Web Hack List

Other nomination

CUPS Detection

CUPS listens on localhost:631 over HTTP and is not covered by Firefox port banning, so a remote page can probe for it. Grossman ties the CVE-2008-0047 CGI heap overflow to drive-by reach and gives a detection probe: an img pointing at localhost:631/images/navbar.gif whose onload and onerror handlers report whether CUPS is running.

Record

Researcher
Jeremiah Grossman
Published by
blog.jeremiahgrossman.com

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman, first published at the original source. Preserved copies are kept so the citation survives its host.