Security findings catalog¶
nfswolf documents 62 NFS security findings across 7 attack categories. Every finding traces to a specific RFC section (or kernel code path) that explains why the vulnerability exists at the protocol level. Together they cover recon, credential forging, export escape, privilege escalation, and lateral movement.
The catalog is the authoritative reference for what nfswolf detects and why each attack works. Findings are numbered F-{category}.{sequence} and carry a severity rating, RFC basis, preconditions, and a mapping to the nfswolf subcommand that exercises them.
How to read a finding¶
Each finding page follows a consistent structure:
| Field | What it tells you |
|---|---|
| Severity | Critical / High / Medium / Low / Info -- based on direct exploitability and impact |
| RFC Basis | The specific RFC section (or kernel code path) that creates the vulnerability |
| Precondition | What must be true on the target for the finding to apply |
| Detection | The protocol operation nfswolf uses to test for the condition |
| Why the RFC allows this | The protocol-level rationale -- why this is a design property, not a bug |
| What nfswolf tests | The concrete checks and subcommands that exercise the finding |
Protocol root causes¶
The 62 findings trace back to four fundamental design properties of NFS:
Client-asserted credentials (AUTH_SYS)
The server trusts whatever UID, GID, and auxiliary groups the client claims. There is no verifier, no challenge-response, no proof of identity. This single design choice enables Category 1 (all 8 identity findings) and is a precondition for most of Category 4 (privilege escalation).
"There is no verifier, so credentials can easily be faked." -- RFC 1057 sec. 9.3
Bearer-token file handles
File handles are opaque blobs that grant access to whoever presents them. There is no binding to the client that received the handle, no expiry, and no revocation mechanism. Possession is authorization. This drives all 12 findings in Category 2.
"An attacker can circumvent the MOUNT server's access control by either stealing a file handle or guessing a file handle." -- RFC 2623 sec. 2.6
No transport security by default
NFS defers encryption and integrity to "underlying transport layers" that are never specified and rarely deployed. All wire traffic is plaintext unless the administrator explicitly configures Kerberos or RPC-with-TLS. This enables Category 3 (network attacks).
"NFS version 3 defers to the authentication provisions of the supporting RPC protocol." -- RFC 1813 sec. 8
Stateless architecture
The MOUNT protocol is an advisory directory service, not a security gate. The NFS daemon never calls back to MOUNT to verify that a client was authorized, and unmounting does not invalidate file handles. See the MOUNT protocol reference for the full architectural analysis.
Categories¶
| Category | ID Range | Count | Severity Breakdown | Description |
|---|---|---|---|---|
| Identity Attacks | F-1.1 -- F-1.8 | 8 | 1 Critical, 6 High, 1 Low | AUTH_SYS trust model exploitation: UID/GID spoofing, root squash bypass, credential replay, version downgrade |
| Access Control Bypass | F-2.1 -- F-2.12 | 12 | 6 Critical, 4 High, 2 Medium | File handle bearer-token abuse: export escape, handle guessing, cross-export lateral movement, LOOKUPP traversal |
| Network Attacks | F-3.1 -- F-3.9 | 9 | 1 Critical, 3 High, 3 Medium, 2 Info | Wire-level attacks: plaintext interception, UDP amplification, STRIPTLS downgrade, AUTH_DH weakness |
| Privilege Escalation | F-4.1 -- F-4.6 | 6 | 1 Critical, 4 High, 1 Medium | Post-access escalation: no_root_squash, SUID/SGID creation, device nodes, symlink escape, chown abuse |
| Information Disclosure | F-5.1 -- F-5.17 | 17 | 2 High, 6 Medium, 6 Low, 3 Info | Data leakage: export enumeration, handle harvesting, NIS extraction, metadata on denial, pNFS downgrade |
| Denial of Service | F-6.1 -- F-6.3 | 3 | 3 Medium | Lock and state attacks (out of scope -- documented only) |
| Configuration Weaknesses | F-7.1 -- F-7.7 | 7 | 1 Critical, 2 High, 3 Medium, 1 Info | Server misconfigurations: wildcard exports, missing nosuid/nodev, squash errors, FreeBSD subnet fingerprint |
Severity distribution¶
| Severity | Count | Proportion |
|---|---|---|
| Critical | 10 | 16% |
| High | 21 | 34% |
| Medium | 18 | 29% |
| Low | 7 | 11% |
| Info | 6 | 10% |
Half of all findings are Critical or High
31 of the 62 findings carry Critical or High severity. The NFS protocol's design (client-asserted credentials, bearer-token file handles, no transport security by default) makes most of these inherent to the protocol rather than implementation bugs.
