it's still possible to telnet through any computer on a network. there are ways to fool the computer into thinking you're the right user, but it will always ask you to supply a password.. I'm not smart enough, but I know a couple of people who could make it think that the right password has been supplied..
obviously, from your point of view, it'd be much easier to send him a small "game" with a trojan attached, and then WHAM, with his IP you have control.