pentesting-631-internet-printing-protocol-ipp.md (10012B)
1 --- 2 title: "Internet Printing Protocol" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-631-internet-printing-protocol-ipp.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-631-internet-printing-protocol-ipp.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Internet Printing Protocol 14 15 The **Internet Printing Protocol (IPP)** is the standard application protocol for network printing. The current IPP/1.1 specifications are RFC 8010 (encoding/transport) and RFC 8011 (model/semantics), which obsolete RFCs 2910 and 2911. IPP is carried over HTTP and supports print jobs, printer capability queries, and queue management. IPP-based profiles such as **IPP Everywhere** also support driverless printing, while PWG extensions reuse the model for additive-manufacturing/3D printers and bind the Cloud Imaging Model so printers can obtain jobs from shared network or cloud services.<sup>[[7]](#references)[[8]](#references)[[9]](#references)[[10]](#references)[[11]](#references)</sup> 16 17 IPP normally uses **TCP/631**. UDP/631 is associated with legacy CUPS browsing/`cups-browsed` discovery rather than the IPP request transport itself. Exposing either surface can create risk on printers and Linux/Unix hosts running CUPS.<sup>[[3]](#references)[[7]](#references)</sup> 18 19 --- 20 ## Quick PoC – crafting raw IPP with Python 21 ```python 22 import struct 23 import requests 24 25 def attribute(tag, name, value): 26 name = name.encode() 27 value = value.encode() 28 return bytes([tag]) + struct.pack(">H", len(name)) + name + struct.pack(">H", len(value)) + value 29 30 printer_uri = "ipp://printer:631/ipp/print" 31 ipp = struct.pack(">BBHI", 2, 0, 0x000B, 1) # version 2.0, operation, request-id 32 ipp += b"\x01" # operation-attributes-tag 33 ipp += attribute(0x47, "attributes-charset", "utf-8") 34 ipp += attribute(0x48, "attributes-natural-language", "en") 35 ipp += attribute(0x45, "printer-uri", printer_uri) 36 ipp += b"\x03" # end-of-attributes 37 38 r = requests.post("http://printer:631/ipp/print", headers={"Content-Type": "application/ipp"}, data=ipp) 39 print(r.status_code, r.content[:40]) 40 ``` 41 --- 42 ## Enumeration & Recon 43 44 ### 1. Nmap NSE 45 ```bash 46 # run all CUPS/IPP scripts 47 nmap -sV -p631 --script=cups* <target> 48 # or only basic info 49 nmap -p631 --script=cups-info,cups-queue-info <target> 50 ``` 51 The `cups-info` script extracts model, state and queue statistics while `cups-queue-info` enumerates pending jobs. 52 53 ### 2. IPP utilities from CUPS 54 * `ippfind` – multicast/UDP discovery (works against cups-browsed): 55 ```bash 56 ippfind --timeout 3 --txt -v "@local and port=631" # list printers 57 ``` 58 * `ipptool` – arbitrary requests defined in a *.test* file: 59 ```bash 60 ipptool -tv ipp://<IP>/ipp/print get-printer-attributes.test 61 ``` 62 The bundled *get-printer-attributes.test* file queries firmware version, supported document formats, etc. 63 64 ### 3. Shodan / Censys dorks 65 ```bash 66 shodan search 'product:"CUPS (IPP)" port:631' 67 ``` 68 More than **70 000** hosts were publicly exposing CUPS in April 2025.<sup>[[1]](#references)</sup> 69 70 ### 4. Emulating a rogue IPP printer in the lab 71 For client-side testing you do not need real hardware: `ippeveprinter` exposes a minimal IPP Everywhere server, can advertise itself over DNS-SD, optionally require HTTP Basic auth with `-A`, and can either write rendered jobs to a directory with `-D` or execute a helper for every printed document with `-c`.<sup>[[4]](#references)</sup> 72 73 ```bash 74 mkdir -p /tmp/ipp-spool /tmp/ipp-out 75 76 # Save rendered jobs into /tmp/ipp-out and listen on TCP/8631 77 ippeveprinter -v -p 8631 -d /tmp/ipp-spool -D /tmp/ipp-out \ 78 -f application/pdf,image/jpeg,image/pwg-raster "LabPrinter" 79 80 # Auth-enabled variant for testing client credential prompts 81 ippeveprinter -v -A -p 8631 "AuthLabPrinter" 82 ``` 83 84 --- 85 ## Recent Vulnerabilities (2023-2025) 86 87 | Year | CVE ID(s) | Affected component | Impact | 88 |------|-----------|--------------------|--------| 89 | 2024 | CVE-2023-50739 | Lexmark firmware (IPP parser) | Heap-overflow → RCE over Wi-Fi/LAN<sup>[[5]](#references)</sup> | 90 | 2024 | CVE-2024-47076, 47175, 47176, 47177 | cups-browsed, libcupsfilters, libppd, cups-filters | Unauthenticated rogue-printer installation leading to command execution when a victim prints<sup>[[3]](#references)</sup> | 91 | 2024 | CVE-2024-35235 | cupsd before the vendor fix | Symlink-assisted permission change that can support local privilege escalation<sup>[[2]](#references)</sup> | 92 | 2023 | CVE-2023-0856 (Canon) + Pwn2Own | Stack-overflow in `sides` attribute → remote code execution<sup>[[6]](#references)</sup> | 93 94 ### cups-browsed RCE chain (September 2024) 95 The 2024 `cups-browsed` bug chain is the most practical modern IPP attack path against UNIX endpoints.<sup>[[3]](#references)</sup> 96 97 1. `cups-browsed` listens on **UDP/631** for printer advertisements. 98 2. An attacker sends a single spoofed packet pointing to a malicious IPP URL (CVE-2024-47176). 99 3. `libcupsfilters` automatically fetches the remote **PPD** without validation (CVE-2024-47076 & 47175). 100 4. A crafted PPD abuses the **foomatic-rip** filter to execute arbitrary shell commands whenever anything is printed (CVE-2024-47177). 101 102 Public PoCs exist, and the attacker can either auto-install a new rogue printer or silently replace an existing printer URI so the payload triggers on the next print job.<sup>[[3]](#references)</sup> 103 104 On LANs, the same path can be reached by spoofing Zeroconf/mDNS/DNS-SD advertisements instead of attacking a public UDP/631 listener directly, so it is worth pairing this with [mDNS/DNS-SD abuse](/hacktricks/network-services-pentesting/5353-udp-multicast-dns-mdns) during local network operations.<sup>[[3]](#references)</sup> 105 106 Execution normally happens when a user prints to the malicious queue, and the resulting code runs in the `lp` context on default Linux installs.<sup>[[3]](#references)</sup> 107 108 #### Temporary mitigations 109 ```bash 110 sudo systemctl stop cups-browsed 111 sudo systemctl disable cups-browsed 112 sudo ufw deny 631/udp # or equivalent firewall rule 113 ``` 114 Update the whole printing stack together — `cups-browsed`, `libcupsfilters`/`cups-filters`, `libppd`, and CUPS — instead of treating this as a single-package issue.<sup>[[1]](#references)[[3]](#references)</sup> 115 116 Install the coordinated fixed packages supplied by the target distribution. Do not rely on a single upstream version number because affected components and backported fixes vary by distribution.<sup>[[1]](#references)[[3]](#references)</sup> 117 118 ### cupsd symlink `Listen` misconfiguration (CVE-2024-35235) 119 Placing a symbolic link in *cupsd.conf*'s `Listen` directive can make `cupsd` (often running as root) change permissions on an attacker-chosen path to world-writable, which is a solid local privilege-escalation primitive when you can influence the configuration or win the bind-time race.<sup>[[2]](#references)</sup> 120 121 --- 122 ## Offensive Techniques 123 124 * **Rogue printer replacement / auto-install** – abuse `cups-browsed` discovery over UDP/631 or spoofed DNS-SD to register a malicious printer or replace a trusted printer URI, then wait for the next print job to reach attacker-controlled IPP metadata.<sup>[[3]](#references)</sup> 125 * **Unauthenticated raw print job** – test whether the printer accepts `POST /ipp/print` without authorization. Some PostScript-capable devices expose unsafe interpreter extensions, but `system(...)` command execution is device/firmware-specific and is not guaranteed by PostScript or IPP. 126 * **Job hijacking** – if authorization checks are missing, operations such as `Cancel-Job` and `Send-Document` may let an attacker disrupt or replace another user's job. The operation names alone do not bypass access control.<sup>[[8]](#references)</sup> 127 * **SNMP → IPP combination** – a default SNMP community such as `public` may reveal the queue or printer URI needed for subsequent IPP testing. 128 129 --- 130 ## Defensive Best Practices 131 1. Patch CUPS and printer firmware promptly; subscribe to vendor PSIRT feeds. 132 2. Disable `cups-browsed` and UDP/631 unless zeroconf printing is required. 133 3. Restrict TCP/631 to trusted subnets/VPN and enforce **TLS (ipps://)**. 134 4. Require **Kerberos/Negotiate** or certificate auth instead of anonymous printing. 135 5. Monitor logs: `/var/log/cups/error_log` with `LogLevel debug2` can reveal unsolicited PPD downloads or suspicious filter invocations. 136 6. In high-security networks, move printing to a hardened, isolated print server that proxies jobs to devices via USB only. 137 138 ## References 139 - [1] [Akamai SIG — Critical Linux RCE Vulnerability in CUPS — What We Know and How to Prepare](https://www.akamai.com/blog/security-research/guidance-on-critical-cups-rce) 140 - [2] [Debian Security Tracker — CVE-2024-35235](https://security-tracker.debian.org/tracker/CVE-2024-35235) 141 - [3] [Simone Margaritelli — Attacking UNIX Systems via CUPS, Part I](https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/) 142 - [4] [ippeveprinter(1) — Linux manual page](https://man7.org/linux/man-pages/man1/ippeveprinter.1.html) 143 - [5] [Lexmark Security Advisory - CVE-2023-50739](https://publications.lexmark.com/publications/security-alerts/CVE-2023-50739.pdf) 144 - [6] [ZDI-23-556: Canon imageCLASS MF743Cdw IPP sides Stack-based Buffer Overflow RCE](https://www.zerodayinitiative.com/advisories/ZDI-23-556/) 145 - [7] [RFC 8010 - IPP/1.1 Encoding and Transport](https://www.rfc-editor.org/rfc/rfc8010.html) 146 - [8] [RFC 8011 - IPP/1.1 Model and Semantics](https://www.rfc-editor.org/rfc/rfc8011.html) 147 - [9] [OpenPrinting - Driverless Printing](https://openprinting.github.io/driverless) 148 - [10] [Printer Working Group - 3D Printing](https://pwg.org/3d/index.html) 149 - [11] [PWG 5100.18-2025 - IPP Shared Infrastructure Extensions v1.1](https://ftp.pwg.org/pub/pwg/candidates/cs-ippinfra11-20250502-5100.18.pdf)