pentesting-rlogin.md (1827B)
1 --- 2 title: "513 - Pentesting Rlogin" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-rlogin.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-rlogin.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 513 - Pentesting Rlogin 14 15 ## Basic Information 16 17 The BSD `rlogin` protocol provides a remote terminal over TCP port 513. Its trusted-host mechanism can bypass password authentication, and the protocol does not protect the session with modern transport encryption; use SSH instead for administration.<sup>[[1]](#references)</sup> 18 19 **Default port:** 513/TCP 20 21 ```text 22 PORT STATE SERVICE 23 513/tcp open login 24 ``` 25 26 ## Login 27 28 Install a client on Debian-based systems: 29 30 ```bash 31 sudo apt-get install rsh-client 32 ``` 33 34 Then test an authorized account. If the server's trust configuration permits passwordless access, no password prompt will appear: 35 36 ```bash 37 rlogin <IP> -l <username> 38 # Explicitly test the privileged account only when it is in scope: 39 rlogin <IP> -l root 40 ``` 41 42 Pay particular attention to privileged accounts and trust entries in `/etc/hosts.equiv` and users' `.rhosts` files. RFC 1282 warns that passwordless trusted-host authentication is dangerous because a compromised trusted host can expose accounts on every server that trusts it.<sup>[[1]](#references)</sup> 43 44 ### [Brute force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#rlogin) 45 46 ## Find trust files 47 48 ```bash 49 find / -name .rhosts 2>/dev/null 50 ``` 51 52 ## References 53 54 - [1] [RFC 1282 - BSD Rlogin](https://datatracker.ietf.org/doc/html/rfc1282)