Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Exploits-HackingTools
[Top] [All Lists]

[NEWS] Insecure FTP Access in HP PSC 2510 Printers

Subject: [NEWS] Insecure FTP Access in HP PSC 2510 Printers
Date: 17 Nov 2004 16:43:09 +0200
The following security advisory is sent to the securiteam mailing list, and can 
be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  Insecure FTP Access in HP PSC 2510 Printers
------------------------------------------------------------------------


SUMMARY

"The  <http://h50025.www5.hp.com/hpcom/au_en/10_38_77_1765_Q3094A.html> HP 
PSC 2510 Photosmart all-in-one printer/flatbed fax/scanner/copier device 
is the ultimate solution for home and home-office needs. With wireless and 
Ethernet capabilities, this all-in-one device provides the pinnacle in 
built-in wireless and wired technology for home networks, while providing 
exceptional digital image printing, all with simple, easy-to-use 
functionality".

Insecure FTP server in the HP PSC 2510 printer allows unauthenticated 
users to store arbitrary data on the printer.

DETAILS

The HP PSC 2510 comes with an FTP print service that is not configurable. 
The same FTP server allows anonymous access, whose home directory is 
mapped to a write only directory. Once a file is dropped in the folder the 
printer will print it.

This allows unauthenticated users to store arbitrary data on the printer 
and retrieve it later with software like  
<http://www.phenoelit.de/hp/docu.html> Hijetter.

This feature is undocumented, nor is there anyway to enable/disable it via 
any of the supplied software or on the printer itself.

Vendor Status:
"HP Technical support commented that if you don't want this feature then 
you should hook up the printer as a local printer".

NOTE: This printer comes with both wireless and wired connectors on its 
back.


ADDITIONAL INFORMATION

The information has been provided by  <mailto:jrush@scout.wisc.edu> Justin 
Rush.



======================================== 


This bulletin is sent to members of the SecuriTeam mailing list. 
To unsubscribe from the list, send mail with an empty subject line and body to: 
list-unsubscribe@securiteam.com 
In order to subscribe to the mailing list, simply forward this email to: 
list-subscribe@securiteam.com 


==================== 
==================== 

DISCLAIMER: 
The information in this bulletin is provided "AS IS" without warranty of any 
kind. 
In no event shall we be liable for any damages whatsoever including direct, 
indirect, incidental, consequential, loss of business profits or special 
damages. 




<Prev in Thread] Current Thread [Next in Thread>
  • [NEWS] Insecure FTP Access in HP PSC 2510 Printers, SecuriTeam <=