Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Nmap Development: Re: Bug Report with jetdirect printer server

Re: Bug Report with jetdirect printer server

From: RB <aoz.syn_at_gmail.com>
Date: Thu, 27 Dec 2007 15:23:42 -0700

> ACK. Most printers are junk. We have the same problem.

ACK. Same with HP-UX 10.x and CNR on Windows running the service in
debug mode - with experiementation one can narrow it down to a small
set of triggers, sometimes even a single packet. This is a
long-standing issue with poorly-written [usually legacy] apps that
Nmap just exposes, usually resulting in denial-of-service with the
occasional compromisable crash.

To reiterate (since I've had long arguments with UNIX greybeards and
firmware engineers that firmly believe otherwise), this is not a bug
in Nmap, it's an application bug. Some commercial scanners have
options for 'safe' scanning, which purport to turn off the
crash-inducing behavior, but tell that to the Zebra printers and
Symbol handsets I've seen crash just because too many TCP ports were
scanned.

RB

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org
Received on Dec 27 2007

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos