Telnet is a remote-terminal protocol on TCP 23 with no encryption whatsoever: the login, the password, every command, and all output travel in cleartext. It persists on legacy systems, network equipment, and IoT devices. The attack surface is accordingly broad: weak authentication (vendor defaults, no authentication, and brute force against the plaintext login), an often-verbose banner that discloses the OS and device, memory-corruption remote code execution in old telnetd implementations, and, because the channel is cleartext, straightforward interception of credentials, commands, and even live session hijacking for a positioned attacker.
nmap -p23 -sV --script telnet-ntlm-info,telnet-encryption <target>
nc <target> 23 # banner and login prompt
Subtopics#
- Enumeration: banner and OS detection.
- Authentication: defaults, no-auth, and brute force.
- Memory corruption: RCE in telnetd implementations.
- Traffic interception: cleartext capture and session hijacking.