Web Hack List

Collected research

Local DoS on CUPS to a remote exploit via specially-crafted webpage

Pwning Ubuntu via CUPS

pagvac uses the browser as a bridge to a localhost-only daemon: cupsd runs as root on default Ubuntu Desktop and listens on 127.0.0.1:631, and a web page writing 101 image tags at its add-rss-subscription endpoint crashes it reliably, with no CUPS authentication on 8.04. Includes the crash PoC, a bash cleanup script, and the argument that root-owned local services are remotely reachable via CSRF.

Record

Document
Pwning Ubuntu via CUPS
Researcher
Adrian Pastor
Published by
gnucitizen.org
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Adrian Pastor, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .