rlogin can leak which usernames exist through differences in its login handling. Depending on the implementation, a trusted-but-nonexistent user, an existing user without trust (prompted for a password), and a nonexistent user (rejected differently) produce distinguishable responses, so probing the -l <user> behaviour separates real accounts from invalid ones. A validated user list then focuses the trust-abuse and password attacks, you plant .rhosts for, or spray/capture against, accounts that actually exist, and reveals which accounts are already trusted (logging in with no password).
# probe usernames and classify the response
for u in root admin oracle bin operator; do
echo "== $u =="; rlogin -l "$u" <target> </dev/null 2>&1 | head -2; done
# distinguish: immediate shell (trusted+exists), password prompt (exists, no trust),
# rejection/error (invalid user) - the differences enumerate valid accounts
Exploitation notes#
- The useful distinction is three-way: a user who logs in with no password is both valid and trusted (immediate win), a user prompted for a password is valid but untrusted (target for capture/planting), and a differing rejection marks an invalid user.
- Seed candidates from legacy-system conventions (
root,oracle,operator,bin, application accounts) and any other enumeration, then validate here. - A discovered already-trusted account is a direct passwordless login, so username enumeration can surface the easiest path, not just a target list.
- Feed validated users into rhosts bypass (plant trust) and cleartext password capture.