Skip to main content

Want to Practice These Techniques?

Try Hackviser's interactive cyber security upskilling platform - Learn by doing!

Start Practicing Now

ISCSI Pentesting

Default Port: 3260

iSCSI (Internet Small Computer System Interface) is a protocol used for establishing and managing connections between storage devices over an IP network. It enables storage devices to be shared and accessed remotely, providing block-level access to storage resources.

iSCSI is commonly used in data centers and enterprise environments for storage area networks (SANs) and virtualization deployments.

Connect​

Login with an iSCSI Initiator​

After discovering a target IQN, use the open-iscsi iscsiadm interface with its target name and portal to log in:

iscsiadm --mode node --targetname <target-iqn> --portal <target-ip>:3260 --login

Recon​

Identifying an iSCSI Target​

Use Nmap service detection to identify an iSCSI target:

nmap -sV -p 3260 <target-ip>

Confirming TCP Access​

iSCSI is a binary protocol, so Netcat does not provide a useful text banner. It can still confirm whether the TCP port is reachable:

nc -nvz <target-ip> 3260

Enumeration​

Discovering Targets​

Use SendTargets discovery to retrieve the target IQNs published by a portal:

iscsiadm --mode discoverydb --type sendtargets --portal <target-ip>:3260 --discover

List the node records created by discovery:

iscsiadm --mode node

Attack Vectors​

Missing or Weak CHAP Authentication​

iSCSI discovery and normal sessions can require separate CHAP credentials. A target that permits unauthenticated discovery may disclose IQNs, while a target that permits unauthenticated login may expose mapped LUNs. An IQN identifies an initiator or target; it is not a password.

Unrestricted Target Access​

Target portal groups and ACLs determine which initiators can access a target and which LUNs they can reach. Weak or missing ACLs can expose storage to unintended initiators.

Writable LUNs​

An authenticated session exposes block devices rather than files. Read access can disclose data stored on a LUN, while write access can modify its partition table, filesystem, or application data.

Post-Exploitation​

Common iSCSI Commands​

CommandDescription
iscsiadm -m nodeList discovered node records
iscsiadm -m node -T <target-iqn> -p <target-ip>:3260 --loginLog in to a selected target
iscsiadm -m session -P 3Display detailed session, connection, and attached-device information
iscsiadm -m node -T <target-iqn> -p <target-ip>:3260 --logoutLog out of a selected target

Inspecting an Attached LUN​

After login, identify the block device associated with the session and inspect its filesystem metadata:

iscsiadm -m session -P 3
lsblk
blkid
mount -o ro <device> <mount-point>