what can ya do with a hacked printer? (jetdirect? port 9100 vuln)

my friend that owns a coffee shop asked me to poke around on his network to look for vulnerabilities in exchange for some free coffees and i saw that they had 9100 open, wasn’t familiar with it so played around and found out about PRET which gave me access to his HP printer, with transversal you can gain access to the file system etc and from what i read you can open a root shell on another port, would the scope be limited to the printer, or can the printer be used as a vector to gain access to other systems connecting to said printer?

tldr im not familar with printers and found a vuln, what do, i like my free cup-a-joes while writing my dnd campaigns.

submitted by /u/werewolfpajamas
[link] [comments]

GitHub Reports Code-Signing Certificate Theft in Security Breach

By Deeba Ahmed
GitHub states that hackers gained access to its code repositories and stole code-signing certificates for two of its desktop apps: Desktop and Atom.
This is a post from HackRead.com Read the original post: GitHub Reports Code-Signing Cer…

Has anyone used O.MG cable? What is it capable of?

I saw video where the attacker sends commands to the target device and for example "Rick "Rolls" the person. And I know there are also keylogger capabilities. But can it be used to actually let the attacker navigate the through your phon…

IT Army of Ukraine gained access to a 1.5GB archive from Gazprom

IT Army of Ukraine claims to have breached the infrastructure of the Russian energy giant Gazprom and had access to a 1.5 GB archive. The collective IT Army of Ukraine announced it has gained access to a 1.5 GB archive belonging to the Russian energy giant Gazprom. The group of hacktivists announced the hack on […]

The post IT Army of Ukraine gained access to a 1.5GB archive from Gazprom appeared first on Security Affairs.

How to bypass ISP throttling?

Whenever I consume 20gb per day, my ISP throttles down the speed to 1mbps, except on social media apps (tiktok, playstore, facebook, etc…) is there any method to trick the ISP into thinking the data is coming from those apps instead of lets say steam, youtube? I tried using a VPN, it doesn’t work. oookla speedtest and fast.com shows the full speed, while testmy.net shows 1mbps (120kb/s) which is the true speed.

submitted by /u/HighNB
[link] [comments]

Experts released VMware vRealize Log RCE exploit for CVE-2022-31706

Horizon3 security researchers released proof-of-concept (PoC) code for VMware vRealize Log Insight RCE vulnerability CVE-2022-31706. Last week, researchers from Horizon3’s Attack Team announced the release of PoC exploit code for remote code execution in VMware vRealize Log tracked as CVE-2022-31706 (CVSS base 9.8/10). The PoC exploit code will trigger a series of flaws in VMware […]

The post Experts released VMware vRealize Log RCE exploit for CVE-2022-31706 appeared first on Security Affairs.