MEDIUM: Accessible Rsync Report

DESCRIPTION LAST UPDATED: 2023-12-27

DEFAULT SEVERITY LEVEL: MEDIUM

This report identifies hosts that have the rsync service running, bound to a network port (873/tcp) and accessible on the Internet without a password.

See https://rsync.samba.org/ for more information.

For a daily update of global Rsync scan statistics please visit our rsync Dashboard statistics.

Severity levels are described here.

For more information on our scanning efforts, check out our Internet scanning summary page..

Filename: scan_rsync

Fields

  • timestamp
    Time that the IP was probed in UTC+0
  • severity
    Severity level
  • ip
    The IP address of the device in question
  • protocol
    Protocol that the rsync response came on (always TCP)
  • port
    Port that the rsync response came from (873/TCP)
  • hostname
    Reverse DNS name of the device in question
  • tag
    This will always be rsync
  • asn
    ASN of where the device in question resides
  • geo
    Country where the device in question resides
  • region
    State / Province / Administrative region where the device in question resides
  • city
    City in which the device in question resides
  • naics
    North American Industry Classification System Code
  • hostname_source
    Hostname source
  • module
    Module(s) (repositories of data) presented
  • motd
    Message of the Day
  • has_password
    Checks to see if a password was requested; if "N" or "" a password challenge was not given
  • sector
    Sector the IP belongs to

Sample

"timestamp","severity","ip","protocol","port","hostname","tag","asn","geo","region","city","naics","hostname_source","module","motd","has_password","sector"
"2010-02-10 00:00:00",medium,192.168.0.1,tcp,873,node01.example.com,rsync,64512,ZZ,Region,City,0,,"system|Backup system;system_full|Backup full system;mysql|Backup virtual mysql;netadmin|Backup virtual netadmin;",,,
"2010-02-10 00:00:01",medium,192.168.0.2,tcp,873,node02.example.com,rsync,64512,ZZ,Region,City,0,,"system|Backup system;system_full|Backup full system;mysql|Backup virtual mysql;netadmin|Backup virtual netadmin;",,N,
"2010-02-10 00:00:02",medium,192.168.0.3,tcp,873,node03.example.com,rsync,64512,ZZ,Region,City,0,,"system|Backup system;system_full|Backup full system;mysql|Backup virtual mysql;netadmin|Backup virtual netadmin;",,N,

Our 131 Report Types