Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Vulnerability 12236, Printer has no password set. |
|---|---|
| Date: | Wed, 08 Nov 2006 20:47:01 -0500 |
On Wed, Nov 08, 2006 at 11:25:21AM -0600, Vanhooser, Mike wrote:
Has anyone in the group actually had a problem related to not having a password set on a printer. Nessus rates this as a high problem as well as high rated CVE but wondering if this is really something that should be considered a high risk.
When looking at CVSS scores, one thing to understand is that we compute only the base scores. These are generated solely based on the characteristics of the vulnerabilities themselves and don't reflect the importance of a service to an organization, the likelihood that an exploit exists, etc that you probably should be concerned about in trying to manage your exposure to vulnerabilities. For example, a local file include flaw in, say, BillyBob's Guestbook installed on a webserver that a summer coop set up on his desktop rates much higher than a denial of service flaw in one of your border routers. Which are you really going to lose sleep over?
Issues would be denial of service but could a redirect of sensitive printer info be possible? Are there other concerns?
Well, the plugin description mentions that the flaw allows "anyone to
change its IP or potentially to intercept print jobs sent to it."
Obviously, intercepting print jobs means a loss of confidentiality
("partial" because someone needs to first send a job to your "printer").
But it could also lead to a loss of integrity as the attacker could
potentially change the documents and then re-route them to the real printer.
George
--
theall@tenablesecurity.com
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Problem Nessus 3.x throught PPTP tunnel, gosha-necr |
|---|---|
| Next by Date: | Re: SCO OpenServer, George A. Theall |
| Previous by Thread: | Re: Vulnerability 12236, Printer has no password set., Doug Nordwall |
| Next by Thread: | Plugin 16192, Greg Smith |
| Indexes: | [Date] [Thread] [Top] [All Lists] |