F-1.5: AUTH_SYS Credential Replay from Wire Traffic¶
Classification¶
- Severity: High
- CVSS Vector: Network / Low Complexity / Requires MITM Position
- Affected Versions: NFSv2, NFSv3 (AUTH_SYS, no encryption)
- Prerequisite: Ability to capture NFS traffic (MITM, span port, compromised switch)
Summary¶
Since AUTH_SYS credentials are plaintext and contain no sequence numbers, nonces, or cryptographic binding, any captured credential can be replayed in new RPC requests with a fresh XID. An attacker who can sniff NFS traffic can extract valid (UID, GID, machinename) tuples and file handles, then construct arbitrary NFS operations without ever needing to mount the export.
Technical detail¶
What gets captured¶
From a single sniffed NFS RPC call, the attacker obtains: 1. AUTH_SYS credential: stamp, machinename, uid, gid, auxiliary gids 2. File handle(s): From LOOKUP replies, READDIRPLUS replies, or call arguments 3. Server responses: Revealing file attributes, directory structure, data
Why replay works¶
AUTH_SYS has no replay protection:
- No nonce or sequence number — the same credential is valid indefinitely
- No timestamp verification — the stamp field is ignored by most servers
- No session binding — credentials are not tied to a TCP connection
- No HMAC or signature — credentials cannot be integrity-checked
Replay attack flow¶
1. Attacker captures:
NFS CALL [XID=0x1234] AUTH_SYS(uid=1000, gid=1000, "client-a")
→ LOOKUP dir_fh "secret.txt"
NFS REPLY [XID=0x1234]
→ OK, file_fh=0x01000700...
2. Attacker constructs:
NFS CALL [XID=0x9999] AUTH_SYS(uid=1000, gid=1000, "client-a")
→ READ file_fh=0x01000700... offset=0 count=65536
Server processes it — the credential and file handle are valid.
Combined with file handle theft¶
Captured file handles don't expire (NFSv3 handles are persistent). An attacker can: - Capture handles over days/weeks of passive sniffing - Build a complete map of the filesystem's handle space - Execute operations long after the original session ended
AUTH_SHORT verifier reuse¶
Some servers respond to AUTH_SYS with an AUTH_SHORT verifier — an opaque token that can be used in place of the full credential. This token can also be captured and replayed until the server flushes it.
Client → Server: AUTH_SYS(uid=1000, gid=1000)
Server → Client: AUTH_SHORT verifier = 0xDEADBEEF...
# Attacker can now use the shorthand:
Attacker → Server: AUTH_SHORT(0xDEADBEEF...) + NFS operation
Impact¶
- Passive access: Read files without ever connecting to the NFS server directly (just sniff + replay)
- Long-lived access: File handles and credentials remain valid indefinitely
- Undetectable: Replayed requests are indistinguishable from legitimate ones
- Full operation set: Any NFS operation can be replayed (read, write, delete, mkdir)
Detection¶
- Network-level: Detect NFS RPC calls from IPs that never performed a MOUNT
- Anomaly detection: Flag XID reuse or credential patterns from unexpected source IPs
- Track file handle usage: Handles used from different IPs than the mounting client
Remediation¶
- Encrypt NFS traffic:
sec=krb5pprevents sniffing entirely - Use
sec=krb5iat minimum — integrity protection detects modified/replayed RPCs - Network encryption: IPsec, WireGuard, or VLAN isolation
- NFSv4.1+ session binding: Binds operations to a session with sequence numbers