M
                All things Konica Minolta

                1,000+ Posts
                • Oct 2009
                • 1804

                #8
                SMB scanning can be set to anything you want. There are restrictions in some cases, like with domain controllers, but in general, any windows machine with a shared folder can make it public, or password protected to the specific user of that computer or folder if the share is set at a server.

                Just because you can "see" the folder shared, does not mean you can view the contents unless you have the login and password authorized from that computer. Even multiple users on a single computer can have separate shared folders that the others cannot see without prior setup to allow those users to view the others in advanced sharing.

                Alternatively, if the copier has user boxes, for example, is a Konica Minolta device, anyone can set up a personal user box, password protect it for their own use, scan and print to and download from that user box securely. I would assume that competitor machines would have something similar to this ability, though I cannot say with any certainty.
                "Many years ago I chased a woman for almost two years, only to discover that her tastes were exactly like mine: we both were crazy about girls."
                ---Groucho Marx


                Please do not PM me for questions related to Konica Minolta hardware.
                I will not answer requests or questions there.
                Please ask in the KM forum for the benefit of others to see the question and give their input.

                Comment

                • RRodgers
                  Service Manager

                  1,000+ Posts
                  • Jun 2009
                  • 1947

                  #9
                  You can use the admin share that is usually hidden anyway's C$.
                  Color is not 4 times harder... it's 65,000 times harder. They call it "TECH MODE" for a reason. I have manual's and firmware for ya, course... you are going to have to earn it.

                  Comment

                  • hackersun

                    #10
                    aficio 3025 with windows 7

                    I have a folder with Windows 7 ordeandor shared with everyone, and firewall off completely, but in the copier ricoh aficio 3025 smb port never see the folder when you scan and send the document, everything is perfect, user without a password on windows 7. Why not send the document?

                    Comment

                    • RRodgers
                      Service Manager

                      1,000+ Posts
                      • Jun 2009
                      • 1947

                      #11
                      Originally posted by JR2ALTA
                      This question is nothing new, but recently I've had customers very upset that their folders must be shared with SMB.

                      First I was using the sharename$ trick to hide the folder on the network, then I remembered the Path will show up on the copiers address book.


                      Now, I've told them that move sensitive docs to an unshared folder.

                      Looking for any other ideas.


                      Thanks
                      Is this on a Konica Box? The Konica's support putting a password on the document before you scan it over.
                      Color is not 4 times harder... it's 65,000 times harder. They call it "TECH MODE" for a reason. I have manual's and firmware for ya, course... you are going to have to earn it.

                      Comment

                      • Stirton.M
                        All things Konica Minolta

                        1,000+ Posts
                        • Oct 2009
                        • 1804

                        #12
                        Differentmed

                        GET LOST ASSHOLE!

                        Nobody here wants your crap that you sell. Find another place to screw with.
                        "Many years ago I chased a woman for almost two years, only to discover that her tastes were exactly like mine: we both were crazy about girls."
                        ---Groucho Marx


                        Please do not PM me for questions related to Konica Minolta hardware.
                        I will not answer requests or questions there.
                        Please ask in the KM forum for the benefit of others to see the question and give their input.

                        Comment

                        • jeffreyclay
                          Technician
                          • Sep 2008
                          • 43

                          #13
                          Since SMB isn't secure (never was, read about it on Microsoft's tech notes) Why not use WEBDAV with SSL certificates?

                          Comment

                          Working...