daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

3260-pentesting-iscsi.md (10010B)


      1 ---
      2 title: "3260 - Pentesting iSCSI"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/3260-pentesting-iscsi.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3260-pentesting-iscsi.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 3260 - Pentesting iSCSI
     14 
     15 ## Basic Information
     16 
     17 **Internet Small Computer System Interface (iSCSI)** carries SCSI commands over TCP. A client called an **initiator** connects to a **target**, selects a logical unit (LUN), and receives block-level storage that the operating system treats much like a locally attached disk. It commonly runs over existing IP networks instead of dedicated Fibre Channel infrastructure.<sup>[[3]](#references)</sup>
     18 
     19 iSCSI requires CHAP support but does not require deployments to use it, and CHAP over an unencrypted channel has known limitations. An exposed target with no authentication can therefore grant raw read/write access to a LUN; even with CHAP, use IPsec or another protected network when confidentiality is required.<sup>[[3]](#references)</sup>
     20 
     21 **Default port:** 3260
     22 
     23 ```text
     24 PORT     STATE SERVICE VERSION
     25 3260/tcp open  iscsi?
     26 ```
     27 
     28 ## Enumeration
     29 
     30 ```text
     31 nmap -sV --script=iscsi-info -p 3260 192.168.xx.xx
     32 ```
     33 
     34 This script will indicate if authentication is required.
     35 
     36 ### [Brute force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#iscsi)
     37 
     38 ### Mount iSCSI on Linux
     39 
     40 **Note:** A SendTargets response may advertise a portal different from the address used for discovery, which is common behind NAT or a virtual IP. Open-iSCSI identifies a persistent node record by both target IQN and portal, so logging in to an unreachable advertised address fails.<sup>[[4]](#references)</sup>
     41 
     42 For example, you are trying to connect to an iSCSI target on `123.123.123.123:3260`. The target is actually at `192.168.1.2` but exposed through NAT, and `iscsiadm` registers the internal address rather than the public address:
     43 
     44 ```text
     45 iscsiadm -m discovery -t sendtargets -p 123.123.123.123:3260
     46 192.168.1.2:3260,1 iqn.1992-05.com.emc:fl1001433000190000-3-vnxe
     47 [...]
     48 ```
     49 
     50 Prefer creating an explicit node record for the reachable portal, then configure authentication on that record if required:<sup>[[4]](#references)</sup>
     51 
     52 ```bash
     53 iscsiadm -m node --op new \
     54   --targetname 'iqn.1992-05.com.emc:fl1001433000190000-3-vnxe' \
     55   --portal 123.123.123.123:3260
     56 iscsiadm -m node \
     57   --targetname 'iqn.1992-05.com.emc:fl1001433000190000-3-vnxe' \
     58   --portal 123.123.123.123:3260 --login
     59 ```
     60 
     61 On older installations where an explicit record cannot be created, the legacy workaround is to adjust the generated node record. Discovery creates a directory such as:
     62 
     63 ```text
     64 /etc/iscsi/nodes/iqn.1992-05.com.emc:fl1001433000190000-3-vnxe/192.168.1.2\,3260\,1/
     65 ```
     66 
     67 Within the directory, there is a default file with all the settings necessary to connect to the target.
     68 
     69 1. Rename `/etc/iscsi/nodes/iqn.1992-05.com.emc:fl1001433000190000-3-vnxe/192.168.1.2\,3260\,1/` to `/etc/iscsi/nodes/iqn.1992-05.com.emc:fl1001433000190000-3-vnxe/123.123.123.123\,3260\,1/`
     70 2. Within `/etc/iscsi/nodes/iqn.1992-05.com.emc:fl1001433000190000-3-vnxe/123.123.123.123\,3260\,1/default`, change the `node.conn[0].address` setting to point to 123.123.123.123 instead of 192.168.1.2. This could be done with a command such as `sed -i 's/192.168.1.2/123.123.123.123/g' /etc/iscsi/nodes/iqn.1992-05.com.emc:fl1001433000190000-3-vnxe/123.123.123.123\,3260\,1/default`
     71 
     72 After login, inspect the newly attached block device with `lsblk` or `lsscsi`. During an assessment, mount filesystems **read-only first** (for example, `mount -o ro,noload`) to avoid journal replay or other writes to evidence and production data.<sup>[[1]](#references)[[2]](#references)</sup>
     73 
     74 ### Mount iSCSI on Windows
     75 
     76 Use the built-in Microsoft iSCSI Initiator (`iscsicpl.exe`), PowerShell iSCSI module, or legacy `iscsicli` tool to add the target portal, discover the IQN, and connect. For example:<sup>[[5]](#references)</sup>
     77 
     78 ```powershell
     79 New-IscsiTargetPortal -TargetPortalAddress <TARGET_IP>
     80 Get-IscsiTarget
     81 Connect-IscsiTarget -NodeAddress '<TARGET_IQN>' -IsPersistent $false
     82 Get-IscsiSession
     83 ```
     84 
     85 Apply the same read-only/evidence-handling precautions before bringing discovered disks online. Disconnect the temporary session with `Disconnect-IscsiTarget -NodeAddress '<TARGET_IQN>' -Confirm:$false` when the assessment is complete.
