Module enumeration

An rsync daemon advertises its modules to anyone who connects without specifying a path. Listing them reveals the exported directory trees, their names often hinting at backups, web roots, or home directories, which guides whether to read or attempt to write.

bash
# List modules (no path = list request)
rsync rsync://<target>/
rsync -av --list-only rsync://<target>/
nmap -p 873 --script rsync-list-modules <target>

Exploitation notes#

  • Module names are descriptive (backup, www, home), pointing straight at high-value trees.
  • A module that lists without credentials is readable anonymously; one that prompts for auth needs credentials from rsyncd.secrets or brute force.
  • Note each module's apparent intent to decide read (Anonymous file access) versus write (Write access).

References#

Cookie Consent

We use cookies to enhance your experience. Learn more