Telnet's authentication is a cleartext username/password exchange, and it falls three ways. Default credentials are endemic on the devices that still run Telnet, routers, switches, cameras, printers, IoT, so the documented vendor pair often works. Some servers require no authentication, dropping straight to a shell or menu. And the plaintext login is brute-forceable, bounded mainly by the device's (often absent) rate limiting. A successful login yields a terminal, frequently on equipment where that terminal is administrative (an enable-capable router, a root BusyBox shell).
nc <target> 23 # try default/no-auth first
hydra -L users.txt -P passwords.txt telnet://<target> -t 4
nxc telnet <target> -u users.txt -p passwords.txt 2>/dev/null
Subtopics#
- Default credentials: vendor and factory Telnet logins.
- No authentication: servers that drop to a shell without a password.
- Password brute force: online attacks on the plaintext login.