daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-information-in-printers.md (6891B)


      1 ---
      2 title: "Information in Printers"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/ad-information-in-printers.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/ad-information-in-printers.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Information in Printers
     14 
     15 There are several blogs in the Internet which **highlight the dangers of leaving printers configured with LDAP with default/weak** logon credentials.  \
     16 This is because an attacker could **trick the printer to authenticate against a rogue LDAP server** (typically a `nc -vv -l -p 389` or `slapd -d 2` is enough) and capture the printer **credentials in clear-text**.
     17 
     18 Also, several printers will contain **logs with usernames** or could even be able to **download all usernames** from the Domain Controller.
     19 
     20 All this **sensitive information** and the common **lack of security** makes printers very interesting for attackers.
     21 
     22 Some introductory blogs about the topic:
     23 
     24 - [https://www.ceos3c.com/hacking/obtaining-domain-credentials-printer-netcat/](https://www.ceos3c.com/hacking/obtaining-domain-credentials-printer-netcat/)<sup>[[4]](#references)</sup>
     25 - [https://medium.com/@nickvangilder/exploiting-multifunction-printers-during-a-penetration-test-engagement-28d3840d8856](https://medium.com/@nickvangilder/exploiting-multifunction-printers-during-a-penetration-test-engagement-28d3840d8856)<sup>[[5]](#references)</sup>
     26 
     27 ---
     28 
     29 ## Printer Configuration
     30 
     31 - **Location**: The LDAP server list is usually found in the web interface (e.g. *Network ➜ LDAP Setting ➜ Setting Up LDAP*).
     32 - **Behavior**: Many embedded web servers allow LDAP server modifications **without re-entering credentials** (usability feature → security risk).
     33 - **Exploit**: Redirect the LDAP server address to an attacker-controlled host and use the *Test Connection* / *Address Book Sync* button to force the printer to bind to you.
     34 
     35 ---
     36 
     37 ## Capturing Credentials
     38 
     39 ### Method 1 – Netcat Listener
     40 
     41 ```bash
     42 sudo nc -k -v -l -p 389     # LDAPS → 636 (or 3269)
     43 ```
     44 
     45 Small/old MFPs may send a simple *simple-bind* in clear-text that netcat can capture. Modern devices usually perform an anonymous query first and then attempt the bind, so results vary.<sup>[[1]](#references)</sup>
     46 
     47 ### Method 2 – Full Rogue LDAP server (recommended)
     48 
     49 Because many devices will issue an anonymous search *before* authenticating, standing up a real LDAP daemon yields much more reliable results:<sup>[[1]](#references)</sup>
     50 
     51 ```bash
     52 # Debian/Ubuntu example
     53 sudo apt install slapd ldap-utils
     54 sudo dpkg-reconfigure slapd   # set any base-DN – it will not be validated
     55 
     56 # run slapd in foreground / debug 2
     57 slapd -d 2 -h "ldap:///"      # only LDAP, no LDAPS
     58 ```
     59 
     60 When the printer performs its lookup you will see the clear-text credentials in the debug output.
     61 
     62 > 💡  You can also use `impacket/examples/ldapd.py` (Python rogue LDAP) or `Responder -w -r -f` to harvest NTLMv2 hashes over LDAP/SMB.
     63 
     64 ---
     65 
     66 ## Recent Pass-Back Vulnerabilities (2024-2025)
     67 
     68 Pass-back is *not* a theoretical issue – vendors keep publishing advisories in 2024/2025 that exactly describe this attack class.
     69 
     70 ### Xerox VersaLink – CVE-2024-12510 & CVE-2024-12511
     71 
     72 Firmware ≤ 57.69.91 of Xerox VersaLink C70xx MFPs allowed an authenticated admin (or anyone when default creds remain) to:
     73 
     74 * **CVE-2024-12510 – LDAP pass-back**: change the LDAP server address and trigger a lookup, causing the device to leak the configured Windows credentials to the attacker-controlled host.
