hosts.equiv trust

/etc/hosts.equiv is the system-wide trust file for the r-commands: hosts (and optionally users) listed there are trusted for passwordless access to all non-root accounts on the system simultaneously. That makes it broader and more dangerous than a single user's .rhosts. The abuse cases: the file already lists a host the attacker controls or can spoof (passwordless access as any non-root user from there), it contains an over-broad or wildcard entry, or the attacker has gained enough local privilege to write it and grant themselves system-wide trust. Root is excepted, root trust lives only in /.rhosts.

bash
# read it to see which hosts are trusted and how broadly
cat /etc/hosts.equiv 2>/dev/null
# from a trusted (or spoofed) host, log in as any non-root user with no password
rlogin -l <anyuser> <target>
rsh -l <anyuser> <target> id
# if writable after local elevation, grant system-wide trust
echo '+' >> /etc/hosts.equiv      # trust all hosts (open door for all non-root users)

Exploitation notes#

  • The breadth is the point: one trusted entry exposes every non-root account, so hosts.equiv trust is a wider win than per-user .rhosts; enumerate which users exist to pick a useful target account.
  • Root is not covered by hosts.equiv; passwordless root requires /.rhosts, so note the distinction when targeting the root account.
  • The file is root-owned, so writing it is a post-elevation/persistence step; the initial vector is usually an already-permissive file plus a trusted or spoofable source host.
  • Applies uniformly to rsh, rlogin, and rexec on the host.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more