Although rexec is password-based by design, the Berkeley trust model frequently overlaps: systems running rexec usually run rsh too, honouring ~/.rhosts and /etc/hosts.equiv, and an attacker who establishes trust executes commands with no password through that trusted path. The techniques are the shared ones, connect from or spoof a trusted host, or plant a .rhosts entry where the target home is writable, after which command execution needs no credential. This sidesteps the cleartext password entirely and is the stronger route when trust can be obtained.
# if trust applies (or via the co-located rsh path), execute with no password
rsh -l <user> <target> id # trusted-host execution, no credential
# plant trust first where the home is writable
echo '+ +' >> ~victim/.rhosts
# then run commands as victim with no password
Exploitation notes#
- rexec hosts almost always also expose rsh/rlogin with the same trust files, so trust abuse established for one applies to all; the rhosts and hosts.equiv techniques carry over directly.
- Trust removes the password requirement that rexec otherwise imposes, so obtaining trust is preferable to capturing or guessing the credential.
- Planting
.rhostsneeds a home-directory write; a permissivehosts.equivor a spoofable trusted host needs no write at all. - Where trust cannot be obtained, fall back to capturing the cleartext password.