873 - Pentesting Rsync
Basic Information
rsync synchronizes files locally, over a remote shell such as SSH, or through the rsync daemon protocol. Its delta-transfer algorithm can reduce network traffic, while options control compression, recursion, and which metadata is preserved.[2]
The earlier zlib and stunnel details remain operationally relevant. With --compress, current rsync versions can negotiate zstd, lz4, zlibx, or zlib; an older peer is normally assumed to support zlib. A direct rsync-daemon connection is not automatically encrypted: use the remote-shell form over SSH or a correctly authenticated TLS wrapper such as rsync-ssl/stunnel when confidentiality and server identity are required.[2][4]
Default port: 873
PORT STATE SERVICE REASON
873/tcp open rsync syn-ack
Enumeration
Banner & Manual communication
nc -vn 127.0.0.1 873
(UNKNOWN) [127.0.0.1] 873 (rsync) open
@RSYNCD: 31.0 <--- You receive this banner with the version from the server
@RSYNCD: 31.0 <--- Then you send the same info
#list <--- Then you ask the sever to list
raidroot <--- The server starts enumerating
USBCopy
NAS_Public
_NAS_Recycle_TOSRAID <--- Enumeration finished
@RSYNCD: EXIT <--- Sever closes the connection
#Now lets try to enumerate "raidroot"
nc -vn 127.0.0.1 873
(UNKNOWN) [127.0.0.1] 873 (rsync) open
@RSYNCD: 31.0
@RSYNCD: 31.0
raidroot
@RSYNCD: AUTHREQD 7H6CqsHCPG06kRiFkKwD8g <--- This means you need the password
Enumerating Shared Folders
Rsync modules are recognized as directory shares that might be protected with passwords. To identify available modules and check if they require passwords, the following commands are used:[1]
nmap -sV --script "rsync-list-modules" -p <PORT> <IP>
msf> use auxiliary/scanner/rsync/modules_list
# Example with IPv6 and alternate port
rsync -av --list-only rsync://[dead:beef::250:56ff:feb9:e90a]:8730
Be aware that some shares might not appear in the list, possibly hiding them. Additionally, accessing some shares might be restricted to specific credentials, indicated by an “Access Denied” message.
Brute Force
Manual Rsync Usage
Upon obtaining a module list, actions depend on whether authentication is needed. Without authentication, listing and copying files from a shared folder to a local directory is achieved through:
# Listing a shared folder
rsync -av --list-only rsync://192.168.0.123/shared_name
# Copying files from a shared folder
rsync -av rsync://192.168.0.123:8730/shared_name ./rsyn_shared
With -a, this process recursively transfers files and requests archive-mode metadata preservation. Actual ownership, ACL, xattr, device, and permission behavior depends on additional options and privileges.[1][2]
With credentials, listing and downloading from a shared folder can be done as follows, where a password prompt will appear:
rsync -av --list-only rsync://username@192.168.0.123/shared_name
rsync -av rsync://username@192.168.0.123:8730/shared_name ./rsyn_shared
To upload content, such as an authorized_keys file for access, use:
rsync -av home_user/.ssh/ rsync://username@192.168.0.123/home_user/.ssh
POST
To locate the rsyncd configuration file, execute:
find /etc \( -name rsyncd.conf -o -name rsyncd.secrets \)
Within this file, a secrets file parameter might point to a file containing usernames and passwords for rsyncd authentication. Module options also control listing, read/write access, path confinement, and allowed hosts.[3]