rsh

rsh runs a command (or an interactive shell) on a remote host via rshd on TCP 514. Its authentication is host-based: the server checks whether the connecting source IP and username are trusted via the target user's ~/.rhosts or the system-wide /etc/hosts.equiv, and if so, grants access with no password. This design is the whole vulnerability. An attacker who can make the server trust them, by writing a .rhosts entry, abusing a permissive hosts.equiv, or spoofing a trusted source address, runs commands as the target user with no credential, and because the channel is cleartext, any real session is also interceptable.

bash
# if trusted (or trust is permissive), run commands with no password
rsh -l <user> <target> id
rsh -l root <target> 'cat /etc/shadow'
# test reachability
nmap -p514 -sV <target>

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more