TGViewer
r0 Crew (Channel) r0 Crew (Channel) @r0_crew · 8.96K subscribers
Post #2119 12.8K
Attacking UNIX Systems via CUPS, Part I

CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177 have been assigned around these CUPS issues.

CVSS 9.9

This remote code execution issue can be exploited across the public Internet via a UDP packet to port 631 without needing any authentication, assuming the CUPS port is open through your router/firewall. LAN attacks are also possible via spoofing zeroconf / mDNS / DNS-SD advertisements.


https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/

A series of bugs in the CUPS printers discovery mechanism (cups-browsed) and in other components of the CUPS system, can be chained together to allow a remote attacker to automatically install a malicious printer (or hijack an existing one via mDNS) to execute arbitrary code on the target host as the lp user when a print job is sent to it.


https://gist.github.com/stong/c8847ef27910ae344a7b5408d9840ee1

#linux #rce #printer
  • ❤ 8
  • 🤣 8
  • 👍 5
  • 😐 4
  • 🔥 2
  • 🥰 2
  • 😁 2
  • 🤯 1
More from @r0_crew
  1. Jan 19, 2025New blog on using CLR customizations to improve the OPSEC of your .NET execution harness.…
  2. Jan 1, 2025Happy New Year! May every binary reveal its secrets, every challenge find its solution, an…
  3. Nov 15, 2024Complete list of LPE exploits for Windows (starting from 2023) https://github.com/MzHmO/Ex…
  4. Sep 26, 20240-Click exploit in MediaTek Wi-Fi chipsets affects routers and smartphones / Exploiting (C…
  5. Sep 3, 2024Native function and Assembly Code Invocation https://research.checkpoint.com/2022/native-f…
  6. Aug 27, 2024Exploiting the Windows Kernel via Malicious IPv6 Packets (CVE-2024-38063) https://malwaret…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →