Each user can grant passwordless r-command access by listing trusted host user pairs in their ~/.rhosts file; a matching connection is accepted with no password. The offensive use is to create or extend that trust. If an attacker can write a target user's .rhosts, via a file-write vulnerability, a writable home directory (commonly over NFS), or an existing foothold as another user, they add an entry trusting their own host and username, then rsh/rlogin in as the target with no credential. The wildcard entry + + trusts every host and user, turning the account into an open door. This doubles as persistence.
# plant trust in the target user's .rhosts (requires a write to their home)
echo '+ +' >> /mnt/nfs-home/victim/.rhosts # trust everyone (open door)
echo 'attacker-host attacker-user' >> ~victim/.rhosts # trust a specific identity
# then log in / run commands with no password
rlogin -l victim <target>
rsh -l victim <target> id
Exploitation notes#
- The precondition is a write to the target's
.rhosts; pair with any home-directory write primitive (an NFS UID-spoof write, a writable share, or a foothold), which is exactly why writable home directories are dangerous with r-commands enabled. + +is the maximal entry (any host, any user); a targetedhost userentry is stealthier.- This is both access and persistence: the planted trust survives and grants passwordless re-entry until the file is cleaned.
- The same
.rhostsmechanism serves rsh, rlogin, and rexec; see rhosts write for the write technique in the trust-abuse view.