Pentesting R-Services
Last updated
Legacy Unix suite, transmit data unencrypted. Largely replaced by SSH.
Ports: TCP 512 (rexec), TCP 513 (rlogin), TCP 514 (rsh/rcp)
rcp
rshd
514
TCP
Copy files between systems. Like cp but remote. No warning on overwrite.
rsh
rshd
514
TCP
Open a shell on remote machine without login. Uses trusted entries in .rhosts/hosts.equiv.
rexec
rexecd
512
TCP
Execute commands on remote with username and password.
rlogin
rlogind
513
TCP
Log in to remote Unix host. Similar to telnet but auto-login for trusted entries.
/etc/hosts.equiv — global trusted hosts
~/.rhosts — per-user trusted hosts
Format: <hostname> <username> or + + (trust everyone — very dangerous)
sudo nmap -sV -p 512,513,514 10.0.17.2Last updated
rlogin 10.0.17.2 -l htb-studentrwhorusers -al 10.0.17.5