Postscript printers at risk

D

DelJo63

Security researchers have said they've uncovered a new way for hackers to crash Brother printers(but likely ALL PS printers).

More specifically, they've put out an advisory saying a vulnerability in the web front-end of Brother printers (the Debut embedded http server) allows an attacker to launch a Denial of Service attack. The attack might be carried out simply by sending a single malformed HTTP POST request, they claim.

“The attacker will receive a 500 error code in response, the web server is rendered inaccessible and all printing will cease to function,” Trustwave explains. “This vulnerability appears to affect all Brother printers with the Debut web front-end.”
so says TheRegister.co.uk .

Postscript is serviced on TCP port 9100 using "the popular Common Unix Printing System, CUPS" interface so this is a Cross-Platform issue.

Circumvention: Restrict port 9100 at the Gateway firewall to only local LAN addresses.
LPD & CUPS operate on port 515.
 
Back