Executive brief
The remote shell daemon (rshd), a service used for executing commands on remote computers, contains a flaw in how it handles login errors. By observing the specific error messages returned during a connection attempt, an attacker can distinguish between valid and invalid usernames. This allows an attacker to build a list of real user accounts on the system, which can be used to facilitate more targeted password-guessing or social engineering attacks.
Technical details
The rsh daemon (rshd) is vulnerable to information disclosure via an observable response discrepancy (user enumeration). When a remote user attempts to connect, the daemon returns distinct error messages depending on whether the provided username exists on the local system. This is a network-based attack that requires no prior authentication. An attacker can automate requests to the service to brute-force or 'harvest' valid account names, significantly reducing the effort required for subsequent credential-based attacks. This behavior is inherent to older implementations of the rsh protocol.
Affected products
- unknown rshd (rsh daemon)
Timeline
- 1997-06-13: disclosed