     86 
     87 ## **Manual enumeration**
     88 
     89 ```bash
     90 sudo apt-get install open-iscsi
     91 ```
     92 
     93 Example from [iscsiadm docs](https://ptestmethod.readthedocs.io/en/latest/LFF-IPS-P2-VulnerabilityAnalysis.html#iscsiadm):<sup>[[1]](#references)[[2]](#references)</sup>
     94 
     95 First of all you need to **discover the targets** name behind the IP:
     96 
     97 ```bash
     98 iscsiadm -m discovery -t sendtargets -p 123.123.123.123:3260
     99 123.123.123.123:3260,1 iqn.1992-05.com.emc:fl1001433000190000-3-vnxe
    100 [2a01:211:7b7:1223:211:32ff:fea9:fab9]:3260,1 iqn.2000-01.com.synology:asd3.Target-1.d0280fd382
    101 [fe80::211:3232:fab9:1223]:3260,1 iqn.2000-01.com.synology:Oassdx.Target-1.d0280fd382
    102 ```
    103 
    104 _Note that it will show the I**P and port of the interfaces** where you can **reach** those **targets**. It can even **show internal IPs or different IPs** from the one you used._
    105 
    106 Then you **catch the 2nd part of the printed string of each line** (_iqn.1992-05.com.emc:fl1001433000190000-3-vnxe_ from the first line) and **try to login**:
    107 
    108 ```bash
    109 iscsiadm -m node --targetname="iqn.1992-05.com.emc:fl1001433000190000-3-vnxe" -p 123.123.123.123:3260 --login
    110 Logging in to [iface: default, target: iqn.1992-05.com.emc:fl1001433000190000-3-vnxe, portal: 123.123.123.123,3260] (multiple)
    111 Login to [iface: default, target: iqn.1992-05.com.emc:fl1001433000190000-3-vnxe, portal: 123.123.123.123,3260] successful.
    112 ```
    113 
    114 Then, you can **log out** using `--logout`:
    115 
    116 ```bash
    117 iscsiadm -m node --targetname="iqn.1992-05.com.emc:fl1001433000190000-3-vnxe" -p 123.123.123.123:3260 --logout
