The Wayback Machine - http://web.archive.org/web/20130415035544/http://h20000.www2.hp.com:80/bizsupport/TechSupport/Document.jsp?objectID=c02239581
» Sign-in with HP Passport | » Register Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
HP.com Home Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Products and Services Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Support and Drivers Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Solutions Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html How to Buy Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Contact HP Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Search: Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html More options
 
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
hp.com home
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html

Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Instant

Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » 

Business Support Center

Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html

HP Passport Sign-in

Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
» Sign-in with HP Passport
» Register
» Learn more...
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html

Tasks

Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Download drivers and software Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Troubleshoot a problem Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Setup, install, and configure Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Discover and use a product Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Perform regular maintenance Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Upgrade and migrate Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Recycle and dispose Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html »

Resources

Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Customer Self Repair Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Diagnose problem or Chat (HP Instant Support) Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Support Forums Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Guided troubleshooting Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Manuals Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Submit a support case Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » See more... Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Help Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » Site map Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html » HP Support Center Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02239581

Version: 1

HPSBMA02545 SSRT100139 rev.1 - HP Power Manager (HPPM) Running on Linux and Windows, Remote Execution of Arbitrary Code
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2010-12-15

Last Updated: 2010-12-15


Potential Security Impact: Remote execution of arbitrary code

Source: Hewlett-Packard Company, HP Software Security Response Team

VULNERABILITY SUMMARY

A potential security vulnerability has been identified with HP Power Manager (HPPM) running on Linux and Windows. The vulnerability could be exploited remotely to execute arbitrary code.

References: CVE-2010-4113, ZDI-CAN-697

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.

HP Power Manager earlier than v4.3.2

BACKGROUND

For a PGP signed version of this security bulletin please write to: security-alert@hp.com

Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Instant

| Step | Goal | Tools & Techniques | |------|------|---------------------| | | Gather public metadata (WHOIS, DNS, TLS, reputation). | whois , nslookup , VirusTotal, URLVoid, Cisco Talos. | | 2. URL Decomposition | Break the URL into components, identify suspicious patterns. | Manual parsing or scripts ( urllib.parse in Python). | | 3. Safe Rendering | Load the page in a sandboxed environment to capture redirects and network activity. | Browser sandbox (e.g., Firefox with Multi‑Account Containers), cURL with -L for follow‑redirects, wget , httpie . | | 4. Traffic Capture | Record all HTTP(S) requests/responses, JavaScript execution, DNS lookups. | Burp Suite, OWASP ZAP, Wireshark, mitmproxy . | | 5. Content Analysis | Inspect HTML/JS for obfuscation, malicious payloads, or hidden redirects. | jsbeautifier , unpackers , static analysis tools (e.g., Yara ). | | 6. Parameter Fuzzing | Test how the server reacts to altered jid values (e.g., ../ , URL‑encoded payloads). | ffuf , wfuzz , dirb , custom Python scripts. | | 7. Reputation Lookup of Final Destination | After any redirects, evaluate the final URL. | Same tools as step 1; check for blacklists and domain age. | | 8. Documentation & Reporting | Record findings, screenshots, and remediation suggestions. | Markdown/Word templates, CVE‑style vulnerability description. |

| Threat | Mechanism | Potential Impact | |--------|-----------|------------------| | | The server blindly redirects to a URL supplied in a parameter. | Users are sent to phishing or malware sites; brand reputation is abused. | | Drive‑by Download | A “jump” page loads a hidden iframe or script that triggers an automatic download. | Malware infection without user interaction. | | Phishing / Credential Harvesting | The final destination mimics a legitimate login portal (e.g., banking, social media). | Theft of usernames, passwords, OTPs. | | Tracking & Analytics Abuse | The jump page records user agent, IP, referrer, then forwards. | Privacy leakage; data can be sold or used for targeted attacks. | | Cross‑Site Scripting (XSS) via Parameter | If the value of jid is reflected without sanitisation, it can execute arbitrary JavaScript. | Session hijacking, defacement, further malware injection. | | Server‑Side Request Forgery (SSRF) | If the backend fetches the jid value as a URL, an attacker could force internal network calls. | Exposure of internal services, credential leakage. | Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html

| Audience | Recommendation | |----------|----------------| | | • Do not scan QR codes from unknown sources. • Hover over shortened or “jump” links to view the true destination (use browser extensions like “URL Unshortener”). • Keep browsers, OS, and anti‑malware software up‑to‑date. | | Developers / Web Operators | • Enforce HTTPS (TLS 1.3 or higher). • Validate and whitelist redirect destinations; never trust raw query parameters. • Encode output (HTML‑escape) to prevent XSS. • Implement Content‑Security‑Policy (CSP) to limit script execution. • Use a “same‑origin” policy for iframes and disallow target="_blank" without rel="noopener" . | | Security Teams | • Deploy a Web‑Application Firewall (WAF) with rules for open‑redirect, LFI, and SSRF patterns. • Monitor DNS queries for newly registered domains that resolve to the same IP. • Conduct periodic red‑team simulations involving QR‑code and “jump‑page” scenarios. | | Network Administrators | • Block outbound traffic to known malicious IP ranges (feed from reputable threat intel). • Enable DNS‑level filtering for suspicious domains. • Log and alert on HTTP Location: responses that redirect to external domains. | | Step | Goal | Tools & Techniques

: The "jid" parameter could be used for tracking purposes. This might raise privacy concerns, especially if you're not aware of how your data is being used. URL Decomposition | Break the URL into components,

: This is the protocol used for transmitting data across the internet. The "http" part of the URL indicates that the site uses this protocol, which, unlike HTTPS, does not provide encrypted connections. This can pose a risk, especially if you're planning to enter sensitive information.

RESOLUTION

HP has made HP Power Manager 4.3.2 or subsequent available to resolve the vulnerability.

HP Power Manager 4.3.2 for Linux is available for download from
https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=Z7550-63115

HP Power Manager 4.3.2 for Windows is available for download from
http://h18004.www1.hp.com/products/servers/proliantstorage/power-protection/software/power-manager/pm3-dl.html

HISTORY
Version:1 (rev.1) - 15 December 2010 Initial release

Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

©Copyright 2010 Hewlett-Packard Development Company, L.P.
Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits;damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.

   Content feedback
To help us improve our content, please provide your feedback below.

1. How does the information on this page help you?

   very helpful somewhat helpful not helpful
 

2. Was it easy to find this document?

   easy not easy

3. If you selected not easy for question 2, in which section did you expect to find it?

     

4. Comments:

Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
 
 
- Your feedback will be used to improve our content. Please note this form is for feedback only, so you will not receive a response.
Contact HP if you need technical assistance.
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Printable versionPrintable version
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
Privacy statement Using this site means you accept its terms Feedback to webmaster
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html
© 2013 Hewlett-Packard Development Company, L.P.
Http- Www.lhzl666.com Home Qrcode Jump Index Jid 2.html