Telnet is talkative: on connect it typically presents a banner and a login prompt, and both frequently disclose the operating system, device vendor and model, and software version, with some systems adding pre-login messages that reveal configuration or purpose. This identification drives the follow-on, the device and OS map directly to known default credentials and to the telnetd implementation's memory-corruption vulnerabilities, and the login-prompt format itself can leak OS specifics useful for fingerprinting.
nc <target> 23 # banner + login prompt
nmap -p23 -sV <target> # service/version
nmap -p23 --script telnet-ntlm-info <target> # NTLM info on Windows telnet
Subtopics#
- Banner grabbing: the service banner and version.
- OS detection: identifying the OS from banner and prompt.