F-1.4: Machine Name Spoofing and Log Poisoning¶
Classification¶
- Severity: Low
- CVSS Vector: Network / Low Complexity / No Auth Required
- Affected Versions: NFSv2, NFSv3 (AUTH_SYS)
- Prerequisite: Network access to NFS server
Summary¶
The AUTH_SYS credential includes a machinename field (up to 255 bytes) that the NFS server logs for audit purposes (e.g., in rmtab, mountd logs). This field is entirely client-controlled and never verified. An attacker can set it to any value — a trusted hostname, a misleading string, or even injection payloads for log processing pipelines.
Technical detail¶
The machinename field¶
struct authsys_parms {
unsigned int stamp;
string machinename<255>; ← attacker-controlled, server never verifies
unsigned int uid;
unsigned int gid;
unsigned int gids<16>;
};
The server records machinename in:
- /var/lib/nfs/rmtab (mount tracking)
- mountd syslog entries
- NFS server access logs (where enabled)
- showmount -a output
Attack 1: Forensic misdirection¶
Set machinename to a trusted host's name to blame legitimate infrastructure:
Server logs show connections from "backup-server.internal" — investigators chase the wrong host.
Attack 2: Log injection¶
If log processing pipelines don't sanitize the machinename, inject structured data:
Or inject syslog format strings, JSON payloads, or CSV field separators depending on the log consumer.
Attack 3: Fingerprint concealment¶
nfs_analyze uses machinename = b"test" (a 4-byte fixed string). Any non-standard machinename in server logs is a detection opportunity. Setting it to a plausible hostname (workstation-04.corp) avoids triggering alerts.
Impact¶
- Forensic evasion: Misdirect incident response to wrong hosts
- Log pollution: Corrupt log parsing pipelines
- SIEM confusion: Generate false attribution in security monitoring
- Audit trail invalidation:
rmtaband mount logs become unreliable
Detection¶
- Compare
showmount -ahostnames against DNS/DHCP inventory - Alert on machinenames that don't resolve or resolve to different IPs
- Monitor for special characters in machinename (newlines, control chars)
- Cross-reference NFS server logs with network flow data (source IP vs claimed name)
Remediation¶
- Use Kerberos — principal names are cryptographically verified
- Don't trust machinename for attribution — it's an unauthenticated string
- Log source IP alongside machinename for cross-reference
- Sanitize machinename in log processing pipelines