Password sniffing

Where the r-commands use a password, rexec always, rlogin when host trust does not grant access, that password is sent in cleartext, so a positioned attacker captures it straight from the stream. rexec includes the username and password in each execution request (so every invocation is a capture opportunity), and rlogin's fallback password prompt is sent character by character and reassembled. The result is a reusable account credential obtained quietly, no brute force, no failed-login records, no lockout, and such credentials are typically reused across the legacy environment.

bash
# capture credentials from rexec (512) and rlogin (513)
tcpdump -i eth0 -A 'port 512 or port 513' -w creds.pcap
tshark -r creds.pcap -q -z follow,tcp,ascii,0     # username/password in the stream

Exploitation notes#

  • rexec is the richest source because it transmits the credential with every command, so scripted/automated rexec usage leaks it repeatedly; rlogin leaks only when it falls back to a password (not when host trust applies).
  • Reassemble the client-to-server bytes (rlogin sends per-character) to recover the typed password; tshark/Wireshark do this automatically.
  • Captured credentials are reusable on the host and across legacy systems; test broadly, and prefer capture over brute force-style guessing wherever a position exists.
  • rsh host-trust sessions usually carry no password (nothing to sniff there); target rexec/rlogin for credentials and rsh for command/content.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more