security1 publisher
Rewriting one field in a printer's web UI hands over its stored LDAP credentials
Pen Test Partners demoed a passback attack on an unauthenticated printer interface: change the LDAP host, force a lookup, and the device sends its own bind password in cleartext. Every mitigation listed is configuration.
Publishers:pentestpartners.com
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence55