Mailing List Archive

Fw: Fw: hp jetdirect password leakage
From kim0's msg below, it appears as if some of the details of the bug are
still forthcoming...

hopefully they come out before my holiday is over :-)


----- Original Message -----
From: "kim0" <kim0@phenoelit.de>
To: "John Lampe" <j_lampe@bellsouth.net>
Sent: Saturday, July 27, 2002 9:42 PM
Subject: Re: Fw:


John,
This was not a module for nessus but rather a simple advisory concerning
the vulnerability or exposure. CERT and/or HP should be posting more
tonight or on the 28th. For the next few days we want to wait since we
have been working with the vendor for a while now and want to give them
a chance for their reply (next 12 hours or so I believe...)


kim0

John Lampe wrote:

> Guten Abend,
> Am I missing something from your advisory?
>
> John Lampe
> https://f00dikator.hn.org/
>
> "Knowledge will forever govern ignorance, and a people who mean to be
their
> own governors, must arm themselves with the power knowledge gives. A
popular
> government without popular information or the means of acquiring it, is
but
> a prologue to a farce or a tragedy or perhaps both."
> --James Madison
>
> ----- Original Message -----
> From: "John Lampe" <j_lampe@bellsouth.net>
> To: "plugins writer" <plugins-writers@list.nessus.org>
> Sent: Saturday, July 27, 2002 3:39 PM
>
>
> This module should be the beginning of a script to check for password
> leakage on hp jetdirect servers (per phenoelit advisory from this
> morning)...It doesn't work for me and is incomplete (see comments at
> bottom)...in fact...
>
> $ snmpget 10.10.10.10 public .iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0
> Error in packet
> Reason: (noSuchName) There is no such variable name in this MIB.
> This name doesn't exist: enterprises.11.2.3.9.4.2.1.3.9.1.1.0
> $
>
> If someone has a better env to test in, then please complete the script,
put
> your name on the script and forward back...
>
>
>
>
>


--
kim0 <kim0@phenoelit.de>
Phenoelit (http://www.phenoelit.de)
90C0 969C EC71 01DC 36A0 FBEF 2D72 33C0 77FC CD42
Re: Fw: Fw: hp jetdirect password leakage [ In reply to ]
Maybe your snmp client isn't able to send out that query because it
doesn't have a local matching MIB file. Try modifying snmp_sysDesc.nasl
to send that OID manually.


On Saturday 27 July 2002 10:49, John Lampe wrote:
> From kim0's msg below, it appears as if some of the details of the bug
> are still forthcoming...
>
> hopefully they come out before my holiday is over :-)

> > $ snmpget 10.10.10.10 public .iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0
> > Error in packet
> > Reason: (noSuchName) There is no such variable name in this MIB.
> > This name doesn't exist: enterprises.11.2.3.9.4.2.1.3.9.1.1.0
Re: Fw: Fw: hp jetdirect password leakage [ In reply to ]
I'm using snmpget. The query is sent just fine...I see the request go out
and the error coming back from the HP printer...I pulled down all the HP
mibs last night and glanced over some of the printer MIBS....The correct
OID should be .1.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0 and, per the MIB
<quote>
-- 1) Proprietary Objects containing a string which are defined in this MIB
use the
-- first two bytes to hold the symbol set used to encode the string.
-- The Roman-8 symbol set has a hex encoding of 0x0115. Other
-- symbol sets are listed in the PCL 5 Comparison Guide in table
-- C-1 Symbol Set Values. Standard Printer MIB (prt...objects) and Host
Resurces
</quote>

This is inline with what the advisory stated regarding looking for the hex
dump after the 0x01,0x15 bytes...

The test script that I sent was sending the OID manually, as well.

John Lampe
https://f00dikator.hn.org/

"Knowledge will forever govern ignorance, and a people who mean to be their
own governors, must arm themselves with the power knowledge gives. A popular
government without popular information or the means of acquiring it, is but
a prologue to a farce or a tragedy or perhaps both."
--James Madison

----- Original Message -----
From: "H D Moore" <hdm@digitaloffense.net>
To: "John Lampe" <j_lampe@bellsouth.net>; "plugins writer"
<plugins-writers@list.nessus.org>
Sent: Saturday, July 27, 2002 9:51 PM
Subject: Re: Fw: Fw: hp jetdirect password leakage


Maybe your snmp client isn't able to send out that query because it
doesn't have a local matching MIB file. Try modifying snmp_sysDesc.nasl
to send that OID manually.


On Saturday 27 July 2002 10:49, John Lampe wrote:
> From kim0's msg below, it appears as if some of the details of the bug
> are still forthcoming...
>
> hopefully they come out before my holiday is over :-)

> > $ snmpget 10.10.10.10 public .iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0
> > Error in packet
> > Reason: (noSuchName) There is no such variable name in this MIB.
> > This name doesn't exist: enterprises.11.2.3.9.4.2.1.3.9.1.1.0