During an internal engagement, Nathan compromises a legacy Linux server and observes that administrators remotely manage the system using a protocol that transmits authentication credentials and command traffic in cleartext over TCP port 23. Nathan positions himself between an administrator workstation and the server to capture credentials and potentially modify command traffic in transit. Which protocol is Nathan MOST likely targeting to successfully conduct this on-path attack?
