daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-rlogin.md (1827B)


      1 ---
      2 title: "513 - Pentesting Rlogin"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-rlogin.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-rlogin.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 513 - Pentesting Rlogin
     14 
     15 ## Basic Information
     16 
     17 The BSD `rlogin` protocol provides a remote terminal over TCP port 513. Its trusted-host mechanism can bypass password authentication, and the protocol does not protect the session with modern transport encryption; use SSH instead for administration.<sup>[[1]](#references)</sup>
     18 
     19 **Default port:** 513/TCP
     20 
     21 ```text
     22 PORT    STATE SERVICE
     23 513/tcp open  login
     24 ```
     25 
     26 ## Login
     27 
     28 Install a client on Debian-based systems:
     29 
     30 ```bash
     31 sudo apt-get install rsh-client
     32 ```
     33 
     34 Then test an authorized account. If the server's trust configuration permits passwordless access, no password prompt will appear:
     35 
     36 ```bash
     37 rlogin <IP> -l <username>
     38 # Explicitly test the privileged account only when it is in scope:
     39 rlogin <IP> -l root
     40 ```
     41 
     42 Pay particular attention to privileged accounts and trust entries in `/etc/hosts.equiv` and users' `.rhosts` files. RFC 1282 warns that passwordless trusted-host authentication is dangerous because a compromised trusted host can expose accounts on every server that trusts it.<sup>[[1]](#references)</sup>
     43 
     44 ### [Brute force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#rlogin)
     45 
     46 ## Find trust files
     47 
     48 ```bash
     49 find / -name .rhosts 2>/dev/null
     50 ```
     51 
     52 ## References
     53 
     54 - [1] [RFC 1282 - BSD Rlogin](https://datatracker.ietf.org/doc/html/rfc1282)