The rsync daemon (rsyncd, port 873) exports directory trees as named modules. It is often deployed for backups and mirrors with weak or no authentication. Attacks enumerate the modules, read from anonymous or weakly-authenticated ones, and abuse writable modules to plant files that grant code execution.
Subtopics#
- Module enumeration: listing the exported modules.
- Anonymous file access: reading from open modules.
- Write access: uploading to writable modules for execution.