    118 Logging out of session [sid: 6, target: iqn.1992-05.com.emc:fl1001433000190000-3-vnxe, portal: 123.123.123.123,3260]
    119 Logout of [sid: 6, target: iqn.1992-05.com.emc:fl1001433000190000-3-vnxe, portal: 123.123.123.123,3260] successful.
    120 ```
    121 
    122 We can find **more information** about it by just using **without** any `--login`/`--logout` parameter
    123 
    124 ```bash
    125 iscsiadm -m node --targetname="iqn.1992-05.com.emc:fl1001433000190000-3-vnxe" -p 123.123.123.123:3260
    126 # BEGIN RECORD 2.0-873
    127 node.name = iqn.1992-05.com.emc:fl1001433000190000-3-vnxe
    128 node.tpgt = 1
    129 node.startup = manual
    130 node.leading_login = No
    131 iface.hwaddress = <empty>
    132 iface.ipaddress = <empty>
    133 iface.iscsi_ifacename = default
    134 iface.net_ifacename = <empty>
    135 iface.transport_name = tcp
    136 iface.initiatorname = <empty>
    137 iface.bootproto = <empty>
    138 iface.subnet_mask = <empty>
    139 iface.gateway = <empty>
    140 iface.ipv6_autocfg = <empty>
    141 iface.linklocal_autocfg = <empty>
    142 iface.router_autocfg = <empty>
    143 iface.ipv6_linklocal = <empty>
    144 iface.ipv6_router = <empty>
    145 iface.state = <empty>
    146 iface.vlan_id = 0
    147 iface.vlan_priority = 0
    148 iface.vlan_state = <empty>
    149 iface.iface_num = 0
    150 iface.mtu = 0
    151 iface.port = 0
    152 node.discovery_address = 192.168.xx.xx
    153 node.discovery_port = 3260
    154 node.discovery_type = send_targets
    155 node.session.initial_cmdsn = 0
    156 node.session.initial_login_retry_max = 8
    157 node.session.xmit_thread_priority = -20
    158 node.session.cmds_max = 128
    159 node.session.queue_depth = 32
    160 node.session.nr_sessions = 1
    161 node.session.auth.authmethod = None
    162 node.session.auth.username = <empty>
    163 node.session.auth.password = <empty>
    164 node.session.auth.username_in = <empty>
    165 node.session.auth.password_in = <empty>
    166 node.session.timeo.replacement_timeout = 120
    167 node.session.err_timeo.abort_timeout = 15
    168 node.session.err_timeo.lu_reset_timeout = 30
    169 node.session.err_timeo.tgt_reset_timeout = 30
    170 node.session.err_timeo.host_reset_timeout = 60
    171 node.session.iscsi.FastAbort = Yes
    172 node.session.iscsi.InitialR2T = No
    173 node.session.iscsi.ImmediateData = Yes
    174 node.session.iscsi.FirstBurstLength = 262144
    175 node.session.iscsi.MaxBurstLength = 16776192
    176 node.session.iscsi.DefaultTime2Retain = 0
    177 node.session.iscsi.DefaultTime2Wait = 2
    178 node.session.iscsi.MaxConnections = 1
    179 node.session.iscsi.MaxOutstandingR2T = 1
    180 node.session.iscsi.ERL = 0
    181 node.conn[0].address = 192.168.xx.xx
    182 node.conn[0].port = 3260
    183 node.conn[0].startup = manual
    184 node.conn[0].tcp.window_size = 524288
    185 node.conn[0].tcp.type_of_service = 0
    186 node.conn[0].timeo.logout_timeout = 15
    187 node.conn[0].timeo.login_timeout = 15
    188 node.conn[0].timeo.auth_timeout = 45
    189 node.conn[0].timeo.noop_out_interval = 5
    190 node.conn[0].timeo.noop_out_timeout = 5
    191 node.conn[0].iscsi.MaxXmitDataSegmentLength = 0
    192 node.conn[0].iscsi.MaxRecvDataSegmentLength = 262144
    193 node.conn[0].iscsi.HeaderDigest = None
    194 node.conn[0].iscsi.DataDigest = None
    195 node.conn[0].iscsi.IFMarker = No
    196 node.conn[0].iscsi.OFMarker = No
    197 # END RECORD
    198 ```
    199 
    200 **There is a script to automate basic subnet enumeration process available at** [**iscsiadm**](https://github.com/bitvijays/Pentest-Scripts/tree/master/Vulnerability_Analysis/isciadm)
    201 
    202 ## **Shodan**
    203 
    204 - `port:3260 AuthMethod`
    205 
    206 ## References
    207 
    208 - [1] [Archived LFF-IPS-P2 Vulnerability Analysis - iSCSI pentesting guide](https://web.archive.org/web/20230000000000id_/https://bitvijays.github.io/LFF-IPS-P2-VulnerabilityAnalysis.html)
    209 - [2] [LFF-IPS-P2 Vulnerability Analysis – iscsiadm section (ptestmethod docs mirror)](https://ptestmethod.readthedocs.io/en/latest/LFF-IPS-P2-VulnerabilityAnalysis.html#iscsiadm)
    210 - [3] [RFC 7143 - Internet Small Computer System Interface (iSCSI) Protocol](https://datatracker.ietf.org/doc/html/rfc7143)
    211 - [4] [Open-iSCSI - iscsiadm usage and node database](https://github.com/open-iscsi/open-iscsi)
    212 - [5] [Microsoft Learn - Windows iSCSI Initiator PowerShell module](https://learn.microsoft.com/en-us/powershell/module/iscsi/?view=windowsserver2025-ps)