|
|
|
|
| |
"The HP PSC 2510 Photosmart all-in-one printer/flatbed fax/scanner/copier device is the ultimate solution for home and home-office needs. With wireless and Ethernet capabilities, this all-in-one device provides the pinnacle in built-in wireless and wired technology for home networks, while providing exceptional digital image printing, all with simple, easy-to-use functionality".
Insecure FTP server in the HP PSC 2510 printer allows unauthenticated users to store arbitrary data on the printer. |
| |
Credit:
The information has been provided by Justin Rush.
|
| |
The HP PSC 2510 comes with an FTP print service that is not configurable. The same FTP server allows anonymous access, whose home directory is mapped to a write only directory. Once a file is dropped in the folder the printer will print it.
This allows unauthenticated users to store arbitrary data on the printer and retrieve it later with software like Hijetter.
This feature is undocumented, nor is there anyway to enable/disable it via any of the supplied software or on the printer itself.
Vendor Status:
"HP Technical support commented that if you don't want this feature then you should hook up the printer as a local printer".
NOTE: This printer comes with both wireless and wired connectors on its back.
|
|
|
|
|
|
|
|
|
|