rsh runs a command (or an interactive shell) on a remote host via rshd on TCP 514. Its authentication is host-based: the server checks whether the connecting source IP and username are trusted via the target user's ~/.rhosts or the system-wide /etc/hosts.equiv, and if so, grants access with no password. This design is the whole vulnerability. An attacker who can make the server trust them, by writing a .rhosts entry, abusing a permissive hosts.equiv, or spoofing a trusted source address, runs commands as the target user with no credential, and because the channel is cleartext, any real session is also interceptable.
# if trusted (or trust is permissive), run commands with no password
rsh -l <user> <target> id
rsh -l root <target> 'cat /etc/shadow'
# test reachability
nmap -p514 -sV <target>
Subtopics#
- rhosts bypass: passwordless access via .rhosts trust.
- hosts.equiv: system-wide trust abuse.
- IP spoofing: impersonating a trusted source address.
- Cleartext interception: capturing the unencrypted session.