daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

9100-pjl.md (5630B)


      1 ---
      2 title: "9100/tcp - PJL (Printer Job Language)"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/9100-pjl.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/9100-pjl.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 9100/tcp - PJL (Printer Job Language)
     14 
     15 ## Basic Information
     16 
     17 From [here](http://hacking-printers.net/wiki/index.php/Port_9100_printing): Raw printing is what we define as the process of making a connection to port 9100/tcp of a network printer. It is the default method used by CUPS and the Windows printing architecture to communicate with network printers as it is considered as ‘_the simplest, fastest, and generally the most reliable network protocol used for printers_’. Raw port 9100 printing, also referred to as JetDirect, AppSocket or PDL-datastream actually **is not a printing protocol by itself**. Instead **all data sent is directly processed by the printing device**, just like a parallel connection over TCP. In contrast to LPD, IPP and SMB, this can send direct feedback to the client, including status and error messages. Such a **bidirectional channel** gives us direct **access** to **results** of **PJL**, **PostScript** or **PCL** commands. Therefore raw port 9100 printing – which is supported by almost any network printer – is used as the channel for security analysis with PRET and PFT.<sup>[[1]](#references)</sup>
     18 
     19 For broader printer-assessment background, see the Hacking Printers wiki.<sup>[[6]](#references)</sup>
     20 
     21 **Default port:** 9100
     22 
     23 ```text
     24 9100/tcp open  jetdirect
     25 ```
     26 
     27 ## Enumeration
     28 
     29 ### Manual
     30 
     31 ```bash
     32 nc -vn <IP> 9100
     33 @PJL INFO STATUS      #CODE=40000   DISPLAY="Sleep"   ONLINE=TRUE
     34 @PJL INFO ID          # ID (Brand an version): Brother HL-L2360D series:84U-F75:Ver.b.26
     35 @PJL INFO PRODINFO    #Product info
     36 @PJL FSDIRLIST NAME="0:\" ENTRY=1 COUNT=65535  #List dir
     37 @PJL INFO VARIABLES   # Environment variables
     38 @PJL INFO FILESYS     #?
     39 @PJL INFO TIMEOUT     #Timeout variables
     40 @PJL RDYMSG           #Ready message
     41 @PJL FSINIT             # Potentially destructive filesystem initialization; do not issue during enumeration
     42 @PJL FSDIRLIST
     43 @PJL FSUPLOAD         # Read/upload a printer filesystem object to the client
     44 @PJL FSDOWNLOAD       # Send/download client data into the printer filesystem
     45 @PJL FSDELETE         #Useful to delete a file
     46 ```
     47 
     48 PJL filesystem commands are vendor- and model-dependent. `FSDELETE`, `FSDOWNLOAD`, and especially `FSINIT` can alter or destroy printer data, so begin with read-only `INFO`/`FSDIRLIST` requests and use write operations only with explicit authorization.<sup>[[4]](#references)</sup>
     49 
     50 ### Automatic
     51 
     52 ```bash
     53 nmap -sV --script pjl-ready-message -p <PORT> <IP>
     54 ```
     55 
     56 ```bash
     57 msf> use auxiliary/scanner/printer/printer_env_vars
     58 msf> use auxiliary/scanner/printer/printer_list_dir
     59 msf> use auxiliary/scanner/printer/printer_list_volumes
     60 msf> use auxiliary/scanner/printer/printer_ready_message
     61 msf> use auxiliary/scanner/printer/printer_version_info
     62 msf> use auxiliary/scanner/printer/printer_download_file
     63 msf> use auxiliary/scanner/printer/printer_upload_file
     64 msf> use auxiliary/scanner/printer/printer_delete_file
     65 ```
     66 
     67 ## Printers Hacking tool
     68 
     69 PRET automates PostScript, PJL, and PCL printer-security testing, including filesystem operations where supported.<sup>[[5]](#references)</sup>
     70 
     71 ## XPS/TrueType VM exploitation (Canon ImageCLASS)
     72 
     73 - Deliver XPS over PJL:<sup>[[2]](#references)</sup>
     74   - `@PJL ENTER LANGUAGE = XPS`
     75   - Then send the XPS ZIP bytes on the same TCP connection.
     76 
     77 - Minimal XPS page referencing an attacker font:
     78 
     79 ```xml
     80 <Glyphs Fill="#ff000000" FontUri="/Resources/evil.ttf" FontRenderingEmSize="12" OriginX="10" OriginY="10"/>
     81 ```
     82 
     83 - RCE primitive summary (TrueType hinting VM):<sup>[[2]](#references)[[3]](#references)</sup>
     84   - Hinting bytecode in TTF is executed by a TrueType VM. Canon’s VM lacked stack bounds checks.
     85   - CINDEX: OOB stack read → info leak
     86   - DELTAP1: unchecked relative stack pivot → controlled writes with subsequent pushes
     87   - Combine `WS`/`RS` (VM storage write/read) to stage values and perform a precise 32-bit write after pivot.
     88 
     89 - Exploit outline:
     90   1) Create XPS with the page above and include `/Resources/evil.ttf`.
     91   2) In `fpgm`/`prep`, use `CINDEX` to leak and compute `stack_cur`.
     92   3) Stage target value with `WS`; pivot with `DELTAP1` to the destination; use `RS` to write it (e.g., to a function pointer) to gain PC control.
     93 
     94 - Send over 9100/tcp:
     95 
     96 ```bash
     97 { printf "@PJL ENTER LANGUAGE = XPS\r\n"; cat exploit.xps; } | nc -q0 <PRINTER_IP> 9100
     98 ```
     99 
    100 - `exploit.xps` is a valid XPS ZIP containing `Documents/1/Pages/1.fpage` and `/Resources/evil.ttf`.
    101 
    102 ## **Shodan**
    103 
    104 - `pjl port:9100`
    105 
    106 ## References
    107 
    108 - [1] [Hacking Printers Wiki – Port 9100 (Raw) Printing](http://hacking-printers.net/wiki/index.php/Port_9100_printing)
    109 - [2] [Hacking printers using fonts (Canon ImageCLASS TrueType VM bugs)](https://haxx.in/posts/2025-09-23-canon-ttf/)
    110 - [3] [Apple TrueType Reference Manual – Instruction Set and VM (26.6 fixed point)](https://developer.apple.com/fonts/TrueType-Reference-Manual/RM05/Chap5.html)
    111 - [4] [HP — Printer Job Language Technical Reference Manual](https://developers.hp.com/system/files/attachments/PJL_Technical_Reference_Manual.pdf)
    112 - [5] [RUB-NDS/PRET — Printer Exploitation Toolkit](https://github.com/RUB-NDS/PRET)
    113 - [6] [Hacking Printers Wiki](http://hacking-printers.net/wiki/index.php/Main_Page)