Banner grabbing

Connecting to Telnet almost always yields a banner before or at the login prompt, and it is frequently rich: it names the OS (a Linux login banner, a Cisco IOS header, a BusyBox prompt), the device vendor and model for network gear and IoT, and sometimes the exact firmware or software version. This is the primary fingerprint for Telnet, because the device and version map directly to documented default credentials and to the specific telnetd implementation (and its known RCE bugs).

bash
nc <target> 23                                 # read the banner/login header
echo | nc -w3 <target> 23 | head
nmap -p23 -sV <target>                         # version detection
# at scale
for h in $(cat hosts.txt); do echo "== $h =="; echo | nc -w2 $h 23 | head -5; done

Exploitation notes#

  • The banner commonly identifies the device class (router/switch/camera/printer/IoT) and vendor, which is exactly what a default-credential lookup needs.
  • Firmware/version strings map an embedded telnetd (often BusyBox or a vendor build) to its known memory-corruption flaws, see Memory corruption.
  • Cisco and other network-gear banners reveal the OS family and sometimes the model, guiding both credential and exploit choices.
  • Everything here is pre-auth and cleartext; it costs nothing and should precede any authentication attempt.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more