     75 * **CVE-2024-12511 – SMB/FTP pass-back**: identical issue via *scan-to-folder* destinations, leaking NetNTLMv2 or FTP clear-text creds.<sup>[[2]](#references)</sup>
     76 
     77 A simple listener such as:
     78 
     79 ```bash
     80 sudo nc -k -v -l -p 389     # capture LDAP bind
     81 ```
     82 
     83 or a rogue SMB server (`impacket-smbserver`) is enough to harvest the credentials.  
     84 
     85 ### Canon imageRUNNER / imageCLASS – Advisory 20 May 2025
     86 
     87 Canon confirmed a **SMTP/LDAP pass-back** weakness in dozens of Laser & MFP product lines. An attacker with admin access can modify the server configuration and retrieve the stored credentials for LDAP **or** SMTP (many orgs use a privileged account to allow scan-to-mail).<sup>[[3]](#references)</sup>
     88 
     89 The vendor guidance explicitly recommends:
     90 
     91 1. Updating to patched firmware as soon as available.
     92 2. Using strong, unique admin passwords.
     93 3. Avoiding privileged AD accounts for printer integration.
     94 
     95 ---
     96 
     97 ## Automated Enumeration / Exploitation Tools
     98 
     99 | Tool | Purpose | Example |
    100 |------|---------|---------|
    101 | **PRET** (Printer Exploitation Toolkit) | PostScript/PJL/PCL abuse, file-system access, default-creds check, *SNMP discovery* | `python pret.py 192.168.1.50 pjl` |
    102 | **Praeda** | Harvest configuration (including address books & LDAP creds) via HTTP/HTTPS | `perl praeda.pl -t 192.168.1.50` |
    103 | **Responder / ntlmrelayx** | Capture & relay NetNTLM hashes from SMB/FTP pass-back | `responder -I eth0 -wrf` |
    104 | **impacket-ldapd.py** | Lightweight rogue LDAP service to receive clear-text binds | `python ldapd.py -debug` |
    105 
    106 ---
    107 
    108 ## Hardening & Detection
    109 
    110 1. **Patch / firmware-update** MFPs promptly (check vendor PSIRT bulletins).
    111 2. **Least-Privilege Service Accounts** – never use Domain Admin for LDAP/SMB/SMTP; restrict to *read-only* OU scopes.
    112 3. **Restrict Management Access** – place printer web/IPP/SNMP interfaces in a management VLAN or behind an ACL/VPN.
    113 4. **Disable Unused Protocols** – FTP, Telnet, raw-9100, older SSL ciphers.
    114 5. **Enable Audit Logging** – some devices can syslog LDAP/SMTP failures; correlate unexpected binds.
    115 6. **Monitor for Clear-Text LDAP binds** on unusual sources (printers should normally talk only to DCs).
    116 7. **SNMPv3 or disable SNMP** – community `public` often leaks device & LDAP config.
    117 
    118 ---
    119 
    120 ## References
    121 
    122 - [1] [It's just a printer… What's the worst that could happen?](https://grimhacker.com/2018/03/09/just-a-printer/)
    123 - [2] [Xerox Versalink C7025 Multifunction Printer: Pass-Back Attack Vulnerabilities (Fixed)](https://www.rapid7.com/blog/post/2025/02/14/xerox-versalink-c7025-multifunction-printer-pass-back-attack-vulnerabilities-fixed/)
    124 - [3] [CP2025-004 Vulnerability Mitigation/Remediation for Production Printers, Office/Small Office Multifunction Printers and Laser Printers](https://psirt.canon/advisory-information/cp2025-004/)
    125 - [4] [Obtaining Domain Credentials through a Printer with Netcat](https://www.ceos3c.com/hacking/obtaining-domain-credentials-printer-netcat/)
    126 - [5] [Exploiting Multifunction Printers During A Penetration Test Engagement](https://medium.com/@nickvangilder/exploiting-multifunction-printers-during-a-penetration-test-engagement-28d3840d8856)