An rsync daemon advertises its modules to anyone who connects without specifying a path. Listing them reveals the exported directory trees, their names often hinting at backups, web roots, or home directories, which guides whether to read or attempt to write.
# List modules (no path = list request)
rsync rsync://<target>/
rsync -av --list-only rsync://<target>/
nmap -p 873 --script rsync-list-modules <target>
Exploitation notes#
- Module names are descriptive (
backup,www,home), pointing straight at high-value trees. - A module that lists without credentials is readable anonymously; one that prompts for auth needs credentials from
rsyncd.secretsor brute force. - Note each module's apparent intent to decide read (Anonymous file access) versus write (Write access).