The defining weakness of the r-commands is their host-based trust: ~/.rhosts (per user) and /etc/hosts.equiv (system-wide) list host user pairs that are granted passwordless access, and the check is made against the connecting source address. This is authentication by spoofable network identity, and it is abused four ways that apply uniformly across rsh, rlogin, and rexec: planting a .rhosts entry where a home is writable, exploiting a permissive or wildcard trust already present, leveraging the breadth of hosts.equiv (all non-root users at once), and spoofing a trusted source IP to satisfy the check without controlling the trusted host.
# read existing trust where files are accessible (reveals who is trusted)
cat ~*/.rhosts /etc/hosts.equiv 2>/dev/null
# any of the techniques below yields passwordless rsh/rlogin/rexec
Subtopics#
- rhosts write: planting a trusting .rhosts entry.
- Wildcard trust: abusing
+ +and over-broad entries. - hosts.equiv trust: exploiting system-wide trust.
- IP spoofing: impersonating a trusted source address.