[37302] in bugtraq
Unsecure Ftpd on HP PSC 2510 Printer
daemon@ATHENA.MIT.EDU (Justin Rush)
Wed Nov 10 17:32:14 2004
Date: Wed, 10 Nov 2004 15:26:15 -0600
From: Justin Rush <jrush@scout.wisc.edu>
To: bugtraq@securityfocus.com
Message-ID: <20041110212615.GA22293@fromage.scout.wisc.edu>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Product Name: HP PSC 2510
Summary: Ftp print service is not configurable
This printer comes with an ftp daemon which allows anonymous
access, and drops the user into a write only directory. By default
anyone from anywhere can drop a file into this directory and the
printer will print the document. There is no documentation about
this feature, nor is there anyway to change (enable/disable) it
via any of their software or on the printer itself. HP Tech.
support says that if you don't want this feature then you should
hook up the printer as a local printer, however this printer
comes with both wireless and wired connectors on the back.
Justin Rush
jrush@scout.wisc.edu