what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Samsung SyncThruWeb SMB Hash Disclosure

Samsung SyncThruWeb SMB Hash Disclosure
Posted Aug 31, 2015
Authored by Shad Malloy

Samsung SyncThruWeb suffers from an SMB hash disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 89e66f78180f90029a6312a4b79f51f9a7ee6a5113073cf30a134e0a91a4078f

Samsung SyncThruWeb SMB Hash Disclosure

Change Mirror Download
# Exploit Title: Samsung SyncThruWeb SMB Hash Disclosure

# Date: 8/28/15

# Exploit Author: Shad Malloy

# Contact: http://twitter.com/SecureNM

# Website: https://securenetworkmanagement.com

# Vendor Homepage: http://www.samsung.com

# Software Link:
http://www.samsung.com/hk_en/consumer/solutions/type/SyncThruWebService.html

# Version: Known Vulnerable versions Samsung SCX-5835_5935 Series Printer
Main Firmware Version : 2.01.00.26

Samsung SCX-5635 Series Printer Main Firmware Version : 2.01.01.18
12-08-2009



# Tested on:

Samsung SCX-5835_5935 Series Printer

Main Firmware Version : 2.01.00.26

Network Firmware Version : V4.01.05(SCX-5835/5935)
12-22-2008

Engine Firmware Version : 1.20.73

UI Firmware Version : V1.03.01.55 07-13-2009

Finisher Firmware Version : Not Installed

PCL5E Firmware Version : PCL5e 5.87 11-07-2008

PCL6 Firmware Version : PCL6 5.86 10-28-2008

PostScript Firmware Version : PS3 V1.93.06 12-19-2008

SPL Firmware Version : SPL 5.32 01-03-2008

TIFF Firmware Version : TIFF 0.91.00 10-07-2008

Samsung SCX-5635 Series

Main Firmware Version : 2.01.01.18 12-08-2009

Network Firmware Version : V4.01.16(SCX-5635)
12-04-2009

Engine Firmware Version : 1.31.32

PCL5E Firmware Version : PCL5e 5.92 02-12-2009


PCL6 Firmware Version : PCL6 5.93 03-21-2009


PostScript Firmware Version : PS3 1.94.06 12-22-2008

TIFF Firmware Version : TIFF 0.91.00 10-07-2008



Proof of Concept

1. Using the default username and password (admin/admin), it is
possible to obtain all credentials used for SMB file transfer. To obtain the
file access http://<printer url>/smb_serverList.csv.

2. The UserName and UserPassword fields are unencrypted and
visible using any text editor.



Relevant Patches

http://downloadcenter.samsung.com/content/FM/201508/20150825111208555/SCX563
5_V2.01.01.28_0401113_1.00.zip

http://downloadcenter.samsung.com/content/FM/201508/20150825112233867/SCX583
5_5935_V2.01.00.56_0401113_1.01.zip



Shad Malloy

Secure Network Management, LLC


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close