daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

1026-pentesting-rusersd.md (3992B)


      1 ---
      2 title: "1026 - Pentesting Rusersd"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/1026-pentesting-rusersd.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/1026-pentesting-rusersd.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 1026 - Pentesting Rusersd
     14 
     15 ## Basic Information
     16 
     17 `rusersd` is a legacy SunRPC/ONC RPC service that answers `rusers` queries and returns `who`-style information about users currently logged in to the target. In long format this can reveal the username, hostname, TTY, login time, idle time, and sometimes the remote host the session came from, which is enough to identify real usernames, active sessions, and interesting pivot hosts.<sup>[[1]](#references)</sup>
     18 
     19 Although this page is named after **port 1026**, `rusersd` is usually **not** a fixed `1026/tcp` or `1026/udp` service. In practice it is normally discovered through **rpcbind/portmapper** as RPC program **`100002`**, often exposing versions **2** and **3** over UDP and sometimes TCP on dynamically assigned high ports.<sup>[[2]](#references)</sup>
     20 
     21 If you haven't mapped the RPC programs yet, start with [Pentesting Portmapper / RPCBind](/hacktricks/network-services-pentesting/pentesting-rpcbind).
     22 
     23 ![1026 - Pentesting Rusersd: This protocol will provide you the usernames of the host. You may be able to find this services listed by the port-mapper service like this](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281041%29.png)
     24 
     25 ## Enumeration
     26 
     27 ### Discover it behind rpcbind
     28 
     29 ```bash
     30 rpcinfo -p <target> | grep -i rusersd
     31 # or
     32 nmap -sV -p 111 --script rpcinfo <target>
     33 ```
     34 
     35 The interesting part of the output is the RPC program number, supported versions, transport, and the real high port assigned by `rpcbind`.<sup>[[2]](#references)</sup>
     36 
     37 ```bash
     38 100002  2,3  32776/udp  rusersd
     39 100002  2,3  32780/tcp  rusersd
     40 ```
     41 
     42 ### Query a single host
     43 
     44 ```bash
     45 apt-get install rusers
     46 rusers -l <target>
     47 rusers -al <target>
     48 ```
     49 
     50 `-l` requests the long listing, which is the most useful mode during a pentest because it exposes the TTY, login timestamp, idle time, and remote origin host when available. `-a` is useful when you want to confirm that the daemon responds even if nobody is currently logged in.<sup>[[1]](#references)</sup>
     51 
     52 Example:
     53 
     54 ```bash
     55 root@kali:~# rusers -l 192.168.10.1
     56 Sending broadcast for rusersd protocol version 3...
     57 Sending broadcast for rusersd protocol version 2...
     58 tiff       potatohead:console         Sep  2 13:03   22:03
     59 katykat    potatohead:ttyp5           Sep  1 09:35      14
     60 ```
     61 
     62 ### Broadcast the local segment
     63 
     64 If no host is specified, `rusers` queries the local network and waits briefly for late responses, which makes it useful for quickly identifying legacy UNIX hosts on the same broadcast domain.<sup>[[1]](#references)</sup>
     65 
     66 ```bash
     67 rusers -a
     68 rusers -al
     69 rusers -h
     70 rusers -il
     71 ```
     72 
     73 Useful flags:<sup>[[1]](#references)</sup>
     74 
     75 - `-a`: Print hosts that answer even when no one is logged in.
     76 - `-h`: Sort results by hostname.
     77 - `-i`: Sort by idle time to quickly spot active sessions.
     78 - `-l`: Print the long `who`-style listing.
     79 
     80 ### Offensive use of the output
     81 
     82 Treat `rusersd` as a **username and session-intelligence leak**, not just as a banner grab. Low-idle sessions often point to real operators or admins currently working on the system, while the optional remote-host field can reveal jump boxes, trusted workstations, or naming conventions worth reusing against SSH, NFS, NIS/YP, or other legacy RPC services on the same environment.<sup>[[1]](#references)</sup>
     83 
     84 ## References
     85 
     86 - [1] [OpenBSD `rusers(1)` manual page](https://man.openbsd.org/rusers.1)
     87 - [2] [Nmap `rpcinfo` NSE script documentation](https://nmap.org/nsedoc/scripts/rpcinfo.html)