3260-pentesting-iscsi.md (10010B)
1 --- 2 title: "3260 - Pentesting iSCSI" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/3260-pentesting-iscsi.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3260-pentesting-iscsi.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 3260 - Pentesting iSCSI 14 15 ## Basic Information 16 17 **Internet Small Computer System Interface (iSCSI)** carries SCSI commands over TCP. A client called an **initiator** connects to a **target**, selects a logical unit (LUN), and receives block-level storage that the operating system treats much like a locally attached disk. It commonly runs over existing IP networks instead of dedicated Fibre Channel infrastructure.<sup>[[3]](#references)</sup> 18 19 iSCSI requires CHAP support but does not require deployments to use it, and CHAP over an unencrypted channel has known limitations. An exposed target with no authentication can therefore grant raw read/write access to a LUN; even with CHAP, use IPsec or another protected network when confidentiality is required.<sup>[[3]](#references)</sup> 20 21 **Default port:** 3260 22 23 ```text 24 PORT STATE SERVICE VERSION 25 3260/tcp open iscsi? 26 ``` 27 28 ## Enumeration 29 30 ```text 31 nmap -sV --script=iscsi-info -p 3260 192.168.xx.xx 32 ``` 33 34 This script will indicate if authentication is required. 35 36 ### [Brute force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#iscsi) 37 38 ### Mount iSCSI on Linux 39 40 **Note:** A SendTargets response may advertise a portal different from the address used for discovery, which is common behind NAT or a virtual IP. Open-iSCSI identifies a persistent node record by both target IQN and portal, so logging in to an unreachable advertised address fails.<sup>[[4]](#references)</sup> 41 42 For example, you are trying to connect to an iSCSI target on `123.123.123.123:3260`. The target is actually at `192.168.1.2` but exposed through NAT, and `iscsiadm` registers the internal address rather than the public address: 43 44 ```text 45 iscsiadm -m discovery -t sendtargets -p 123.123.123.123:3260 46 192.168.1.2:3260,1 iqn.1992-05.com.emc:fl1001433000190000-3-vnxe 47 [...] 48 ``` 49 50 Prefer creating an explicit node record for the reachable portal, then configure authentication on that record if required:<sup>[[4]](#references)</sup> 51 52 ```bash 53 iscsiadm -m node --op new \ 54 --targetname 'iqn.1992-05.com.emc:fl1001433000190000-3-vnxe' \ 55 --portal 123.123.123.123:3260 56 iscsiadm -m node \ 57 --targetname 'iqn.1992-05.com.emc:fl1001433000190000-3-vnxe' \ 58 --portal 123.123.123.123:3260 --login 59 ``` 60 61 On older installations where an explicit record cannot be created, the legacy workaround is to adjust the generated node record. Discovery creates a directory such as: 62 63 ```text 64 /etc/iscsi/nodes/iqn.1992-05.com.emc:fl1001433000190000-3-vnxe/192.168.1.2\,3260\,1/ 65 ``` 66 67 Within the directory, there is a default file with all the settings necessary to connect to the target. 68 69 1. Rename `/etc/iscsi/nodes/iqn.1992-05.com.emc:fl1001433000190000-3-vnxe/192.168.1.2\,3260\,1/` to `/etc/iscsi/nodes/iqn.1992-05.com.emc:fl1001433000190000-3-vnxe/123.123.123.123\,3260\,1/` 70 2. Within `/etc/iscsi/nodes/iqn.1992-05.com.emc:fl1001433000190000-3-vnxe/123.123.123.123\,3260\,1/default`, change the `node.conn[0].address` setting to point to 123.123.123.123 instead of 192.168.1.2. This could be done with a command such as `sed -i 's/192.168.1.2/123.123.123.123/g' /etc/iscsi/nodes/iqn.1992-05.com.emc:fl1001433000190000-3-vnxe/123.123.123.123\,3260\,1/default` 71 72 After login, inspect the newly attached block device with `lsblk` or `lsscsi`. During an assessment, mount filesystems **read-only first** (for example, `mount -o ro,noload`) to avoid journal replay or other writes to evidence and production data.