F-5.1: Export List Enumeration¶
Classification¶
- Severity: Medium
- CVSS Vector: Network / Low Complexity / No Auth Required
- Affected Versions: NFSv2, NFSv3 (via mountd)
- RFC Reference: RFC 1094 Appendix A §5.6, RFC 1813 §5.2.5
- Prerequisite: Mountd reachable (dynamic port via portmapper, or directly)
Summary¶
The MOUNT protocol's EXPORT procedure returns the complete list of exported directories, their access control lists (allowed hosts/subnets), and auth flavors — all without any authentication. This is the equivalent of showmount -e and gives an attacker a complete map of what's shared and who can access it.
Technical detail¶
MNTPROC_EXPORT¶
Per RFC 1094 Appendix A:
"Returns a variable number of export list entries. Each entry contains a filesystem name and a list of groups."
The response includes:
- Export path: Full server-side directory path (e.g., /home/engineering)
- Allowed hosts: IP addresses, hostnames, subnets, wildcards
- Auth flavors (NFSv3): AUTH_SYS, krb5, krb5i, krb5p per export
What an attacker learns¶
$ showmount -e target
Export list for target:
/home/engineering 192.168.1.0/24
/srv/backups *
/data/sensitive admin-host.internal
From this:
- /srv/backups is accessible from anywhere (wildcard) → immediate target
- /home/engineering is accessible from the /24 → spoof an IP in that range
- /data/sensitive is restricted to one host → target that host for pivot
- Directory names hint at content types
Connected client enumeration¶
MOUNT also supports listing currently connected clients:
This reveals active NFS client IPs — targets for IP spoofing or lateral movement.
Impact¶
- Complete export topology revealed without authentication
- ACL details enable targeted IP spoofing
- Directory paths reveal organizational structure and data classifications
- Connected client list identifies targets for lateral movement
Detection (nfswolf)¶
nfswolf's scanner: 1. Call MNTPROC_EXPORT to enumerate all exports 2. Parse ACLs for wildcards, broad subnets, and stale hosts 3. Call MNTPROC_DUMP to enumerate connected clients
Remediation¶
- Use NFSv4 only — no MOUNT protocol, no
showmount - Firewall mountd port to restrict who can enumerate exports
- Restrict port 111 — prevents discovering mountd's dynamic port
- Fix mountd port for consistent firewall rules:
[mountd] port=892in/etc/nfs.conf