
from xalgorix627
Procedures and checks to enumerate and exploit rsync daemon modules (port 873), detect unauthenticated shares, brute-force auth, and safely verify read/write ex
This skill provides a practical, operator-focused guide for testing rsync daemon services (rsync://) typically on port 873. It explains how to detect and enumerate rsync modules, confirm authentication requirements, and verify read or write access. The guidance covers banner inspection, nmap NSE usage, native rsync client commands, and common exploitation patterns such as recursive download of exposed backups and planting authorized_keys when write access is available. The content is written for authorized security assessments and emphasizes confirmation steps and practical remediation recommendations.
Use this skill during network services penetration tests, vulnerability assessments of NAS devices, or when nmap/banners indicate an active rsync daemon. It’s appropriate for: initial reconnaissance to enumerate modules; triage to determine auth requirements; exploitation verification when write/read access is suspected; and post-access pivoting to search for rsyncd.conf/secrets.
Best used by agents or operators with shell access and network scanning tools (nmap, hydra, rsync client, nc, Metasploit).
This skill has not been reviewed by our automated audit pipeline yet.
Building Threat Hunt Hypothesis Framework
Framework and workflow to turn threat intelligence and telemetry into testable, falsifiable threat-hunting hypotheses for proactive detection.
Ransomware-Resilient Backup Strategy
Designs and documents a ransomware-resilient backup architecture (3-2-1-1-0), immutability, credential isolation and automated restore testing aligned to RPO/RT
Performing SSL/TLS Security Assessment
Use sslyze to assess SSL/TLS server configurations: supported protocols, cipher suites, certificate chains, HSTS/OCSP, and common vulnerabilities like Heartblee
Configuring Identity-Aware Proxy (IAP) for Google Cloud
Step-by-step guide to secure Google Cloud services (Compute, App Engine, Cloud Run, GKE) with Identity-Aware Proxy, access levels, and programmatic service-acco
Pentesting FreeIPA — LDAP & Kerberos attack paths
Offensive/blue-team skill for authorized pentests: enumerates FreeIPA/LDAP/Kerberos environments, finds HBAC/sudo misconfigurations, reuses CCACHE/keytabs and m
Deception-Based Detection with Canarytoken
Create, deploy, and monitor Thinkst Canary Tokens (web, DNS, document, AWS key) to detect lateral movement and credential misuse.