daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

10000-network-data-management-protocol-ndmp.md (2402B)


      1 ---
      2 title: "10000/tcp - Network Data Management Protocol (NDMP)"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/10000-network-data-management-protocol-ndmp.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/10000-network-data-management-protocol-ndmp.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 10000/tcp - Network Data Management Protocol (NDMP)
     14 
     15 ## Protocol information
     16 
     17 The Network Data Management Protocol (NDMP) coordinates backup and recovery between network-attached storage (NAS) and backup systems. Its architecture separates control from the data path, allowing backup data to move directly between an NDMP data server and a tape or backup data server instead of passing through the application that controls the job. This avoids turning the controlling backup application into the data-transfer bottleneck and reduces the processing and network load placed on it.<sup>[[4]](#references)</sup> IANA registers the service name `ndmp` on port 10000 for both TCP and UDP; the Nmap discovery scripts below target the TCP service.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     18 
     19 **Default port:** 10000/TCP
     20 
     21 ```text
     22 PORT      STATE SERVICE REASON  VERSION
     23 10000/tcp open  ndmp    syn-ack Symantec/Veritas Backup Exec ndmp
     24 ```
     25 
     26 ## Enumeration
     27 
     28 Nmap's `ndmp-version` and `ndmp-fs-info` scripts are in the `default`, `discovery`, and `safe` categories. They can identify the NDMP version and, when the service permits it, list remote file systems.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup>
     29 
     30 ```bash
     31 nmap -n -sV --script "ndmp-fs-info or ndmp-version" -p 10000 <IP>
     32 ```
     33 
     34 ## Shodan
     35 
     36 `port:10000 ndmp`
     37 
     38 ## References
     39 
     40 - [1] [IANA - Service Name and Transport Protocol Port Number Registry](https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=ndmp)
     41 - [2] [Nmap NSE documentation - `ndmp-version`](https://nmap.org/nsedoc/scripts/ndmp-version.html)
     42 - [3] [Nmap NSE documentation - `ndmp-fs-info`](https://nmap.org/nsedoc/scripts/ndmp-fs-info.html)
     43 - [4] [SNIA - Network Data Management Protocol White Paper](https://www.snia.org/sites/default/files/technical-work/whitepapers/SNIA-NDMP-White-Paper.pdf)