Skip to content

F-1.4: Machine Name Spoofing and Log Poisoning

Classification

  • Severity: Low
  • CVSS Vector: Network / Low Complexity / No Auth Required
  • Affected Versions: NFSv2, NFSv3 (AUTH_SYS)
  • Prerequisite: Network access to NFS server

Summary

The AUTH_SYS credential includes a machinename field (up to 255 bytes) that the NFS server logs for audit purposes (e.g., in rmtab, mountd logs). This field is entirely client-controlled and never verified. An attacker can set it to any value — a trusted hostname, a misleading string, or even injection payloads for log processing pipelines.

Technical detail

The machinename field

struct authsys_parms {
    unsigned int stamp;
    string machinename<255>;     ← attacker-controlled, server never verifies
    unsigned int uid;
    unsigned int gid;
    unsigned int gids<16>;
};

The server records machinename in: - /var/lib/nfs/rmtab (mount tracking) - mountd syslog entries - NFS server access logs (where enabled) - showmount -a output

Attack 1: Forensic misdirection

Set machinename to a trusted host's name to blame legitimate infrastructure:

machinename = "backup-server.internal"

Server logs show connections from "backup-server.internal" — investigators chase the wrong host.

Attack 2: Log injection

If log processing pipelines don't sanitize the machinename, inject structured data:

machinename = "host\n2026-04-12 admin logged out normally"

Or inject syslog format strings, JSON payloads, or CSV field separators depending on the log consumer.

Attack 3: Fingerprint concealment

nfs_analyze uses machinename = b"test" (a 4-byte fixed string). Any non-standard machinename in server logs is a detection opportunity. Setting it to a plausible hostname (workstation-04.corp) avoids triggering alerts.

Impact

  • Forensic evasion: Misdirect incident response to wrong hosts
  • Log pollution: Corrupt log parsing pipelines
  • SIEM confusion: Generate false attribution in security monitoring
  • Audit trail invalidation: rmtab and mount logs become unreliable

Detection

  • Compare showmount -a hostnames against DNS/DHCP inventory
  • Alert on machinenames that don't resolve or resolve to different IPs
  • Monitor for special characters in machinename (newlines, control chars)
  • Cross-reference NFS server logs with network flow data (source IP vs claimed name)

Remediation

  1. Use Kerberos — principal names are cryptographically verified
  2. Don't trust machinename for attribution — it's an unauthenticated string
  3. Log source IP alongside machinename for cross-reference
  4. Sanitize machinename in log processing pipelines