rlogin opens an interactive login session on a remote host via rlogind on TCP 513. It authenticates the same way as rsh, host-based trust through ~/.rhosts and /etc/hosts.equiv, and falls back to a cleartext password prompt when trust does not apply. The attacks follow: passwordless login by abusing or planting trust, capture of the cleartext password and the entire session when a password is used, username enumeration from how the login responds, and hijacking the live cleartext session. Because it grants an interactive shell, a successful rlogin is a direct foothold.
# trusted login (no password) or password login
rlogin -l <user> <target>
nmap -p513 -sV <target>
Subtopics#
- rhosts bypass: passwordless login via host trust.
- Cleartext passwords: capturing the password when trust is not used.
- Username enumeration: discovering valid users from login behaviour.
- Session hijacking: taking over the live rlogin session.