daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

69-udp-tftp.md (6307B)


      1 ---
      2 title: "69 - UDP TFTP"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/69-udp-tftp.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/69-udp-tftp.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 69 - UDP TFTP
     14 
     15 ## Basic Information
     16 
     17 **Trivial File Transfer Protocol (TFTP)** is a small UDP-based file-transfer protocol. A client sends its initial read or write request to UDP port 69, after which the transfer uses negotiated transfer identifiers (UDP ports). TFTP provides neither user authentication nor directory listing, so server-side file permissions and path restrictions are its primary access controls.<sup>[[1]](#references)</sup>
     18 
     19 TFTP is still commonly encountered on internal networks for bootstrapping devices—including VoIP handsets—and transferring firmware, ROM images, or configuration files. Those files can reveal credentials and network topology, so test both readable and writable paths within the authorized scope.<sup>[[1]](#references)</sup>
     20 
     21 **Default Port:** 69/UDP
     22 
     23 ```text
     24 PORT   STATE SERVICE REASON
     25 69/udp open  tftp    script-set
     26 ```
     27 
     28 ## Enumeration
     29 
     30 Because TFTP does not provide directory listings, Nmap's `tftp-enum` script requests names from a list of common files. It is categorized as intrusive; use it only against systems you are authorized to test.<sup>[[2]](#references)</sup>
     31 
     32 ```bash
     33 nmap -n -Pn -sU -p69 -sV --script tftp-enum <IP>
     34 ```
     35 
     36 The NSE script also generates Cisco-style `A.B.C.X-confg` candidates from the target address. Supply a target-specific list built from observed boot filenames, device models and provisioning conventions instead of relying only on its generic list.<sup>[[2]](#references)</sup>
     37 
     38 ```bash
     39 nmap -n -Pn -sU -p69 --script tftp-enum \
     40   --script-args tftp-enum.filelist=./tftp-files.txt <IP>
     41 ```
     42 
     43 TFTP error packets distinguish conditions such as **file not found** (code 1), **access violation** (2), **file already exists** (6) and an **unknown transfer ID** (5). Treat the exact mapping as implementation-specific, but preserve responses while enumerating because a policy rejection is more informative than a timeout.<sup>[[1]](#references)</sup>
     44 
     45 The server's first response comes from a new UDP source port, not necessarily 69. If a scanner finds port 69 but transfers time out, capture all UDP traffic to the host and check whether a firewall/NAT is dropping the negotiated flow.<sup>[[1]](#references)[[3]](#references)</sup>
     46 
     47 ```bash
     48 sudo tcpdump -ni any "udp and host <IP>"
     49 ```
     50 
     51 ### Download/Upload
     52 
     53 Use Metasploit's transfer utility or a TFTP client to test explicitly authorized reads and writes. Uploads succeed only when the server permits writing to the requested location.<sup>[[1]](#references)[[3]](#references)</sup>
     54 
     55 ```text
     56 msfconsole -q
     57 use auxiliary/admin/tftp/tftp_transfer_util
     58 set ACTION Download
     59 set RHOST <IP>
     60 set REMOTE_FILENAME <remote-file>
     61 run
     62 ```
     63 
     64 A native client is useful for sending an exact remote pathname. Always use binary (`octet`) mode for firmware, archives and other non-text files.<sup>[[1]](#references)[[3]](#references)</sup>
     65 
     66 ```text
     67 tftp <IP>
     68 tftp> mode binary
     69 tftp> verbose
     70 tftp> get <remote-file> /tmp/downloaded-file
     71 tftp> put /tmp/local-canary <unique-remote-name>
     72 tftp> quit
     73 ```
     74 
     75 Or automate exact filenames with `tftpy`:
     76 
     77 ```python
     78 import tftpy
     79 client = tftpy.TftpClient("192.0.2.10", 69)
     80 client.download("filename in server", "/tmp/filename", timeout=5)
     81 client.upload("remote-filename", "/local/path/file", timeout=5)
     82 ```
     83 
     84 A failed new-file upload does **not** prove that the service is entirely read-only. For example, `tftpd-hpa` normally permits writes only to files that already exist and are publicly writable; its `--create` option enables creation. Test a unique new name first and, only with the system owner's coordination, an existing disposable canary. TFTP has no delete request, so plan cleanup separately.<sup>[[1]](#references)[[5]](#references)</sup>
     85 
     86 If writable provisioning, boot or firmware files are found, determine which client consumes each file and whether it verifies authenticity before modifying anything. For protocol-specific pivots, see [Cisco SNMP configuration copy abuse](/hacktricks/network-services-pentesting/pentesting-snmp/cisco-snmp), [SCCM PXE boot artifacts](/hacktricks/windows-hardening/active-directory-methodology/sccm-management-point-relay-sql-policy-secrets) and [bootloader testing](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/hardware-physical-access/firmware-analysis/bootloader-testing.md).
     87 
     88 ### Path traversal and root confinement
     89 
     90 Do not assume a configured TFTP root is a security boundary. Test canonicalization with a harmless, known file outside the intended root using OS-appropriate separators (for example `../` versus `..\`) and both relative and absolute names. The 2026 Erlang/OTP advisory is a recent example: its `root_dir` handling concatenated attacker-controlled filenames without preventing `..` components, allowing unauthenticated reads or writes with the TFTP process privileges.<sup>[[4]](#references)</sup>
     91 
     92 ```text
     93 tftp <IP>
     94 tftp> mode binary
     95 tftp> get ../../etc/hostname /tmp/tftp-hostname
     96 ```
     97 
     98 A secure implementation should canonicalize the requested path and reject any result outside its export. Server-side containment such as `tftpd-hpa --secure` (chroot), a dedicated low-privilege account, read-only exports and network allowlisting limit the impact if validation fails.<sup>[[4]](#references)[[5]](#references)</sup>
     99 
    100 ### Shodan
    101 
    102 - `port:69`
    103 
    104 
    105 ## References
    106 
    107 - [1] [RFC 1350 - The TFTP Protocol (Revision 2)](https://www.rfc-editor.org/rfc/rfc1350.html)
    108 - [2] [Nmap NSE documentation - tftp-enum](https://nmap.org/nsedoc/scripts/tftp-enum.html)
    109 - [3] [Rapid7 Metasploit - TFTP file transfer utility](https://www.rapid7.com/db/modules/auxiliary/admin/tftp/tftp_transfer_util/)
    110 - [4] [Erlang/OTP security advisory - TFTP Path Traversal](https://github.com/erlang/otp/security/advisories/GHSA-hmrc-prh3-rpvp)
    111 - [5] [Debian manpages - tftpd-hpa](https://manpages.debian.org/trixie/tftpd-hpa/in.tftpd.8.en.html)