Attack chain¶
The 62 findings connect into a directed attack flow where each stage feeds the next with handles, credentials, or filesystem access. See the attack chain page for the full diagram, stage-by-stage walkthrough, defense mapping, and an example attack narrative against a default Linux NFS server.
Cross-reference views¶
Browse findings grouped by a different axis:
By Protocol Version
- ONC RPC / Portmapper -- portmapper amplification, service enumeration, AUTH_SYS wire format
- MOUNT -- export enumeration, handle acquisition, UDP theft
- NFSv2 -- version downgrade, fixed 32-byte handles
- NFSv3 -- READDIRPLUS harvesting, ACCESS advisory, post_op_attr leaks
- NFSv4 -- LOOKUPP escape, pseudo-FS leakage, SECINFO probing, SETCLIENTID state destruction
By Attack Stage
- Recon -- pre-authentication information gathering
- Access -- initial foothold via credential forging or handle reuse
- Lateral Movement -- cross-export traversal
- Privilege Escalation -- post-access root and capability escalation
- Exfiltration -- sensitive data extraction
Scope and limitations¶
Category 6 (Denial of Service) is documented but not implemented
The three DoS findings (F-6.1 NLM lock attacks, F-6.2 grace period blocking, F-6.3 SETCLIENTID state destruction) are cataloged for completeness. The NLM and NSM clients were removed in v0.2.0 and the NFSv4 DoS attacks were never implemented. No nfswolf subcommand exercises these findings.
Some findings are detection-only
Several findings describe attacks that nfswolf detects but does not actively exploit: F-3.3 (IP spoofing requires network positioning), F-4.5 (SELinux bypass requires labeled NFS), F-7.4 (nosuid/nodev are client-side mount options not visible to the server), F-7.6 (audit logging gaps are not remotely testable). These are flagged by analyze as risk indicators.
Complete finding index¶
Every finding in the catalog, sorted by ID. The Detected By column lists the nfswolf subcommand(s) that exercise or detect the finding.
| ID | Name | Severity | Category | Detected By |
|---|---|---|---|---|
| F-1.1 | UID/GID Spoofing | Critical | Identity | uid-spray, shell uid/impersonate, mount --uid |
| F-1.2 | Root Squash Bypass | High | Identity | analyze (squash probe) |
| F-1.3 | Auxiliary Group Injection | High | Identity | analyze (shadow GID), shell gid, mount --aux-gids |
| F-1.4 | Machine Name Spoofing | Low | Identity | --hostname global flag |
| F-1.5 | Credential Replay | High | Identity | Passive -- precondition via F-3.1 |
| F-1.6 | NFSv2 Downgrade | High | Identity | scan (version matrix), analyze |
| F-1.7 | RPCSEC_GSS Flavor Downgrade | High | Identity | analyze (mixed auth flavor) |
| F-1.8 | AUTH_TOOWEAK Oracle | High | Identity | analyze (SECINFO, MOUNT auth-flavors) |
| F-2.1 | Export Escape via FS Root Handle | Critical | Access Control | escape, analyze, shell escape-root |
| F-2.2 | File Handle Guessing | High | Access Control | analyze (entropy), brute-handle |
| F-2.3 | Windows Handle Signing Disabled | Critical | Access Control | analyze (signing check) |
| F-2.4 | BTRFS Subvolume Escape | High | Access Control | escape, shell escape-root |
| F-2.5 | Stale Handle Persistence | Medium | Access Control | shell --handle, mount --handle |
| F-2.6 | Bind Mount Escape | High | Access Control | escape (fsid-based handle) |
| F-2.7 | NFS Daemon ACL Blindness | Critical | Access Control | shell --handle (port 2049, no MOUNT) |
| F-2.8 | Sibling Export Lateral Access | Critical | Access Control | escape + shell (cross-export cd) |
| F-2.9 | WebNFS Public File Handle | Critical | Access Control | analyze (zero-handle probe) |
| F-2.10 | SIGN_FH Root Handle Exemption | Medium | Access Control | shell --handle (constructed root) |
| F-2.11 | NFSv4 LOOKUPP Export Escape | Critical | Access Control | escape-root (v4 shell), cd .. |
| F-2.12 | NFSv4 LOOKUPP Cross-Export Lateral | High | Access Control | cd .. + cd <sibling>, exports |
| F-3.1 | Plaintext Wire Protocol | High | Network | analyze (no RPCSEC_GSS flag) |
| F-3.2 | Portmapper UDP Amplification | Medium | Network | scan (UDP DUMP amplification) |
| F-3.3 | IP Spoofing Against Host ACLs | High | Network | analyze (host-based ACL detection) |
| F-3.4 | STRIPTLS Downgrade | High | Network | analyze (AUTH_TLS probe) |
| F-3.5 | pNFS Metadata Server Detected | Info | Network | analyze (NFSv4.1 EXCHANGE_ID) |
| F-3.6 | Mixed Security Zones (Per-Path SECINFO) | Medium | Network | analyze (NFSv4 SECINFO) |
| F-3.7 | AUTH_DH Advertised | Medium | Network | analyze (flavor 3 detection) |
| F-3.8 | RPC-with-TLS Supported | Info | Network | analyze (AUTH_TLS NULL probe) |
| F-3.9 | AUTH_SHORT Session Credentials | Info | Network | analyze (flavor 2 detection) |
| F-4.1 | no_root_squash Exploitation | Critical | Privilege Escalation | analyze, mount --uid 0 --allow-write |
| F-4.2 | SUID/SGID Binary Creation | High | Privilege Escalation | shell suid-scan, mount + chmod u+s |
| F-4.3 | Device Node Creation | High | Privilege Escalation | shell mknod |
| F-4.4 | Symlink Escape | High | Privilege Escalation | analyze, shell symlink |
| F-4.5 | SELinux/MAC Label Bypass | Medium | Privilege Escalation | Not implemented (documented) |
| F-4.6 | Unrestricted chown | High | Privilege Escalation | analyze (PATHCONF check) |
| F-5.1 | Export List Enumeration | Medium | Info Disclosure | scan, analyze |
| F-5.2 | READDIRPLUS Handle Harvesting | High | Info Disclosure | shell ls, shell find, mount |
| F-5.3 | NIS Credential Extraction | High | Info Disclosure | scan, analyze (portmapper) |
| F-5.4 | RPC Service Enumeration | Low | Info Disclosure | scan (DUMP) |
| F-5.5 | NFSv4 Pseudo-FS Leakage | Low | Info Disclosure | scan (pseudo-root READDIR) |
| F-5.6 | Metadata on Access Denial | Low | Info Disclosure | analyze (post_op_attr harvest) |
| F-5.7 | Case-Insensitive Filesystem | Low | Info Disclosure | analyze (PATHCONF) |
| F-5.8 | AUTH_NONE Metadata Leak | Low | Info Disclosure | analyze (AUTH_NONE GETATTR) |
| F-5.9 | Execute-Only File Content Disclosure | Low | Info Disclosure | analyze (read-if-exec check) |
| F-5.10 | Solaris NFS Server Detected (time_delta) | Info | Info Disclosure | analyze (FSINFO) |
| F-5.11 | Filesystem Lacks Link/Symlink Support | Info | Info Disclosure | analyze (FSINFO) |
| F-5.12 | Near Inode Exhaustion | Medium | Info Disclosure | analyze (FSSTAT) |
| F-5.13 | NFSv4 Named Attributes Exposed | Info | Info Disclosure | analyze (OPENATTR) |
| F-5.14 | POSIX ACL Entries Beyond Mode Bits | Medium | Info Disclosure | analyze (NFS_ACL GETACL) |
| F-5.15 | rquotad UID Activity Disclosure | Medium | Info Disclosure | analyze (RQUOTA GETQUOTA) |
| F-5.16 | Silly-Rename Files Detected | Info | Info Disclosure | analyze (READDIRPLUS pattern) |
| F-5.17 | Write Verifier Change (Reboot Detected) | Medium | Info Disclosure | analyze (COMMIT comparison) |
| F-6.1 | NLM Lock Attacks | Medium | Denial of Service | Out of scope |
| F-6.2 | Grace Period DoS | Medium | Denial of Service | Out of scope |
| F-6.3 | SETCLIENTID State Destruction | Medium | Denial of Service | Out of scope |
| F-7.1 | Wildcard/Broad Subnet Exports | High | Configuration | scan, analyze |
| F-7.2 | Privileged Port Bypass | Medium | Configuration | analyze (probe removed -- see note) |
| F-7.3 | nohide/crossmnt Exposure | Medium | Configuration | analyze (crossmnt LOOKUP) |
| F-7.4 | Missing nosuid/nodev | High | Configuration | Not server-observable (client-side) |
| F-7.5 | all_squash with anonuid=0 | Critical | Configuration | analyze |
| F-7.6 | No Audit Logging | Medium | Configuration | Not remotely detectable (documented) |
| F-7.7 | FreeBSD-Style Truncated Subnet (OS Fingerprint) | Info | Configuration | analyze (MOUNT EXPORT ACL) |