Forums: Niprint Lpd-lpr Print Server <= 4.10 Remote Exp. - Forums

Jump to content

  • (3 Pages)
  • +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • You cannot reply to this topic

Niprint Lpd-lpr Print Server <= 4.10 Remote Exp. i'm back again :)

#31 User is offline   johannes30 

  • Private
  • Icon
  • Group: Members
  • Posts: 16
  • Joined: 29-September 03

Posted 07 November 2003 - 09:44 AM

have anyone a vuln checker for port 515?
0

#32 User is offline   isaiah 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 199
  • Joined: 12-August 03

Posted 08 November 2003 - 02:29 PM

As Some have Said Before...

Port 515 is the Universal Port for Print Servers/Daemons. So if you count the number of Print Servers out there (TONS). The likelyhood of getting a Vuln Server running NiPrint, is very small..

The exploit isnt broken.. :)
0

#33 Guest_Xxplozive_*

  • Group: Guests

Posted 29 November 2003 - 07:31 PM

i search a vulnerable checker scanner. have someone a scanner for this?
0

#34 Guest_DownBload_*

  • Group: Guests

Posted 02 December 2003 - 04:16 AM

LOL...
Shouldn't that system(tmp) be at least a little bit strange???
This is fake exploit - trojan maybe - try to "decrypt" shellcode and see what he does.
0

#35 User is offline   agathos 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 128
  • Joined: 13-October 03

Posted 02 December 2003 - 04:59 AM

so if you read correct :)

sprintf(tmp,"telnet ......."\n);
system(tmp);

that means:

he saves the string "telnet ......" into the char tmp!
and runs then over system procedure
0

#36 Guest_biboupoki_*

  • Group: Guests

Posted 02 December 2003 - 05:20 AM

thanx i m gonna to try it
0

#37 Guest_DownBload_*

  • Group: Guests

Posted 03 December 2003 - 04:38 AM

agathos, on Dec 2 2003, 12:59 PM, said:

so if you read correct :)

sprintf(tmp,"telnet ......."\n);
system(tmp);

that means:

he saves the string "telnet ......" into the char tmp!
and runs then over system procedure

Yes, my fault :-)
0

#38 User is offline   ivan288 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 115
  • Joined: 17-October 03

Posted 03 December 2003 - 05:05 AM

nice exploit but verry hard to find vuln. servers. if anyone has a tool for this please share with us.
0

#39 User is offline   Xion 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 38
  • Joined: 30-November 03

Posted 04 December 2003 - 01:06 PM

it's veru nice exploit I test now :)
0

#40 Guest_Xxplozive_*

  • Group: Guests

Posted 09 December 2003 - 05:15 PM

I've written a niprint autohaxxor but i didn't found a vulnerable niprint! :(
0

#41 User is offline   trunks 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 28
  • Joined: 04-December 03

Posted 09 December 2003 - 07:30 PM

i scanned over 400 ips.. no luck yet :huh:
0

#42 User is offline   Xion 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 38
  • Joined: 30-November 03

Posted 10 December 2003 - 12:24 PM

thx for nice exploit
0

#43 User is offline   Knutinho 

  • Private
  • Icon
  • Group: Members
  • Posts: 11
  • Joined: 01-February 04

Posted 03 February 2004 - 03:54 PM

Thx for the nice Exploit !!

Anybody able to Link the compiled version onlien again ??

Thx a lot !!
0

#44 User is offline   DerangeD 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 23
  • Joined: 22-January 04

Posted 03 February 2004 - 11:03 PM

compiled it but didn't get any results with this sploit

scanned over 500 ip's

anyone had luck using this ?
0

#45 User is offline   Feuerstein 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 47
  • Joined: 26-August 03

Posted 04 February 2004 - 06:17 AM

i added an option for hostlistfiles, but never ever had a shell. anyone ever got 1 ?

// also codet banner scanner for this purpose. see results below:

*.*.*.*: [/usr/sbin/lpd: zappa: Malformed from address
]
*.*.*.*: [/usr/sbin/lpd: zappa: Malformed from address
]
*.*.*.*: [/usr/sbin/lpd: zappa: Malformed from address
]
*.*.*.*: [/usr/sbin/lpd: zappa: Malformed from address
]
*.*.*.*: [/usr/sbin/lpd: zappa: Malformed from address


which look like *nix servers, and furthermore

*.*.*.*: [lpd: master    : Malformed from address
]
*.*.*.*: [lpd: master    : Malformed from address
]
*.*.*.*: [lpd: master    : Malformed from address
]


which might be nt, but with enabled hostmask :(

already scanned bout 20000 ips, but no exploitation yet
0

  • (3 Pages)
  • +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting