Skip to content

Security findings catalog

nfswolf documents 62 NFS security findings across 7 attack categories. Every finding traces to a specific RFC section (or kernel code path) that explains why the vulnerability exists at the protocol level. Together they cover recon, credential forging, export escape, privilege escalation, and lateral movement.

The catalog is the authoritative reference for what nfswolf detects and why each attack works. Findings are numbered F-{category}.{sequence} and carry a severity rating, RFC basis, preconditions, and a mapping to the nfswolf subcommand that exercises them.


How to read a finding

Each finding page follows a consistent structure:

Field What it tells you
Severity Critical / High / Medium / Low / Info -- based on direct exploitability and impact
RFC Basis The specific RFC section (or kernel code path) that creates the vulnerability
Precondition What must be true on the target for the finding to apply
Detection The protocol operation nfswolf uses to test for the condition
Why the RFC allows this The protocol-level rationale -- why this is a design property, not a bug
What nfswolf tests The concrete checks and subcommands that exercise the finding

Protocol root causes

The 62 findings trace back to four fundamental design properties of NFS:

Client-asserted credentials (AUTH_SYS)

The server trusts whatever UID, GID, and auxiliary groups the client claims. There is no verifier, no challenge-response, no proof of identity. This single design choice enables Category 1 (all 8 identity findings) and is a precondition for most of Category 4 (privilege escalation).

"There is no verifier, so credentials can easily be faked." -- RFC 1057 sec. 9.3

Bearer-token file handles

File handles are opaque blobs that grant access to whoever presents them. There is no binding to the client that received the handle, no expiry, and no revocation mechanism. Possession is authorization. This drives all 12 findings in Category 2.

"An attacker can circumvent the MOUNT server's access control by either stealing a file handle or guessing a file handle." -- RFC 2623 sec. 2.6

No transport security by default

NFS defers encryption and integrity to "underlying transport layers" that are never specified and rarely deployed. All wire traffic is plaintext unless the administrator explicitly configures Kerberos or RPC-with-TLS. This enables Category 3 (network attacks).

"NFS version 3 defers to the authentication provisions of the supporting RPC protocol." -- RFC 1813 sec. 8

Stateless architecture

The MOUNT protocol is an advisory directory service, not a security gate. The NFS daemon never calls back to MOUNT to verify that a client was authorized, and unmounting does not invalidate file handles. See the MOUNT protocol reference for the full architectural analysis.


Categories

Category ID Range Count Severity Breakdown Description
Identity Attacks F-1.1 -- F-1.8 8 1 Critical, 6 High, 1 Low AUTH_SYS trust model exploitation: UID/GID spoofing, root squash bypass, credential replay, version downgrade
Access Control Bypass F-2.1 -- F-2.12 12 6 Critical, 4 High, 2 Medium File handle bearer-token abuse: export escape, handle guessing, cross-export lateral movement, LOOKUPP traversal
Network Attacks F-3.1 -- F-3.9 9 1 Critical, 3 High, 3 Medium, 2 Info Wire-level attacks: plaintext interception, UDP amplification, STRIPTLS downgrade, AUTH_DH weakness
Privilege Escalation F-4.1 -- F-4.6 6 1 Critical, 4 High, 1 Medium Post-access escalation: no_root_squash, SUID/SGID creation, device nodes, symlink escape, chown abuse
Information Disclosure F-5.1 -- F-5.17 17 2 High, 6 Medium, 6 Low, 3 Info Data leakage: export enumeration, handle harvesting, NIS extraction, metadata on denial, pNFS downgrade
Denial of Service F-6.1 -- F-6.3 3 3 Medium Lock and state attacks (out of scope -- documented only)
Configuration Weaknesses F-7.1 -- F-7.7 7 1 Critical, 2 High, 3 Medium, 1 Info Server misconfigurations: wildcard exports, missing nosuid/nodev, squash errors, FreeBSD subnet fingerprint

Severity distribution

Severity Count Proportion
Critical 10 16%
High 21 34%
Medium 18 29%
Low 7 11%
Info 6 10%

Half of all findings are Critical or High

31 of the 62 findings carry Critical or High severity. The NFS protocol's design (client-asserted credentials, bearer-token file handles, no transport security by default) makes most of these inherent to the protocol rather than implementation bugs.


Attack chain

The 62 findings connect into a directed attack flow where each stage feeds the next with handles, credentials, or filesystem access. See the attack chain page for the full diagram, stage-by-stage walkthrough, defense mapping, and an example attack narrative against a default Linux NFS server.


Cross-reference views

Browse findings grouped by a different axis:

By Protocol Version

  • ONC RPC / Portmapper -- portmapper amplification, service enumeration, AUTH_SYS wire format
  • MOUNT -- export enumeration, handle acquisition, UDP theft
  • NFSv2 -- version downgrade, fixed 32-byte handles
  • NFSv3 -- READDIRPLUS harvesting, ACCESS advisory, post_op_attr leaks
  • NFSv4 -- LOOKUPP escape, pseudo-FS leakage, SECINFO probing, SETCLIENTID state destruction

By Attack Stage


Scope and limitations

Category 6 (Denial of Service) is documented but not implemented

The three DoS findings (F-6.1 NLM lock attacks, F-6.2 grace period blocking, F-6.3 SETCLIENTID state destruction) are cataloged for completeness. The NLM and NSM clients were removed in v0.2.0 and the NFSv4 DoS attacks were never implemented. No nfswolf subcommand exercises these findings.

Some findings are detection-only

Several findings describe attacks that nfswolf detects but does not actively exploit: F-3.3 (IP spoofing requires network positioning), F-4.5 (SELinux bypass requires labeled NFS), F-7.4 (nosuid/nodev are client-side mount options not visible to the server), F-7.6 (audit logging gaps are not remotely testable). These are flagged by analyze as risk indicators.


Complete finding index

Every finding in the catalog, sorted by ID. The Detected By column lists the nfswolf subcommand(s) that exercise or detect the finding.

