Phenoelit Advisory, 0815 ++ /- Brother_NC

From: kim0 (kim0at_private)
Date: Sat Jul 27 2002 - 03:03:10 PDT

  • Next message: kim0: "Phenoelit Advisory, 0815 ++ * - Cisco_tftp"

    -- 
                kim0   <kim0at_private>
            Phenoelit (http://www.phenoelit.de)
    90C0 969C EC71 01DC 36A0  FBEF 2D72 33C0 77FC CD42
    
    
    Phenoelit Advisory <wir-haben-auch-mal-was-gefunden #0815 +-++>
    
    [ Authors ]
    	FX		<fxat_private>
    	FtR 		<ftrat_private>
    	kim0 		<kim0at_private>	
    	DasIch 		<DasIchat_private>
    
    	Phenoelit Group	(http://www.phenoelit.de)
    	Advisory	http://www.phenoelit.de/stuff/Brother_NC.txt
    
    [ Affected Products ]
    	Brother Corporation
    				NC-3100h
    
    	Brother Bug ID: 	Not assigned
    
    [ Vendor communication ]
            06/29/02        Initial Notification
                            *Note-Initial notification by phenoelit
                            includes a cc to certat_private by default
            07/19/02        Notification of intent to post public
                            in apx. 7 days.
    
    
    [ Overview ]
    	The Brother NC-3100h provides network connectivity for Brother 
    	printers (much in the same way as the HP JetDirect card). 
    	
    [ Description ]
    	By sending an oversized administrative password using the web-interface, 
    	an attacker can cause the printer to crash.
    
    [ Example ]
    	Enter a password for the administrator that is 136 characters or more 
    	and <click> the button. The printer will crash.
    
    [ Solution ]
    	None known at this time. 
    
    [ end of file ]
    



    This archive was generated by hypermail 2b30 : Sat Jul 27 2002 - 11:17:50 PDT