| Service | Port | Notes |
|---|---|---|
| UnrealIRCd | 6667/tcp | Version 3.2.8.1, backdoored build (CVE-2010-2075) |
| distccd | 3632/tcp | Distributed compiler daemon, remote command execution (CVE-2004-2687) |
| ingreslock backdoor | 1524/tcp | Root shell bound directly to the port |
| Java RMI Registry | 1099/tcp | Exposed registry, potential remote code execution |
| r-services (rlogin/rsh/rexec) | 512–514/tcp | Trust-based remote login with no real authentication |
| NFS | 2049/tcp | Exported filesystem shares |
| RPCbind | 111/tcp | Legacy remote procedure call coordination service |
Why These Exist
Each of these was once standard software on Unix systems, and each persists today on real infrastructure precisely because nobody revisited it after initial setup — the same pattern across every entry on this page, even though the specific mechanism differs for each service.
UnrealIRCd 3.2.8.1 (Backdoored Build)
Between November 2009 and June 2010, the downloadable UnrealIRCd 3.2.8.1 archive on the project's own distribution server was replaced with a trojaned copy. The tampered code let anyone send a specific trigger string to the IRC service and have it executed as a shell command — the same supply-chain-compromise pattern as the vsftpd backdoor, just on a different service. This is tracked as CVE-2010-2075.
distccd Remote Command Execution
distcc is a legitimate tool for distributing C/C++ compilation jobs across multiple machines. Its daemon, distccd, was designed to trust any client that could reach it on the network — with no authentication of its own, by design, on the assumption it would only ever run on a trusted internal build network. When exposed more broadly, that trust becomes a remote-command-execution path, tracked as CVE-2004-2687.
The "ingreslock" Backdoor Shell (Port 1524)
Port 1524 has a root command shell bound directly to it, with no exploit needed to reach it — connecting to the port hands you a shell immediately. This convention traces back to older worm and exploit toolchains (historically associated with the Lion worm) that used this specific port as a simple, predictable place to leave a shell after a successful compromise. Metasploitable 2 includes it as a direct illustration of what a "backdoor" actually looks like from the network, without requiring you to trigger one yourself first.
Java RMI Registry Exposure (Port 1099)
Java's Remote Method Invocation (RMI) system lets one Java process call methods on objects living in another process, coordinated through an RMI registry. The registry protocol was not designed with an untrusted network in mind, and an exposed registry can, depending on the Java version and configuration, be manipulated into loading and executing attacker-supplied code.
r-services: rlogin, rsh, and rexec (Ports 512–514)
These predate SSH entirely and authenticate based on trust relationships between hosts (via files like .rhosts) rather than strong per-session credentials. If a trust relationship exists, or can be spoofed, login can happen with effectively no password check at all — the same class of design weakness Telnet has for encryption, applied here to authentication itself.
NFS and RPCbind (Ports 2049, 111)
Network File System (NFS) exports and the RPCbind service that coordinates RPC-based protocols like it were standard on Unix networks for decades. Overly broad export configuration — sharing a filesystem with more hosts, or more permission, than intended — is the recurring real-world issue, the NFS equivalent of an open SMB share.
How They're Identified
A full port scan surfaces all of them at once:
nmap -sV -p 111,512,513,514,1099,1524,2049,3632,6667 192.168.56.101
Targets exactly the ports covered on this page. Version detection on 6667 and 3632 in particular will surface the specific backdoored/vulnerable versions by name.
Port 1524 is the simplest of all to confirm: a plain connection to it (for example with nc) hands back a shell prompt directly, no scanning interpretation required.
The Lesson
Old, forgotten services are exactly the kind of thing an asset inventory is supposed to catch. Two different flavors of risk show up across this single page: software that was actively tampered with (UnrealIRCd, mirroring vsftpd), and software that was simply never designed for an untrusted network in the first place (RMI, r-services, NFS, distcc). Both categories keep appearing on real networks for the same underlying reason — nobody remembered why the service was running, so nobody removed it.
How Defenders Mitigate It
Maintain an accurate inventory of running services, disable anything not tied to an active, documented need, and treat any legacy protocol discovery as a prompt to ask why it's still there. For services that are trust-based by design (r-services, distcc's default mode), the fix is architectural: replace them with modern equivalents (SSH instead of r-services, an authenticated build system instead of open distccd) rather than trying to bolt authentication onto a protocol that was never built for it.
Only interact with these services inside your own isolated Metasploitable 2 lab. Testing them against a system you don't own or have written permission to test is illegal in most jurisdictions.
Related: the FTP page and the SMB page for two more historically specific, CVE-tracked vulnerabilities on this same image, and the vulnerabilities overview to see how this category fits alongside the others.
FAQ
Are legacy services automatically dangerous?
Not automatically, but their age often means less scrutiny, fewer security updates, and less institutional knowledge about their configuration — all of which raise risk over time.
How common is this in real environments?
Very. Legacy protocol discovery is a routine finding in real network assessments, especially on infrastructure that predates current staff.
What is the UnrealIRCd backdoor on Metasploitable 2?
Metasploitable 2 runs UnrealIRCd 3.2.8.1, a version whose downloadable archive was replaced with a tampered copy containing a backdoor in 2009–2010, tracked as CVE-2010-2075. A specially crafted string sent to the IRC service executes arbitrary commands.
What is the ingreslock backdoor on port 1524?
A root command shell bound directly to TCP port 1524, left over from an old exploitation technique (originally associated with the Lion worm) that used this port as a convenient, pre-opened shell. On Metasploitable 2 it's included as a direct, no-exploit-required demonstration of what a backdoor shell looks like from the network.
What does the distccd service expose?
distccd, a distributed compiler daemon on port 3632, accepts compilation jobs from the network and can be manipulated into executing arbitrary commands (CVE-2004-2687) instead of legitimate compiler input.
Why is the Java RMI registry considered risky?
An exposed Java RMI registry (port 1099) can, depending on configuration, be manipulated to load and execute attacker-supplied Java code, since RMI's remote method invocation model was not originally designed with an untrusted network in mind.