Penetration Testing mailing list archives

RE: [lists] Getting Printer IP Addresses Prior to Pen Testing - Question About DHCP


From: "Curt Purdy" <purdy () tecman com>
Date: Wed, 21 Sep 2005 18:37:51 -0500

Marjorie Rintoul wrote:

DHCP allocates IP addresses dynamically.  How does DHCP know 
which (fixed
printer) IP addresses to stay away from?  Does anyone know of 
a way to get this list?


Exception addresses coresponding to the printer addresses are coded into the
DHCP server.  You can obtain printer ip's by using an SNMP scanner like
SolarWinds.  Most printers have SNMP enabled by default with public
community enabled.

Curt Purdy CISSP, GSNA, GSEC, CNE, MCSE+I, CCDA 
Information Security Officer 
Information Systems Security 
www.infosysec.net
cell: 443.846.4231



------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 

Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: