Authentication

Telnet's authentication is a cleartext username/password exchange, and it falls three ways. Default credentials are endemic on the devices that still run Telnet, routers, switches, cameras, printers, IoT, so the documented vendor pair often works. Some servers require no authentication, dropping straight to a shell or menu. And the plaintext login is brute-forceable, bounded mainly by the device's (often absent) rate limiting. A successful login yields a terminal, frequently on equipment where that terminal is administrative (an enable-capable router, a root BusyBox shell).

bash
nc <target> 23        # try default/no-auth first
hydra -L users.txt -P passwords.txt telnet://<target> -t 4
nxc telnet <target> -u users.txt -p passwords.txt 2>/dev/null

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more