Traffic interception

None of the r-commands encrypt their traffic, so an on-path attacker reads everything they carry: the cleartext passwords that rexec and password-fallback rlogin send, every command executed and its full output, and complete interactive sessions. Beyond passive capture, the streams are authenticated only at setup, so they can be hijacked to inject commands as the authenticated user, and captured sessions can be replayed. Interception is frequently the easiest attack on legacy r-command deployments because it needs no credential guessing or trust manipulation, only a position on the network.

bash
# capture across the r-command ports
tcpdump -i eth0 -A 'port 512 or port 513 or port 514' -w rcmds.pcap
tshark -r rcmds.pcap -q -z follow,tcp,ascii,0

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more