69-udp-tftp.md (6307B)
1 --- 2 title: "69 - UDP TFTP" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/69-udp-tftp.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/69-udp-tftp.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 69 - UDP TFTP 14 15 ## Basic Information 16 17 **Trivial File Transfer Protocol (TFTP)** is a small UDP-based file-transfer protocol. A client sends its initial read or write request to UDP port 69, after which the transfer uses negotiated transfer identifiers (UDP ports). TFTP provides neither user authentication nor directory listing, so server-side file permissions and path restrictions are its primary access controls.<sup>[[1]](#references)</sup> 18 19 TFTP is still commonly encountered on internal networks for bootstrapping devices—including VoIP handsets—and transferring firmware, ROM images, or configuration files. Those files can reveal credentials and network topology, so test both readable and writable paths within the authorized scope.<sup>[[1]](#references)</sup> 20 21 **Default Port:** 69/UDP 22 23 ```text 24 PORT STATE SERVICE REASON 25 69/udp open tftp script-set 26 ``` 27 28 ## Enumeration 29 30 Because TFTP does not provide directory listings, Nmap's `tftp-enum` script requests names from a list of common files. It is categorized as intrusive; use it only against systems you are authorized to test.<sup>[[2]](#references)</sup> 31 32 ```bash 33 nmap -n -Pn -sU -p69 -sV --script tftp-enum <IP> 34 ``` 35 36 The NSE script also generates Cisco-style `A.B.C.X-confg` candidates from the target address. Supply a target-specific list built from observed boot filenames, device models and provisioning conventions instead of relying only on its generic list.<sup>[[2]](#references)</sup> 37 38 ```bash 39 nmap -n -Pn -sU -p69 --script tftp-enum \ 40 --script-args tftp-enum.filelist=./tftp-files.txt <IP> 41 ``` 42 43 TFTP error packets distinguish conditions such as **file not found** (code 1), **access violation** (2), **file already exists** (6) and an **unknown transfer ID** (5). Treat the exact mapping as implementation-specific, but preserve responses while enumerating because a policy rejection is more informative than a timeout.<sup>[[1]](#references)</sup> 44 45 The server's first response comes from a new UDP source port, not necessarily 69. If a scanner finds port 69 but transfers time out, capture all UDP traffic to the host and check whether a firewall/NAT is dropping the negotiated flow.<sup>[[1]](#references)[[3]](#references)</sup> 46 47 ```bash 48 sudo tcpdump -ni any "udp and host <IP>" 49 ``` 50 51 ### Download/Upload 52 53 Use Metasploit's transfer utility or a TFTP client to test explicitly authorized reads and writes. Uploads succeed only when the server permits writing to the requested location.<sup>[[1]](#references)[[3]](#references)</sup> 54 55 ```text 56 msfconsole -q 57 use auxiliary/admin/tftp/tftp_transfer_util 58 set ACTION Download 59 set RHOST <IP> 60 set REMOTE_FILENAME <remote-file> 61 run 62 ``` 63 64 A native client is useful for sending an exact remote pathname. Always use binary (`octet`) mode for firmware, archives and other non-text files.<sup>[[1]](#references)[[3]](#references)</sup> 65 66 ```text 67 tftp <IP> 68 tftp> mode binary 69 tftp> verbose 70 tftp> get <remote-file> /tmp/downloaded-file 71 tftp> put /tmp/local-canary <unique-remote-name> 72 tftp> quit 73 ``` 74 75 Or automate exact filenames with `tftpy`: 76 77 ```python 78 import tftpy 79 client = tftpy.TftpClient("192.0.2.10", 69) 80 client.download("filename in server", "/tmp/filename", timeout=5) 81 client.upload("remote-filename", "/local/path/file", timeout=5) 82 ``` 83 84 A failed new-file upload does **not** prove that the service is entirely read-only. For example, `tftpd-hpa` normally permits writes only to files that already exist and are publicly writable; its `--create` option enables creation. Test a unique new name first and, only with the system owner's coordination, an existing disposable canary. TFTP has no delete request, so plan cleanup separately.<sup>[[1]](#references)[[5]](#references)</sup> 85 86 If writable provisioning, boot or firmware files are found, determine which client consumes each file and whether it verifies authenticity before modifying anything. For protocol-specific pivots, see [Cisco SNMP configuration copy abuse](/hacktricks/network-services-pentesting/pentesting-snmp/cisco-snmp), [SCCM PXE boot artifacts](/hacktricks/windows-hardening/active-directory-methodology/sccm-management-point-relay-sql-policy-secrets) and [bootloader testing](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/hardware-physical-access/firmware-analysis/bootloader-testing.md). 87 88 ### Path traversal and root confinement 89 90 Do not assume a configured TFTP root is a security boundary. Test canonicalization with a harmless, known file outside the intended root using OS-appropriate separators (for example `../` versus `..\`) and both relative and absolute names. The 2026 Erlang/OTP advisory is a recent example: its `root_dir` handling concatenated attacker-controlled filenames without preventing `..` components, allowing unauthenticated reads or writes with the TFTP process privileges.<sup>[[4]](#references)</sup> 91 92 ```text 93 tftp <IP> 94 tftp> mode binary 95 tftp> get ../../etc/hostname /tmp/tftp-hostname 96 ``` 97 98 A secure implementation should canonicalize the requested path and reject any result outside its export. Server-side containment such as `tftpd-hpa --secure` (chroot), a dedicated low-privilege account, read-only exports and network allowlisting limit the impact if validation fails.<sup>[[4]](#references)[[5]](#references)</sup> 99 100 ### Shodan 101 102 - `port:69` 103 104 105 ## References 106 107 - [1] [RFC 1350 - The TFTP Protocol (Revision 2)](https://www.rfc-editor.org/rfc/rfc1350.html) 108 - [2] [Nmap NSE documentation - tftp-enum](https://nmap.org/nsedoc/scripts/tftp-enum.html) 109 - [3] [Rapid7 Metasploit - TFTP file transfer utility](https://www.rapid7.com/db/modules/auxiliary/admin/tftp/tftp_transfer_util/) 110 - [4] [Erlang/OTP security advisory - TFTP Path Traversal](https://github.com/erlang/otp/security/advisories/GHSA-hmrc-prh3-rpvp) 111 - [5] [Debian manpages - tftpd-hpa](https://manpages.debian.org/trixie/tftpd-hpa/in.tftpd.8.en.html)