Username enumeration

rlogin can leak which usernames exist through differences in its login handling. Depending on the implementation, a trusted-but-nonexistent user, an existing user without trust (prompted for a password), and a nonexistent user (rejected differently) produce distinguishable responses, so probing the -l <user> behaviour separates real accounts from invalid ones. A validated user list then focuses the trust-abuse and password attacks, you plant .rhosts for, or spray/capture against, accounts that actually exist, and reveals which accounts are already trusted (logging in with no password).

bash
# probe usernames and classify the response
for u in root admin oracle bin operator; do
  echo "== $u =="; rlogin -l "$u" <target> </dev/null 2>&1 | head -2; done
# distinguish: immediate shell (trusted+exists), password prompt (exists, no trust),
#   rejection/error (invalid user) - the differences enumerate valid accounts

Exploitation notes#

  • The useful distinction is three-way: a user who logs in with no password is both valid and trusted (immediate win), a user prompted for a password is valid but untrusted (target for capture/planting), and a differing rejection marks an invalid user.
  • Seed candidates from legacy-system conventions (root, oracle, operator, bin, application accounts) and any other enumeration, then validate here.
  • A discovered already-trusted account is a direct passwordless login, so username enumeration can surface the easiest path, not just a target list.
  • Feed validated users into rhosts bypass (plant trust) and cleartext password capture.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more