bk99.de entertain the web since 1997

17,000 Linux servers vulnerable to critical rsync hole

Summary

In January 2025 six holes in rsync became known, including the critical CVE-2024-12084, which in combination allows servers with only anonymous read access to be taken over. According to Shadowserver, 17,475 freely reachable rsync servers worldwide were vulnerable on 16 January, with Germany in fifth place with 956. All versions up to 3.3.0 were affected; the fixes came in 3.4.0 and 3.4.1.

Ideas

  • Anonymous read access to an rsync daemon is enough as a way in.
  • Detection was based on the version number reported on port 873.
  • rsync is part of many backup tools and often runs unnoticed.
  • Around 88 percent of reachable servers had already been patched.

Insights

  • Inconspicuous infrastructure tools are often forgotten because they simply work for years.
  • Open services without login are immediately attackable with every new hole.

Facts

  • Worldwide, 146,844 rsync servers were reachable without a password.
  • The patched version 3.4.0 appeared on 14 January 2025.

References

Critique

  • The count is based on version information and covers neither backported patches nor password-protected servers.

Recommendations

  • Do not run rsync as an open daemon, but over SSH.
  • Check whether backup tools open an rsync service unnoticed.

Read the original article

Search the Web Archive