Port 873: rsync daemon protocol
TCP 873 is the default port for the rsync daemon (rsyncd), which serves file modules for mirroring, backup and file distribution. Public software mirrors often allow anonymous rsync on this port. rsync can also run over SSH, in which case port 873 is not used.
Port Details
Security Exposure
The rsync daemon protocol provides authentication only and does not encrypt the connection, and modules allow access without a password unless auth users is set. CERT/CC VU#952657 describes a heap buffer overflow (CVE-2024-12084) and an information leak (CVE-2024-12085) in rsync that, combined, let a client with only anonymous read access execute code on the rsync server.
Hardening
- +Apply the latest rsync patches, including in software that bundles rsync, as CERT/CC advises.
- +Set auth users and hosts allow on every module so only known clients can connect.
- +Keep modules read only unless the module must accept uploads.
- +Use ssh as the transport, or put the daemon behind an SSL/TLS proxy, when data crosses untrusted networks.
- +Allow TCP 873 only from the hosts that need to sync, and block it at the network edge.
Monitoring
Enable the rsyncd log file parameter or syslog output and review connections from unexpected addresses. Alert on new hosts listening on TCP 873.
Tools for Auditing and Monitoring rsync
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nessus
CommercialTenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.
OPENVAS
Free / CommercialFull-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.
Related Tool Categories
Frequently Asked Questions
Is rsync on port 873 encrypted?→
No. The rsyncd.conf documentation says the daemon connection provides only authentication and recommends ssh as the transport or an SSL/TLS proxy in front of the daemon for encryption.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 873 is not guaranteed to be rsync. Exploited-in-the-wild data from the CISA KEV catalog (CC0).