Session hijacking

Telnet authenticates only at login; thereafter the session is just an unencrypted TCP stream with no per-packet authentication. An on-path attacker therefore hijacks it: by injecting crafted TCP segments with the correct sequence numbers (observable because the traffic is cleartext), they insert commands into the stream that the server executes as the already-authenticated user, or desynchronise and take the session over entirely. This bypasses the login completely, the attacker never needs the password, they ride a session someone else authenticated, and runs with that user's privileges.

bash
# on-path position to the Telnet session (ARP/route)
# observe the stream to learn the TCP sequence/ack state (cleartext makes this easy)
# inject a command segment with the right seq/ack so the server executes it as the user
# classic tooling automated TCP session hijacking against telnet/rlogin:
#   (e.g. the historic Hunt/Juggernaut tools; modern equivalents craft segments directly)

Exploitation notes#

  • Hijacking rides an authenticated session, so it needs no credential, only an on-path position and the cleartext stream to read sequence/ack state for injection.
  • Injecting a single command (add a user, write a key, start a reverse shell) is often enough and less disruptive than a full takeover, which can desynchronise and alert the user.
  • The injected command runs with the victim's privileges, frequently administrative on the device, so one injected command can be a full compromise.
  • This is the active end of Telnet interception; the passive counterparts are password sniffing and command interception, and the same cleartext weakness enables all three.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more