146
Microsoft Windows Telnet Server detection
Backdoors
2004/09/06
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.2
Corrected the plugin structure and added the accuracy values in 1.2
tcp
23
open|sleep|close|pattern_exists Welcome to Microsoft Telnet Server OR ÿý%ÿûÿûÿý'ÿýÿý
97
This plugin was written with the ATK Attack Editor. I don't know if the rubbish is saved as secondary pattern does really identify Microsofts Telnet service. Need to be verified.
Microsoft Windows Telnet Daemon
Other telnet daemons
Configuration
The target host is running a Telnet server by Microsoft Windows. This can be determined by the welcome banner of the application. An attacker may get additional data about the target. Also telnet connections are not encrypted and usually authenticated via simple username/password credentials.
The telnet service, if not needed, should be disabled or if possible firewalled. Upgrade to the latest software version to be not vulnerable anymore. A server daemon should not advertise its version to the world. So disable or change the banner. To get more security, install SSH.
Approx. 45 minutes
Yes
http://www.nessus.org
Yes
Yes
Medium
7
8
6
7
Most vulnerability scanners are able to do a similar check.
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch