Wildcard trust

The r-command trust files treat + as a wildcard: + in the host field matches any host, + in the user field matches any user, and the infamous + + entry trusts every host and every user for passwordless access. Over-broad trust is a common real-world misconfiguration: a bare +, a wildcard host entry, or a netgroup that resolves to a wide set. Where such an entry exists in a user's .rhosts or in /etc/hosts.equiv, an attacker from any source address (no spoofing even needed) logs in or runs commands as the trusted account with no password.

bash
# detect over-broad trust where the files are readable
grep -R '+' /etc/hosts.equiv ~*/.rhosts 2>/dev/null     # a bare + or "+ +" is wide open
# where present, access needs no password and often no spoofing
rlogin -l <user> <target>
rsh -l <user> <target> id

Exploitation notes#

  • + + and a bare + are the maximal cases: they trust everyone, so any reachable attacker gets passwordless access, no trusted-host control or spoofing required.
  • A + only in the user field of a host entry trusts all users from that host; in the host field, all hosts for that user; read the fields carefully to see how wide the trust is.
  • Netgroup (+@group) and wildcard host entries can resolve more broadly than intended; where you can read the file, evaluate what it actually matches.
  • This is the "already open" case of trust abuse; where no wildcard exists, plant one or spoof a specific trusted host.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more