<sup>[[1]](#references)[[2]](#references)</sup> 73 74 ### Mount iSCSI on Windows 75 76 Use the built-in Microsoft iSCSI Initiator (`iscsicpl.exe`), PowerShell iSCSI module, or legacy `iscsicli` tool to add the target portal, discover the IQN, and connect. For example:<sup>[[5]](#references)</sup> 77 78 ```powershell 79 New-IscsiTargetPortal -TargetPortalAddress <TARGET_IP> 80 Get-IscsiTarget 81 Connect-IscsiTarget -NodeAddress '<TARGET_IQN>' -IsPersistent $false 82 Get-IscsiSession 83 ``` 84 85 Apply the same read-only/evidence-handling precautions before bringing discovered disks online. Disconnect the temporary session with `Disconnect-IscsiTarget -NodeAddress '<TARGET_IQN>' -Confirm:$false` when the assessment is complete. 86 87 ## **Manual enumeration** 88 89 ```bash 90 sudo apt-get install open-iscsi 91 ``` 92 93 Example from [iscsiadm docs](https://ptestmethod.readthedocs.io/en/latest/LFF-IPS-P2-VulnerabilityAnalysis.html#iscsiadm):<sup>[[1]](#references)[[2]](#references)</sup> 94 95 First of all you need to **discover the targets** name behind the IP: 96 97 ```bash 98 iscsiadm -m discovery -t sendtargets -p 123.123.123.123:3260 99 123.123.123.123:3260,1 iqn.1992-05.com.emc:fl1001433000190000-3-vnxe 100 [2a01:211:7b7:1223:211:32ff:fea9:fab9]:3260,1 iqn.2000-01.com.synology:asd3.Target-1.d0280fd382 101 [fe80::211:3232:fab9:1223]:3260,1 iqn.2000-01.com.synology:Oassdx.Target-1.d0280fd382 102 ``` 103 104 _Note that it will show the I**P and port of the interfaces** where you can **reach** those **targets**. It can even **show internal IPs or different IPs** from the one you used._ 105 106 Then you **catch the 2nd part of the printed string of each line** (_iqn.1992-05.com.emc:fl1001433000190000-3-vnxe_ from the first line) and **try to login**: 107 108 ```bash 109 iscsiadm -m node --targetname="iqn.1992-05.com.emc:fl1001433000190000-3-vnxe" -p 123.123.123.123:3260 --login 110 Logging in to [iface: default, target: iqn.1992-05.com.emc:fl1001433000190000-3-vnxe, portal: 123.123.123.123,3260] (multiple) 111 Login to [iface: default, target: iqn.1992-05.com.emc:fl1001433000190000-3-vnxe, portal: 123.123.123.123,3260] successful. 112 ``` 113 114 Then, you can **log out** using `--logout`: 115 116 ```bash 117 iscsiadm -m node --targetname="iqn.1992-05.com.emc:fl1001433000190000-3-vnxe" -p 123.123.123.123:3260 --logout 118 Logging out of session [sid: 6, target: iqn.1992-05.com.emc:fl1001433000190000-3-vnxe, portal: 123.123.123.123,3260] 119 Logout of [sid: 6, target: iqn.1992-05.com.emc:fl1001433000190000-3-vnxe, portal: 123.123.123.123,3260] successful. 