ID Name Severity Category Detected By
F-1.1 UID/GID Spoofing Critical Identity uid-spray, shell uid/impersonate, mount --uid
F-1.2 Root Squash Bypass High Identity analyze (squash probe)
F-1.3 Auxiliary Group Injection High Identity analyze (shadow GID), shell gid, mount --aux-gids
F-1.4 Machine Name Spoofing Low Identity --hostname global flag
F-1.5 Credential Replay High Identity Passive -- precondition via F-3.1
F-1.6 NFSv2 Downgrade High Identity scan (version matrix), analyze
F-1.7 RPCSEC_GSS Flavor Downgrade High Identity analyze (mixed auth flavor)
F-1.8 AUTH_TOOWEAK Oracle High Identity analyze (SECINFO, MOUNT auth-flavors)
F-2.1 Export Escape via FS Root Handle Critical Access Control escape, analyze, shell escape-root
F-2.2 File Handle Guessing High Access Control analyze (entropy), brute-handle
F-2.3 Windows Handle Signing Disabled Critical Access Control analyze (signing check)
F-2.4 BTRFS Subvolume Escape High Access Control escape, shell escape-root
F-2.5 Stale Handle Persistence Medium Access Control shell --handle, mount --handle
F-2.6 Bind Mount Escape High Access Control escape (fsid-based handle)
F-2.7 NFS Daemon ACL Blindness Critical Access Control shell --handle (port 2049, no MOUNT)
F-2.8 Sibling Export Lateral Access Critical Access Control escape + shell (cross-export cd)
F-2.9 WebNFS Public File Handle Critical Access Control analyze (zero-handle probe)
F-2.10 SIGN_FH Root Handle Exemption Medium Access Control shell --handle (constructed root)
F-2.11 NFSv4 LOOKUPP Export Escape Critical Access Control escape-root (v4 shell), cd ..
F-2.12 NFSv4 LOOKUPP Cross-Export Lateral High Access Control cd .. + cd <sibling>, exports
F-3.1 Plaintext Wire Protocol High Network analyze (no RPCSEC_GSS flag)
F-3.2 Portmapper UDP Amplification Medium Network scan (UDP DUMP amplification)
F-3.3 IP Spoofing Against Host ACLs High Network analyze (host-based ACL detection)
F-3.4 STRIPTLS Downgrade High Network analyze (AUTH_TLS probe)
F-3.5 pNFS Metadata Server Detected Info Network analyze (NFSv4.1 EXCHANGE_ID)
F-3.6 Mixed Security Zones (Per-Path SECINFO) Medium Network analyze (NFSv4 SECINFO)
F-3.7 AUTH_DH Advertised Medium Network analyze (flavor 3 detection)
F-3.8 RPC-with-TLS Supported Info Network analyze (AUTH_TLS NULL probe)
F-3.9 AUTH_SHORT Session Credentials Info Network analyze (flavor 2 detection)
F-4.1 no_root_squash Exploitation Critical Privilege Escalation analyze, mount --uid 0 --allow-write
F-4.2 SUID/SGID Binary Creation High Privilege Escalation shell suid-scan, mount + chmod u+s
F-4.3 Device Node Creation High Privilege Escalation shell mknod
F-4.4 Symlink Escape High Privilege Escalation analyze, shell symlink
F-4.5 SELinux/MAC Label Bypass Medium Privilege Escalation Not implemented (documented)
F-4.6 Unrestricted chown High Privilege Escalation analyze (PATHCONF check)
F-5.1 Export List Enumeration Medium Info Disclosure scan, analyze
F-5.2 READDIRPLUS Handle Harvesting High Info Disclosure shell ls, shell find, mount
F-5.3 NIS Credential Extraction High Info Disclosure scan, analyze (portmapper)
F-5.4 RPC Service Enumeration Low Info Disclosure scan (DUMP)
F-5.5 NFSv4 Pseudo-FS Leakage Low Info Disclosure scan (pseudo-root READDIR)
F-5.6 Metadata on Access Denial Low Info Disclosure analyze (post_op_attr harvest)
F-5.7 Case-Insensitive Filesystem Low Info Disclosure analyze (PATHCONF)
F-5.8 AUTH_NONE Metadata Leak Low Info Disclosure analyze (AUTH_NONE GETATTR)
F-5.9 Execute-Only File Content Disclosure Low Info Disclosure analyze (read-if-exec check)
F-5.10 Solaris NFS Server Detected (time_delta) Info Info Disclosure analyze (FSINFO)
F-5.11 Filesystem Lacks Link/Symlink Support Info Info Disclosure analyze (FSINFO)
F-5.12 Near Inode Exhaustion Medium Info Disclosure analyze (FSSTAT)
F-5.13 NFSv4 Named Attributes Exposed Info Info Disclosure analyze (OPENATTR)
F-5.14 POSIX ACL Entries Beyond Mode Bits Medium Info Disclosure analyze (NFS_ACL GETACL)
F-5.15 rquotad UID Activity Disclosure Medium Info Disclosure analyze (RQUOTA GETQUOTA)
F-5.16 Silly-Rename Files Detected Info Info Disclosure analyze (READDIRPLUS pattern)
F-5.17 Write Verifier Change (Reboot Detected) Medium Info Disclosure analyze (COMMIT comparison)
F-6.1 NLM Lock Attacks Medium Denial of Service Out of scope
F-6.2 Grace Period DoS Medium Denial of Service Out of scope
F-6.3 SETCLIENTID State Destruction Medium Denial of Service Out of scope
F-7.1 Wildcard/Broad Subnet Exports High Configuration scan, analyze
F-7.2 Privileged Port Bypass Medium Configuration analyze (probe removed -- see note)
F-7.3 nohide/crossmnt Exposure Medium Configuration analyze (crossmnt LOOKUP)
F-7.4 Missing nosuid/nodev High Configuration Not server-observable (client-side)
F-7.5 all_squash with anonuid=0 Critical Configuration analyze
F-7.6 No Audit Logging Medium Configuration Not remotely detectable (documented)
F-7.7 FreeBSD-Style Truncated Subnet (OS Fingerprint) Info Configuration analyze (MOUNT EXPORT ACL)