ExtremeHacking
Today : | Time : | safemode : ON
> / Main Website / Cyber Surakha Abhiyan / Hackers Charity / Linkedin / facebook / twitter /
Name Author Perms Com Modified Label

HP LaserJet Pro Printers remotely exploitable to gain unauthorized access to Wi-Fi and Printer Unknown rwxr-xr-x 0 8/07/2013

Filename HP LaserJet Pro Printers remotely exploitable to gain unauthorized access to Wi-Fi and Printer
Permission rw-r--r--
Author Unknown
Date and Time 8/07/2013
Label
Action
Ethical Hacking Institute in Pune
./Arizona Team

Do you own an HP printer? If so, it may be vulnerable to Hackers. Multiple HP LaserJet Pro Printers are printer vulnerable to hackers according to a new advisory posted by the vendor, dubbed as CVE-2013-4807 (SSRT101181).



























Researcher 'Micha Sajdak' of Securitum.pl have found a security hole HP LaserJet printers that allows a remote hacker to extract the admin password in plain text, among other information like WiFi settings including the WPS PIN.
The main issue is with some of the networked HP LaserJet printers, having hidden URLs hardcoded in the firmware, which can be accessed without authentication. The vulnerability could be exploited remotely to gain unauthorized access to data.

For example : http://IP_ADDRESS/dev/save_restore.xml











Where the password seems to be encrypted, but the value contains a hex representation of the admin password in plain text, i.e. 0x746573746f7765 = testowe.

Also, If a printer is WiFi enabled, then the WiFi info can be extracted from using below url:
http://IP_ADDRESS:8080/IoMgmt/Adapters/wifi0/WPS/Pin























Affected models are HP LaserJet Pro P1102w, HP LaserJet Pro P1606dn, HP LaserJet Pro CP1025nw, HP LaserJet Pro M1212nf MFP, HP LaserJet Pro M1213nf MFP, HP LaserJet Pro M1214nfh MFP, HP LaserJet Pro M1216nfh MFP, HP LaserJet Pro M1217nfw MFP, HP LaserJet Pro M1218nfs MFP, and Possibly others too.

HP has provided an updated printer firmware version: 20130703 to resolve this issue.

www.arizonainfotech.com
CEH CHFI ECSA ENSA CCNA CCNA SECURITY MCITP RHCE CLOUD ANDROID IPHONE NETWORKING HARDWARE TRAINING INSTITUTE IN PUNE, Certified Ethical Hacking, IT Security Training Information Security Traning Courses in Pune, ceh certification in pune, Ethical Hacking Course in Pune
 

Cyber Suraksha Abhiyan | Sadik Shaikh © 2015 Sadik Shaikh | CEH V9 | ETHICAL HACKING Course Training Institute in India-Pune
Extreme Hacking Template design by Sadik Shaikh | Cyber Suraksha Abhiyan