HP JetDirect web server vulnerable to long URL attack
21 Nov. 1999
Summary
It is possible to cause HP JetDirect J3111A module (firmware G.05.35) to crash, possibly making the printer execute arbitrary code, by sending it a specially crafted URL.
Credit:
This vulnerability has been discovered by: Tobias Haustein.
If you enter the following URL in your web browser:
http://my-printer's-ip/very-long-string(256 bytes or so)
The printer will print out a diagnostics page showing the contents of all registers and followed by 64 bytes of all memory addresses that address registers point to.