Skip to content

F-7.7: FreeBSD-Style Truncated Subnet in Export ACL

Classification

  • Severity: Info
  • CVSS Vector: Network / Low Complexity / No Auth Required
  • Affected Versions: FreeBSD NFS servers
  • Prerequisite: MOUNT EXPORT returns ACL entries with truncated subnet notation

Summary

Export ACL entries with 2-3 octet dotted notation (e.g., 10.0 or 10.0.1) without an explicit netmask are characteristic of FreeBSD NFS servers. This truncated subnet notation is an OS fingerprint. The intended access scope may not match the implied CIDR: 10.0.1 could mean a /24 or could be an incomplete specification that admits more hosts than intended.

Technical detail

Truncated subnet notation

Standard NFS export ACLs use full IP addresses with optional CIDR masks:

/export  10.0.1.0/24(rw)
/data    10.0.1.50(rw)

FreeBSD NFS servers accept and display truncated notation:

/export  10.0.1(rw)       # 3-octet: implies 10.0.1.0/24?
/data    10.0(rw)          # 2-octet: implies 10.0.0.0/16?

This truncated form is not used by Linux knfsd, which requires full IP addresses or explicit CIDR notation. Its presence in the MOUNT EXPORT response is a reliable FreeBSD fingerprint.

Detection logic

The analyzer parses each hostname entry in the MOUNT EXPORT ACL. An entry qualifies as a truncated subnet when:

  1. It contains only digits and dots (no /, *, or ? characters)
  2. It has exactly 2 or 3 dot-separated octets (not 1 or 4)
  3. Each octet parses as a valid u8 (0-255)

Entries matching this pattern are flagged with the FreeBSD OS fingerprint signal.

Ambiguity risk

The truncated notation is ambiguous because the implied netmask depends on FreeBSD's interpretation rules, which differ from the CIDR convention. An administrator writing 10.0.1 may intend to restrict to a specific /24, but the actual kernel behavior may match a broader or narrower range depending on the FreeBSD version and NFS configuration.

Exploitation

Automated (nfswolf)

nfswolf analyze <target>
# F-7.7 fires when export ACL entries use 2-3 octet dotted notation.
# Evidence: truncated_subnets=["10.0.1"], FreeBSD OsGuess signal

Manual

# 1. Query the export list
showmount -e <target>

# 2. Look for ACL entries with 2-3 dot-separated octets (no netmask)
# Examples: "10.0", "10.0.1", "192.168"

# 3. If present, the server is likely FreeBSD
# 4. Verify the actual access scope by attempting mount from addresses
#    within and outside the implied subnet

Impact

  • OS fingerprinting: Confirms the NFS server is FreeBSD, enabling targeted exploit selection and handle format construction
  • Scope ambiguity: The truncated subnet may admit more hosts than the administrator intended, widening the attack surface
  • Reconnaissance value: FreeBSD NFS servers have different file handle formats, export behavior, and default configurations compared to Linux knfsd

Limitations

  • Only identifies FreeBSD; other non-Linux NFS implementations may use different ACL notation
  • The finding is informational and does not indicate a direct vulnerability
  • Cannot determine the actual netmask that FreeBSD applies to the truncated notation without testing from multiple source IPs

Detection

nfswolf: nfswolf analyze parses the MOUNT EXPORT ACL entries and flags those matching the truncated subnet pattern (2-3 octet dotted notation without a netmask).

Server-side: Review /etc/exports for truncated subnet entries. Replace with explicit CIDR notation to eliminate ambiguity.

Remediation

  1. Informational: Verify the intended subnet scope matches the implied CIDR by testing access from addresses inside and outside the expected range.
  2. Use explicit CIDR notation: Replace truncated subnets with full IP/mask specifications (e.g., 10.0.1.0/24 instead of 10.0.1).
  3. Reduce NFS exposure: If the FreeBSD server hosts sensitive exports, restrict access to specific IPs or migrate to Kerberos authentication.
Finding Relationship
F-5.10 Solaris time_delta fingerprint: another OS fingerprinting finding via protocol fields
F-7.1 Wildcard/broad subnet exports: truncated subnets may be unintentionally broad
F-3.3 IP spoofing against host-based ACLs: applies if the truncated subnet is the only access control