> For the complete documentation index, see [llms.txt](https://strange-1.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://strange-1.gitbook.io/notes/enumeration/linux-remote-management-protocols.md).

# Linux Remote Management Protocols

### SSH-Audit

```bash
# Downloading SSh-Audit 
git clone <https://github.com/jtesta/ssh-audit.git> && cd ssh-audit

# footprinting ssh server
./ssh-audit.py ip
```

### Change Authentication Method

```bash
# Changing authentication method
ssh -v eren@ip

# for brute force attacks, changing method 
ssh -v eren@ip -o PreferredAuthentications=password
```

### Rsync - 873

```bash
# Useful guide to abuse Rsync : <https://book.hacktricks.xyz/network-services-pentesting/873-pentesting-rsync> 

# Scanning Rsync using Nmap
sudo nmap -sV -p 873 127.0.0.1

# Probing for Accessible Shares
nc -nv 127.0.0.1 873

(UNKNOWN) [127.0.0.1] 873 (rsync) open
@RSYNCD: 31.0
@RSYNCD: 31.0
#list
dev            	Dev Tools
@RSYNCD: EXIT

# Enumerating an Open Share
rsync -av --list-only rsync://127.0.0.1/dev

# sync all files to our attack host with the command :
rsync -av rsync://127.0.0.1/dev
```
