Connecting to Telnet almost always yields a banner before or at the login prompt, and it is frequently rich: it names the OS (a Linux login banner, a Cisco IOS header, a BusyBox prompt), the device vendor and model for network gear and IoT, and sometimes the exact firmware or software version. This is the primary fingerprint for Telnet, because the device and version map directly to documented default credentials and to the specific telnetd implementation (and its known RCE bugs).
nc <target> 23 # read the banner/login header
echo | nc -w3 <target> 23 | head
nmap -p23 -sV <target> # version detection
# at scale
for h in $(cat hosts.txt); do echo "== $h =="; echo | nc -w2 $h 23 | head -5; done
Exploitation notes#
- The banner commonly identifies the device class (router/switch/camera/printer/IoT) and vendor, which is exactly what a default-credential lookup needs.
- Firmware/version strings map an embedded
telnetd(often BusyBox or a vendor build) to its known memory-corruption flaws, see Memory corruption. - Cisco and other network-gear banners reveal the OS family and sometimes the model, guiding both credential and exploit choices.
- Everything here is pre-auth and cleartext; it costs nothing and should precede any authentication attempt.