1026-pentesting-rusersd.md (3992B)
1 --- 2 title: "1026 - Pentesting Rusersd" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/1026-pentesting-rusersd.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/1026-pentesting-rusersd.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 1026 - Pentesting Rusersd 14 15 ## Basic Information 16 17 `rusersd` is a legacy SunRPC/ONC RPC service that answers `rusers` queries and returns `who`-style information about users currently logged in to the target. In long format this can reveal the username, hostname, TTY, login time, idle time, and sometimes the remote host the session came from, which is enough to identify real usernames, active sessions, and interesting pivot hosts.<sup>[[1]](#references)</sup> 18 19 Although this page is named after **port 1026**, `rusersd` is usually **not** a fixed `1026/tcp` or `1026/udp` service. In practice it is normally discovered through **rpcbind/portmapper** as RPC program **`100002`**, often exposing versions **2** and **3** over UDP and sometimes TCP on dynamically assigned high ports.<sup>[[2]](#references)</sup> 20 21 If you haven't mapped the RPC programs yet, start with [Pentesting Portmapper / RPCBind](/hacktricks/network-services-pentesting/pentesting-rpcbind). 22 23  24 25 ## Enumeration 26 27 ### Discover it behind rpcbind 28 29 ```bash 30 rpcinfo -p <target> | grep -i rusersd 31 # or 32 nmap -sV -p 111 --script rpcinfo <target> 33 ``` 34 35 The interesting part of the output is the RPC program number, supported versions, transport, and the real high port assigned by `rpcbind`.<sup>[[2]](#references)</sup> 36 37 ```bash 38 100002 2,3 32776/udp rusersd 39 100002 2,3 32780/tcp rusersd 40 ``` 41 42 ### Query a single host 43 44 ```bash 45 apt-get install rusers 46 rusers -l <target> 47 rusers -al <target> 48 ``` 49 50 `-l` requests the long listing, which is the most useful mode during a pentest because it exposes the TTY, login timestamp, idle time, and remote origin host when available. `-a` is useful when you want to confirm that the daemon responds even if nobody is currently logged in.<sup>[[1]](#references)</sup> 51 52 Example: 53 54 ```bash 55 root@kali:~# rusers -l 192.168.10.1 56 Sending broadcast for rusersd protocol version 3... 57 Sending broadcast for rusersd protocol version 2... 58 tiff potatohead:console Sep 2 13:03 22:03 59 katykat potatohead:ttyp5 Sep 1 09:35 14 60 ``` 61 62 ### Broadcast the local segment 63 64 If no host is specified, `rusers` queries the local network and waits briefly for late responses, which makes it useful for quickly identifying legacy UNIX hosts on the same broadcast domain.<sup>[[1]](#references)</sup> 65 66 ```bash 67 rusers -a 68 rusers -al 69 rusers -h 70 rusers -il 71 ``` 72 73 Useful flags:<sup>[[1]](#references)</sup> 74 75 - `-a`: Print hosts that answer even when no one is logged in. 76 - `-h`: Sort results by hostname. 77 - `-i`: Sort by idle time to quickly spot active sessions. 78 - `-l`: Print the long `who`-style listing. 79 80 ### Offensive use of the output 81 82 Treat `rusersd` as a **username and session-intelligence leak**, not just as a banner grab. Low-idle sessions often point to real operators or admins currently working on the system, while the optional remote-host field can reveal jump boxes, trusted workstations, or naming conventions worth reusing against SSH, NFS, NIS/YP, or other legacy RPC services on the same environment.<sup>[[1]](#references)</sup> 83 84 ## References 85 86 - [1] [OpenBSD `rusers(1)` manual page](https://man.openbsd.org/rusers.1) 87 - [2] [Nmap `rpcinfo` NSE script documentation](https://nmap.org/nsedoc/scripts/rpcinfo.html)