what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

jetdirect.crash.txt

jetdirect.crash.txt
Posted Nov 20, 1999
Authored by Tobias Haustein

HP network printers (tested on HP LaserJet 4500) crash when given a URL loger then 256 characters.

tags | exploit
SHA-256 | d123734b6144ec16fede7b2f3f1b576848b20cada113ae27077f9c444a9ea6cd

jetdirect.crash.txt

Change Mirror Download
--SLDf9lqlvOQaIe6s
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable

Hi folks!

I just played with our network printer (a HP LaserJet 4500) and --
boom -- it crashed ;-)=20

The HP JetDirect J3111A module with firmware G.05.35 suffers from a
buffer overflow in it's internal web server. If you enter the
following URL in your web browser

http://my-printer's-ip/very-long-rubbish(256 bytes or so)

the printer prints a diagnostics page showing the contents of all
registers and the following 64 bytes of all memory addresses that
address registers point to.

Obviously it's a M680x0 CPU with 512 KB of RAM in our model, so
writing an exploit should be fairly easy. The nice point about it is
that most people wouldn't expect their printer to be compromised --
and since there is no logging on the printer, you can't easily be
tracked down...

Ciao,

Tobias

PS: I searched the web page of HP for any e-mail-address that could be=20
used to inform them about bugs, but i did not find any e-mail-address
at all. The web site seems to be one-way...=20

--=20
Dipl. Inform. Tobias Haustein

Department of Computer Science IV, Aachen University of Technology
Ahornstr. 55, D-52056 Aachen
Phone +49 (241) 80-21417, Fax +49 (241) 8888-220
E-Mail haustein@informatik.rwth-aachen.de
Web http://www-i4.informatik.rwth-aachen.de/~haustein/

--SLDf9lqlvOQaIe6s
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 5.0i for non-commercial use
MessageID: H+VKmigVK59pAjCnxblKrhcnezMKRLG5

iQEVAwUBODUe6xs02tO3FOYBAQHkAQgAmZ2khTPxMP9L6hV3wj/srGHw8GKlG6ix
pB8YZ9v2M/I+OrTaaviHUObgQA+mP6jXhb++xA0tLYFLc70ktfh8p2bsLc+a31Pu
lKbRTyydc2/gB9LKXj5uX+3SwG+6s8zcB59njKRQCL52sUiY88YwEtReVqrrs9DX
AovmzhlZGouWc0jUsgVsA6Ou3uEyDtQSZCvX573c4PBv0fMn6+ZdRM/qs1Movo98
Q4ilXJpIuM84wSZUg3jko6gaXSY4kc8vTAh7yKsNqqX4Kve5ZTRGZUn50MKS1hKM
nFw3ArqwZui4QDH7U+feJcCspx7FALIfuenZ9wJSUJq276moBjs2Gg==
=1zrQ
-----END PGP SIGNATURE-----


Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close