Because Telnet encrypts nothing, an attacker with a network position gets everything for free: the username and password as they are typed at login, every command the user runs, and all the server's output. Beyond passive capture, the unauthenticated, unencrypted TCP session can be hijacked, injecting commands that execute as the already-authenticated user. Where a capture or on-path position exists, interception is usually the easiest and quietest Telnet attack, bypassing authentication entirely.
# capture Telnet from an on-path position
tcpdump -i eth0 -A port 23 -w telnet.pcap
# follow the TCP stream to read credentials, commands, and output
Subtopics#
- Password sniffing: capturing credentials from the cleartext login.
- Command interception: reading commands and output in transit.
- Session hijacking: taking over the live Telnet session.