120 ``` 121 122 We can find **more information** about it by just using **without** any `--login`/`--logout` parameter 123 124 ```bash 125 iscsiadm -m node --targetname="iqn.1992-05.com.emc:fl1001433000190000-3-vnxe" -p 123.123.123.123:3260 126 # BEGIN RECORD 2.0-873 127 node.name = iqn.1992-05.com.emc:fl1001433000190000-3-vnxe 128 node.tpgt = 1 129 node.startup = manual 130 node.leading_login = No 131 iface.hwaddress = <empty> 132 iface.ipaddress = <empty> 133 iface.iscsi_ifacename = default 134 iface.net_ifacename = <empty> 135 iface.transport_name = tcp 136 iface.initiatorname = <empty> 137 iface.bootproto = <empty> 138 iface.subnet_mask = <empty> 139 iface.gateway = <empty> 140 iface.ipv6_autocfg = <empty> 141 iface.linklocal_autocfg = <empty> 142 iface.router_autocfg = <empty> 143 iface.ipv6_linklocal = <empty> 144 iface.ipv6_router = <empty> 145 iface.state = <empty> 146 iface.vlan_id = 0 147 iface.vlan_priority = 0 148 iface.vlan_state = <empty> 149 iface.iface_num = 0 150 iface.mtu = 0 151 iface.port = 0 152 node.discovery_address = 192.168.xx.xx 153 node.discovery_port = 3260 154 node.discovery_type = send_targets 155 node.session.initial_cmdsn = 0 156 node.session.initial_login_retry_max = 8 157 node.session.xmit_thread_priority = -20 158 node.session.cmds_max = 128 159 node.session.queue_depth = 32 160 node.session.nr_sessions = 1 161 node.session.auth.authmethod = None 162 node.session.auth.username = <empty> 163 node.session.auth.password = <empty> 164 node.session.auth.username_in = <empty> 165 node.session.auth.password_in = <empty> 166 node.session.timeo.replacement_timeout = 120 167 node.session.err_timeo.abort_timeout = 15 168 node.session.err_timeo.lu_reset_timeout = 30 169 node.session.err_timeo.tgt_reset_timeout = 30 170 node.session.err_timeo.host_reset_timeout = 60 171 node.session.iscsi.FastAbort = Yes 172 node.session.iscsi.InitialR2T = No 173 node.session.iscsi.ImmediateData = Yes 174 node.session.iscsi.FirstBurstLength = 262144 175 node.session.iscsi.MaxBurstLength = 16776192 176 node.session.iscsi.DefaultTime2Retain = 0 177 node.session.iscsi.DefaultTime2Wait = 2 178 node.session.iscsi.MaxConnections = 1 179 node.session.iscsi.MaxOutstandingR2T = 1 180 node.session.iscsi.ERL = 0 181 node.conn[0].address = 192.168.xx.xx 182 node.conn[0].port = 3260 183 node.conn[0].startup = manual 184 node.conn[0].tcp.window_size = 524288 185 node.conn[0].tcp.type_of_service = 0 186 node.conn[0].timeo.logout_timeout = 15 187 node.conn[0].timeo.login_timeout = 15 188 node.conn[0].timeo.auth_timeout = 45 189 node.conn[0].timeo.noop_out_interval = 5 190 node.conn[0].timeo.noop_out_timeout = 5 191 node.conn[0].iscsi.MaxXmitDataSegmentLength = 0 192 node.conn[0].iscsi.MaxRecvDataSegmentLength = 262144 193 node.conn[0].iscsi.HeaderDigest = None 194 node.conn[0].iscsi.DataDigest = None 195 node.conn[0].iscsi.IFMarker = No 196 node.conn[0].iscsi.OFMarker = No 197 # END RECORD 198 ``` 199 200 **There is a script to automate basic subnet enumeration process available at** [**iscsiadm**](https://github.com/bitvijays/Pentest-Scripts/tree/master/Vulnerability_Analysis/isciadm) 201 202 ## **Shodan** 203 204 - `port:3260 AuthMethod` 205 206 ## References 207 208 - [1] [Archived LFF-IPS-P2 Vulnerability Analysis - iSCSI pentesting guide](https://web.archive.org/web/20230000000000id_/https://bitvijays.github.io/LFF-IPS-P2-VulnerabilityAnalysis.html) 209 - [2] [LFF-IPS-P2 Vulnerability Analysis – iscsiadm section (ptestmethod docs mirror)](https://ptestmethod.readthedocs.io/en/latest/LFF-IPS-P2-VulnerabilityAnalysis.html#iscsiadm) 210 - [3] [RFC 7143 - Internet Small Computer System Interface (iSCSI) Protocol](https://datatracker.ietf.org/doc/html/rfc7143) 211 - [4] [Open-iSCSI - iscsiadm usage and node database](https://github.com/open-iscsi/open-iscsi) 212 - [5] [Microsoft Learn - Windows iSCSI Initiator PowerShell module](https://learn.microsoft.com/en-us/powershell/module/iscsi/?view=windowsserver2025-ps)