daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-631-internet-printing-protocol-ipp.md (10012B)


      1 ---
      2 title: "Internet Printing Protocol"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-631-internet-printing-protocol-ipp.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-631-internet-printing-protocol-ipp.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Internet Printing Protocol
     14 
     15 The **Internet Printing Protocol (IPP)** is the standard application protocol for network printing. The current IPP/1.1 specifications are RFC 8010 (encoding/transport) and RFC 8011 (model/semantics), which obsolete RFCs 2910 and 2911. IPP is carried over HTTP and supports print jobs, printer capability queries, and queue management. IPP-based profiles such as **IPP Everywhere** also support driverless printing, while PWG extensions reuse the model for additive-manufacturing/3D printers and bind the Cloud Imaging Model so printers can obtain jobs from shared network or cloud services.<sup>[[7]](#references)[[8]](#references)[[9]](#references)[[10]](#references)[[11]](#references)</sup>
     16 
     17 IPP normally uses **TCP/631**. UDP/631 is associated with legacy CUPS browsing/`cups-browsed` discovery rather than the IPP request transport itself. Exposing either surface can create risk on printers and Linux/Unix hosts running CUPS.<sup>[[3]](#references)[[7]](#references)</sup>
     18 
     19 ---
     20 ## Quick PoC – crafting raw IPP with Python
     21 ```python
     22 import struct
     23 import requests
     24 
     25 def attribute(tag, name, value):
     26     name = name.encode()
     27     value = value.encode()
     28     return bytes([tag]) + struct.pack(">H", len(name)) + name + struct.pack(">H", len(value)) + value
     29 
     30 printer_uri = "ipp://printer:631/ipp/print"
     31 ipp = struct.pack(">BBHI", 2, 0, 0x000B, 1)  # version 2.0, operation, request-id
     32 ipp += b"\x01"  # operation-attributes-tag
     33 ipp += attribute(0x47, "attributes-charset", "utf-8")
     34 ipp += attribute(0x48, "attributes-natural-language", "en")
     35 ipp += attribute(0x45, "printer-uri", printer_uri)
     36 ipp += b"\x03"  # end-of-attributes
     37 
     38 r = requests.post("http://printer:631/ipp/print", headers={"Content-Type": "application/ipp"}, data=ipp)
     39 print(r.status_code, r.content[:40])
     40 ```
     41 ---
     42 ## Enumeration & Recon
     43 
     44 ### 1. Nmap NSE
     45 ```bash
     46 # run all CUPS/IPP scripts
     47 nmap -sV -p631 --script=cups* <target>
     48 # or only basic info
     49 nmap -p631 --script=cups-info,cups-queue-info <target>
     50 ```
     51 The `cups-info` script extracts model, state and queue statistics while `cups-queue-info` enumerates pending jobs.
     52 
     53 ### 2. IPP utilities from CUPS
     54 * `ippfind` – multicast/UDP discovery (works against cups-browsed):
     55   ```bash
     56   ippfind --timeout 3 --txt -v "@local and port=631"  # list printers
     57   ```
     58 * `ipptool` – arbitrary requests defined in a *.test* file:
     59   ```bash
     60   ipptool -tv ipp://<IP>/ipp/print get-printer-attributes.test
     61   ```
     62   The bundled *get-printer-attributes.test* file queries firmware version, supported document formats, etc.
     63 
     64 ### 3. Shodan / Censys dorks
     65 ```bash
     66 shodan search 'product:"CUPS (IPP)" port:631'
     67 ```
     68 More than **70 000** hosts were publicly exposing CUPS in April 2025.<sup>[[1]](#references)</sup>
     69 
     70 ### 4. Emulating a rogue IPP printer in the lab
     71 For client-side testing you do not need real hardware: `ippeveprinter` exposes a minimal IPP Everywhere server, can advertise itself over DNS-SD, optionally require HTTP Basic auth with `-A`, and can either write rendered jobs to a directory with `-D` or execute a helper for every printed document with `-c`.<sup>[[4]](#references)</sup>
     72 
     73 ```bash
     74 mkdir -p /tmp/ipp-spool /tmp/ipp-out
     75 
     76 # Save rendered jobs into /tmp/ipp-out and listen on TCP/8631
     77 ippeveprinter -v -p 8631 -d /tmp/ipp-spool -D /tmp/ipp-out \
     78   -f application/pdf,image/jpeg,image/pwg-raster "LabPrinter"
     79 
     80 # Auth-enabled variant for testing client credential prompts
     81 ippeveprinter -v -A -p 8631 "AuthLabPrinter"
     82 ```
     83 
     84 ---
     85 ## Recent Vulnerabilities (2023-2025)
     86 
     87 | Year | CVE ID(s) | Affected component | Impact |
     88 |------|-----------|--------------------|--------|
     89 | 2024 | CVE-2023-50739 | Lexmark firmware (IPP parser) | Heap-overflow → RCE over Wi-Fi/LAN<sup>[[5]](#references)</sup> |
     90 | 2024 | CVE-2024-47076, 47175, 47176, 47177 | cups-browsed, libcupsfilters, libppd, cups-filters | Unauthenticated rogue-printer installation leading to command execution when a victim prints<sup>[[3]](#references)</sup> |
     91 | 2024 | CVE-2024-35235 | cupsd before the vendor fix | Symlink-assisted permission change that can support local privilege escalation<sup>[[2]](#references)</sup> |
     92 | 2023 | CVE-2023-0856 (Canon) + Pwn2Own | Stack-overflow in `sides` attribute → remote code execution<sup>[[6]](#references)</sup> |
     93 
     94 ### cups-browsed RCE chain (September 2024)
     95 The 2024 `cups-browsed` bug chain is the most practical modern IPP attack path against UNIX endpoints.<sup>[[3]](#references)</sup>
     96 
     97 1. `cups-browsed` listens on **UDP/631** for printer advertisements.
