Re: Nimda affecting HP LaserJet / JetDirect devices?

From: Michael W. Shaffer (shafferat_private)
Date: Fri Sep 21 2001 - 10:59:42 PDT

  • Next message: John Stauffacher: "RE:New Version of Retina Nimba Scanner"

    On Fri, 21 Sep 2001, Michael W. Shaffer wrote:
    
    > We are starting to get reports here from various users around our
    > site that our HP network printers are displaying strange messages
    > such as 'Good Morning', 'Nimda Live', and 'Kill Trees'. Has anyone
    > else noticed this behavior? Any information on what vulnerability
    > is being exploited here or whether this is the same Nimda agent as
    > that propagating across Windows platforms would be greatly
    > appreciated.
    
    I found a small exploit from 1997 on securityfocus.com (ID 2245)
    which includes a simple little program to set the display message
    on an HP Printer. The program works here on our LaserJets which
    are supposedly running the latest available firmware from HP. It
    would appear that this is a benign but possibly annoying exploit
    which has been known for quite a while but never fixed by HP.
    
    [ Michael W. Shaffer                            Agilent Labs RCS ]
    [ email: shafferat_private         phone: +1 650.485.2955 ]
    [ public key: http://alcatraz.labs.agilent.com/shaffer/publickey ]
    
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Fri Sep 21 2001 - 11:09:47 PDT