rexec

rexec executes a command on a remote host via rexecd on TCP 512. Unlike rsh, it was designed around a username/password, sent in cleartext, and some implementations also honour the host-based trust files. The attacks follow from those two facts. The cleartext credential is captured by a positioned attacker. Trusted-host relationships, where honoured, give passwordless command execution just as with rsh. And where the server or a wrapper builds the executed command from attacker-influenced input unsafely, command injection extends what runs. A successful rexec runs a command as the authenticated user.

bash
# run a command with credentials (sent in cleartext)
rexec -l <user> -p <password> <target> id
nmap -p512 -sV <target>

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more