Junglewise Threat Intelligence

CVE-1999-1266: rshd user enumeration via differential error messages

CVE-1999-1266 · Severity: medium · CVSS 5 · Published 1997-06-13

Technologies: Metamail Corporation Metamail. Vendors: Metamail Corporation, Unknown.

Executive brief

The remote shell daemon (rshd), a service used for executing commands on remote computers, contains a flaw in how it handles login errors. By observing the specific error messages returned during a connection attempt, an attacker can distinguish between valid and invalid usernames. This allows an attacker to build a list of real user accounts on the system, which can be used to facilitate more targeted password-guessing or social engineering attacks.

Technical details

The rsh daemon (rshd) is vulnerable to information disclosure via an observable response discrepancy (user enumeration). When a remote user attempts to connect, the daemon returns distinct error messages depending on whether the provided username exists on the local system. This is a network-based attack that requires no prior authentication. An attacker can automate requests to the service to brute-force or 'harvest' valid account names, significantly reducing the effort required for subsequent credential-based attacks. This behavior is inherent to older implementations of the rsh protocol.

Affected products

  • unknown rshd (rsh daemon)

Timeline

  • 1997-06-13: disclosed

References

Related threats