Shell protocols

The Berkeley r-commands are a family of legacy Unix remote-access services: rsh (remote shell, TCP 514), rlogin (remote login, TCP 513), and rexec (remote execution, TCP 512). They predate SSH and share two fatal weaknesses. First, no encryption: credentials, commands, and sessions travel in cleartext. Second, a host-based trust model, .rhosts and /etc/hosts.equiv files that grant passwordless access based on the client's source IP and username, which is authentication by spoofable network identity. The attack surface is therefore trust abuse (forging or planting trust to get passwordless shells), cleartext interception, and the per-command execution paths.

bash
nmap -p512,513,514 -sV <target>                # rexec, rlogin, rsh
# the services are often found together on legacy Unix

Subtopics#

  • rsh: remote shell on 514 and its trust abuse.
  • rlogin: remote login on 513.
  • rexec: remote execution on 512.
  • Trust abuse: .rhosts and hosts.equiv exploitation across the r-commands.
  • Traffic interception: cleartext capture and replay.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more