9100-pjl.md (5630B)
1 --- 2 title: "9100/tcp - PJL (Printer Job Language)" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/9100-pjl.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/9100-pjl.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 9100/tcp - PJL (Printer Job Language) 14 15 ## Basic Information 16 17 From [here](http://hacking-printers.net/wiki/index.php/Port_9100_printing): Raw printing is what we define as the process of making a connection to port 9100/tcp of a network printer. It is the default method used by CUPS and the Windows printing architecture to communicate with network printers as it is considered as ‘_the simplest, fastest, and generally the most reliable network protocol used for printers_’. Raw port 9100 printing, also referred to as JetDirect, AppSocket or PDL-datastream actually **is not a printing protocol by itself**. Instead **all data sent is directly processed by the printing device**, just like a parallel connection over TCP. In contrast to LPD, IPP and SMB, this can send direct feedback to the client, including status and error messages. Such a **bidirectional channel** gives us direct **access** to **results** of **PJL**, **PostScript** or **PCL** commands. Therefore raw port 9100 printing – which is supported by almost any network printer – is used as the channel for security analysis with PRET and PFT.<sup>[[1]](#references)</sup> 18 19 For broader printer-assessment background, see the Hacking Printers wiki.<sup>[[6]](#references)</sup> 20 21 **Default port:** 9100 22 23 ```text 24 9100/tcp open jetdirect 25 ``` 26 27 ## Enumeration 28 29 ### Manual 30 31 ```bash 32 nc -vn <IP> 9100 33 @PJL INFO STATUS #CODE=40000 DISPLAY="Sleep" ONLINE=TRUE 34 @PJL INFO ID # ID (Brand an version): Brother HL-L2360D series:84U-F75:Ver.b.26 35 @PJL INFO PRODINFO #Product info 36 @PJL FSDIRLIST NAME="0:\" ENTRY=1 COUNT=65535 #List dir 37 @PJL INFO VARIABLES # Environment variables 38 @PJL INFO FILESYS #? 39 @PJL INFO TIMEOUT #Timeout variables 40 @PJL RDYMSG #Ready message 41 @PJL FSINIT # Potentially destructive filesystem initialization; do not issue during enumeration 42 @PJL FSDIRLIST 43 @PJL FSUPLOAD # Read/upload a printer filesystem object to the client 44 @PJL FSDOWNLOAD # Send/download client data into the printer filesystem 45 @PJL FSDELETE #Useful to delete a file 46 ``` 47 48 PJL filesystem commands are vendor- and model-dependent. `FSDELETE`, `FSDOWNLOAD`, and especially `FSINIT` can alter or destroy printer data, so begin with read-only `INFO`/`FSDIRLIST` requests and use write operations only with explicit authorization.<sup>[[4]](#references)</sup> 49 50 ### Automatic 51 52 ```bash 53 nmap -sV --script pjl-ready-message -p <PORT> <IP> 54 ``` 55 56 ```bash 57 msf> use auxiliary/scanner/printer/printer_env_vars 58 msf> use auxiliary/scanner/printer/printer_list_dir 59 msf> use auxiliary/scanner/printer/printer_list_volumes 60 msf> use auxiliary/scanner/printer/printer_ready_message 61 msf> use auxiliary/scanner/printer/printer_version_info 62 msf> use auxiliary/scanner/printer/printer_download_file 63 msf> use auxiliary/scanner/printer/printer_upload_file 64 msf> use auxiliary/scanner/printer/printer_delete_file 65 ``` 66 67 ## Printers Hacking tool 68 69 PRET automates PostScript, PJL, and PCL printer-security testing, including filesystem operations where supported.<sup>[[5]](#references)</sup> 70 71 ## XPS/TrueType VM exploitation (Canon ImageCLASS) 72 73 - Deliver XPS over PJL:<sup>[[2]](#references)</sup> 74 - `@PJL ENTER LANGUAGE = XPS` 75 - Then send the XPS ZIP bytes on the same TCP connection. 76 77 - Minimal XPS page referencing an attacker font: 78 79 ```xml 80 <Glyphs Fill="#ff000000" FontUri="/Resources/evil.ttf" FontRenderingEmSize="12" OriginX="10" OriginY="10"/> 81 ``` 82 83 - RCE primitive summary (TrueType hinting VM):<sup>[[2]](#references)[[3]](#references)</sup> 84 - Hinting bytecode in TTF is executed by a TrueType VM. Canon’s VM lacked stack bounds checks. 85 - CINDEX: OOB stack read → info leak 86 - DELTAP1: unchecked relative stack pivot → controlled writes with subsequent pushes 87 - Combine `WS`/`RS` (VM storage write/read) to stage values and perform a precise 32-bit write after pivot. 88 89 - Exploit outline: 90 1) Create XPS with the page above and include `/Resources/evil.ttf`. 91 2) In `fpgm`/`prep`, use `CINDEX` to leak and compute `stack_cur`. 92 3) Stage target value with `WS`; pivot with `DELTAP1` to the destination; use `RS` to write it (e.g., to a function pointer) to gain PC control. 93 94 - Send over 9100/tcp: 95 96 ```bash 97 { printf "@PJL ENTER LANGUAGE = XPS\r\n"; cat exploit.xps; } | nc -q0 <PRINTER_IP> 9100 98 ``` 99 100 - `exploit.xps` is a valid XPS ZIP containing `Documents/1/Pages/1.fpage` and `/Resources/evil.ttf`. 101 102 ## **Shodan** 103 104 - `pjl port:9100` 105 106 ## References 107 108 - [1] [Hacking Printers Wiki – Port 9100 (Raw) Printing](http://hacking-printers.net/wiki/index.php/Port_9100_printing) 109 - [2] [Hacking printers using fonts (Canon ImageCLASS TrueType VM bugs)](https://haxx.in/posts/2025-09-23-canon-ttf/) 110 - [3] [Apple TrueType Reference Manual – Instruction Set and VM (26.6 fixed point)](https://developer.apple.com/fonts/TrueType-Reference-Manual/RM05/Chap5.html) 111 - [4] [HP — Printer Job Language Technical Reference Manual](https://developers.hp.com/system/files/attachments/PJL_Technical_Reference_Manual.pdf) 112 - [5] [RUB-NDS/PRET — Printer Exploitation Toolkit](https://github.com/RUB-NDS/PRET) 113 - [6] [Hacking Printers Wiki](http://hacking-printers.net/wiki/index.php/Main_Page)