10000-network-data-management-protocol-ndmp.md (2402B)
1 --- 2 title: "10000/tcp - Network Data Management Protocol (NDMP)" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/10000-network-data-management-protocol-ndmp.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/10000-network-data-management-protocol-ndmp.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 10000/tcp - Network Data Management Protocol (NDMP) 14 15 ## Protocol information 16 17 The Network Data Management Protocol (NDMP) coordinates backup and recovery between network-attached storage (NAS) and backup systems. Its architecture separates control from the data path, allowing backup data to move directly between an NDMP data server and a tape or backup data server instead of passing through the application that controls the job. This avoids turning the controlling backup application into the data-transfer bottleneck and reduces the processing and network load placed on it.<sup>[[4]](#references)</sup> IANA registers the service name `ndmp` on port 10000 for both TCP and UDP; the Nmap discovery scripts below target the TCP service.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 18 19 **Default port:** 10000/TCP 20 21 ```text 22 PORT STATE SERVICE REASON VERSION 23 10000/tcp open ndmp syn-ack Symantec/Veritas Backup Exec ndmp 24 ``` 25 26 ## Enumeration 27 28 Nmap's `ndmp-version` and `ndmp-fs-info` scripts are in the `default`, `discovery`, and `safe` categories. They can identify the NDMP version and, when the service permits it, list remote file systems.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup> 29 30 ```bash 31 nmap -n -sV --script "ndmp-fs-info or ndmp-version" -p 10000 <IP> 32 ``` 33 34 ## Shodan 35 36 `port:10000 ndmp` 37 38 ## References 39 40 - [1] [IANA - Service Name and Transport Protocol Port Number Registry](https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=ndmp) 41 - [2] [Nmap NSE documentation - `ndmp-version`](https://nmap.org/nsedoc/scripts/ndmp-version.html) 42 - [3] [Nmap NSE documentation - `ndmp-fs-info`](https://nmap.org/nsedoc/scripts/ndmp-fs-info.html) 43 - [4] [SNIA - Network Data Management Protocol White Paper](https://www.snia.org/sites/default/files/technical-work/whitepapers/SNIA-NDMP-White-Paper.pdf)