daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-rsh.md (1452B)


      1 ---
      2 title: "514 - Pentesting Rsh"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-rsh.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-rsh.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 514 - Pentesting Rsh
     14 
     15 ## Basic Information
     16 
     17 The remote shell service (`rsh`) historically used `/etc/hosts.equiv` and per-user `.rhosts` files to trust remote hosts and users. This host-based model depends on IP-address and Domain Name System (DNS) assumptions and is vulnerable to address or name-resolution spoofing, especially on a local network.<sup>[[1]](#references)</sup>
     18 
     19 Because `.rhosts` resides in a user's home directory, an attacker who can modify that file—for example, through an exposed NFS home directory—may be able to add a trusted host or user.<sup>[[1]](#references)</sup>
     20 
     21 **Default port:** 514/TCP
     22 
     23 ## Login
     24 
     25 ```bash
     26 rsh <IP> <Command>
     27 rsh <IP> -l domain\user <Command>
     28 rsh domain/user@<IP> <Command>
     29 rsh domain\\user@<IP> <Command>
     30 ```
     31 
     32 ### [**Brute Force**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#rsh)
     33 
     34 ## References
     35 
     36 - [1] [Overview of the Remote Shell RSH - SSH Academy](https://www.ssh.com/ssh/rsh)