Every r-command exchange carries its payload in cleartext: for rsh/rexec the command and arguments and their output, and for rlogin the whole interactive session. A positioned attacker reconstructs all of it, learning exactly what was executed, seeing the results, and capturing any sensitive data or secondary credentials that pass through (a command that prints a config with secrets, a su/sudo password typed in an rlogin session, data read from files). This frequently yields more than a captured login, because administrative commands and their output expose the systems and secrets the operator was working with.
# capture and reconstruct the command/output content
tcpdump -i eth0 -A 'port 513 or port 514' -w content.pcap
tshark -r content.pcap -q -z follow,tcp,ascii,0 # command (c->s) and output (s->c)
Exploitation notes#
- Content capture often beats the login: executed commands and their output reveal configuration, secrets printed to the terminal, and secondary credentials entered mid-session.
- For rsh/rexec the key direction is client-to-server (the command) and server-to-client (the output); for rlogin reconstruct the full bidirectional session.
- This is passive and quiet; pair with password sniffing from the same capture for credentials plus content, and with session replay or hijacking for active use.
- Needs an on-path/tap position; legacy r-command segments are typically flat and easily intercepted.