Hacker News new | past | comments | ask | show | jobs | submit login

What is interesting is that the rsync daemon is not something typically enabled by default, you have to go in and manually turn it on, and if you don't alter the configuration to add users and passwords, it simply won't allow login at all.

So someone has gone out of their way to set up insecure rsync daemons.

I wonder if all of these open rsync daemons is due to a poorly configured appliances like a NAS or some other "turn-key" vendor supplied kit. But even then it is a strange thing to enable insecurely...




One of the comments below did mention an insecure-by-default NAS:

https://news.ycombinator.com/item?id=7232518


Interesting. I knew it needed to be turned on but didn't realize that you needed to add users. So Rsync doesn't just use the default login info, the way SSH does?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: