Skip to main content

Port Details

Port
873
Transport
TCP
Service
rsync
IANA service name
rsync
Range
System port (0-1023)
Related ports

Security Exposure

The rsync daemon protocol provides authentication only and does not encrypt the connection, and modules allow access without a password unless auth users is set. CERT/CC VU#952657 describes a heap buffer overflow (CVE-2024-12084) and an information leak (CVE-2024-12085) in rsync that, combined, let a client with only anonymous read access execute code on the rsync server.

Hardening

  • +Apply the latest rsync patches, including in software that bundles rsync, as CERT/CC advises.
  • +Set auth users and hosts allow on every module so only known clients can connect.
  • +Keep modules read only unless the module must accept uploads.
  • +Use ssh as the transport, or put the daemon behind an SSL/TLS proxy, when data crosses untrusted networks.
  • +Allow TCP 873 only from the hosts that need to sync, and block it at the network edge.

Monitoring

Enable the rsyncd log file parameter or syslog output and review connections from unexpected addresses. Alert on new hosts listening on TCP 873.

Tools for Auditing and Monitoring rsync

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

OPENVAS

Free / Commercial
Vulnerability Scanning

Full-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.

LicenseGPL-2.0-only (C scanner); GPL-2.0-or-later WITH OpenSSL-exception (Rust)
PlatformLinux

Frequently Asked Questions

Is rsync on port 873 encrypted?→

No. The rsyncd.conf documentation says the daemon connection provides only authentication and recommends ssh as the transport or an SSL/TLS proxy in front of the daemon for encryption.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 873 is not guaranteed to be rsync. Exploited-in-the-wild data from the CISA KEV catalog (CC0).