     98 2. An attacker sends a single spoofed packet pointing to a malicious IPP URL (CVE-2024-47176).
     99 3. `libcupsfilters` automatically fetches the remote **PPD** without validation (CVE-2024-47076 & 47175).
    100 4. A crafted PPD abuses the **foomatic-rip** filter to execute arbitrary shell commands whenever anything is printed (CVE-2024-47177).
    101 
    102 Public PoCs exist, and the attacker can either auto-install a new rogue printer or silently replace an existing printer URI so the payload triggers on the next print job.<sup>[[3]](#references)</sup>
    103 
    104 On LANs, the same path can be reached by spoofing Zeroconf/mDNS/DNS-SD advertisements instead of attacking a public UDP/631 listener directly, so it is worth pairing this with [mDNS/DNS-SD abuse](/hacktricks/network-services-pentesting/5353-udp-multicast-dns-mdns) during local network operations.<sup>[[3]](#references)</sup>
    105 
    106 Execution normally happens when a user prints to the malicious queue, and the resulting code runs in the `lp` context on default Linux installs.<sup>[[3]](#references)</sup>
    107 
    108 #### Temporary mitigations
    109 ```bash
    110 sudo systemctl stop cups-browsed
    111 sudo systemctl disable cups-browsed
    112 sudo ufw deny 631/udp  # or equivalent firewall rule
    113 ```
    114 Update the whole printing stack together — `cups-browsed`, `libcupsfilters`/`cups-filters`, `libppd`, and CUPS — instead of treating this as a single-package issue.<sup>[[1]](#references)[[3]](#references)</sup>
    115 
    116 Install the coordinated fixed packages supplied by the target distribution. Do not rely on a single upstream version number because affected components and backported fixes vary by distribution.<sup>[[1]](#references)[[3]](#references)</sup>
    117 
    118 ### cupsd symlink `Listen` misconfiguration (CVE-2024-35235)
    119 Placing a symbolic link in *cupsd.conf*'s `Listen` directive can make `cupsd` (often running as root) change permissions on an attacker-chosen path to world-writable, which is a solid local privilege-escalation primitive when you can influence the configuration or win the bind-time race.<sup>[[2]](#references)</sup>
    120 
    121 ---
    122 ## Offensive Techniques
    123 
    124 * **Rogue printer replacement / auto-install** – abuse `cups-browsed` discovery over UDP/631 or spoofed DNS-SD to register a malicious printer or replace a trusted printer URI, then wait for the next print job to reach attacker-controlled IPP metadata.<sup>[[3]](#references)</sup>
    125 * **Unauthenticated raw print job** – test whether the printer accepts `POST /ipp/print` without authorization. Some PostScript-capable devices expose unsafe interpreter extensions, but `system(...)` command execution is device/firmware-specific and is not guaranteed by PostScript or IPP.
    126 * **Job hijacking** – if authorization checks are missing, operations such as `Cancel-Job` and `Send-Document` may let an attacker disrupt or replace another user's job. The operation names alone do not bypass access control.<sup>[[8]](#references)</sup>
    127 * **SNMP → IPP combination** – a default SNMP community such as `public` may reveal the queue or printer URI needed for subsequent IPP testing.
    128 
    129 ---
    130 ## Defensive Best Practices
    131 1. Patch CUPS and printer firmware promptly; subscribe to vendor PSIRT feeds.
    132 2. Disable `cups-browsed` and UDP/631 unless zeroconf printing is required.
    133 3. Restrict TCP/631 to trusted subnets/VPN and enforce **TLS (ipps://)**.
    134 4. Require **Kerberos/Negotiate** or certificate auth instead of anonymous printing.
    135 5. Monitor logs: `/var/log/cups/error_log` with `LogLevel debug2` can reveal unsolicited PPD downloads or suspicious filter invocations.
    136 6. In high-security networks, move printing to a hardened, isolated print server that proxies jobs to devices via USB only.
    137 
    138 ## References
    139 - [1] [Akamai SIG — Critical Linux RCE Vulnerability in CUPS — What We Know and How to Prepare](https://www.akamai.com/blog/security-research/guidance-on-critical-cups-rce)
    140 - [2] [Debian Security Tracker — CVE-2024-35235](https://security-tracker.debian.org/tracker/CVE-2024-35235)
    141 - [3] [Simone Margaritelli — Attacking UNIX Systems via CUPS, Part I](https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/)
    142 - [4] [ippeveprinter(1) — Linux manual page](https://man7.org/linux/man-pages/man1/ippeveprinter.1.html)
    143 - [5] [Lexmark Security Advisory - CVE-2023-50739](https://publications.lexmark.com/publications/security-alerts/CVE-2023-50739.pdf)
    144 - [6] [ZDI-23-556: Canon imageCLASS MF743Cdw IPP sides Stack-based Buffer Overflow RCE](https://www.zerodayinitiative.com/advisories/ZDI-23-556/)
    145 - [7] [RFC 8010 - IPP/1.1 Encoding and Transport](https://www.rfc-editor.org/rfc/rfc8010.html)
    146 - [8] [RFC 8011 - IPP/1.1 Model and Semantics](https://www.rfc-editor.org/rfc/rfc8011.html)
    147 - [9] [OpenPrinting - Driverless Printing](https://openprinting.github.io/driverless)
    148 - [10] [Printer Working Group - 3D Printing](https://pwg.org/3d/index.html)
    149 - [11] [PWG 5100.18-2025 - IPP Shared Infrastructure Extensions v1.1](https://ftp.pwg.org/pub/pwg/candidates/cs-ippinfra11-20250502-5100.18.pdf)