Skip to content

F-5.1: Export List Enumeration

Classification

  • Severity: Medium
  • CVSS Vector: Network / Low Complexity / No Auth Required
  • Affected Versions: NFSv2, NFSv3 (via mountd)
  • RFC Reference: RFC 1094 Appendix A §5.6, RFC 1813 §5.2.5
  • Prerequisite: Mountd reachable (dynamic port via portmapper, or directly)

Summary

The MOUNT protocol's EXPORT procedure returns the complete list of exported directories, their access control lists (allowed hosts/subnets), and auth flavors — all without any authentication. This is the equivalent of showmount -e and gives an attacker a complete map of what's shared and who can access it.

Technical detail

MNTPROC_EXPORT

Per RFC 1094 Appendix A:

"Returns a variable number of export list entries. Each entry contains a filesystem name and a list of groups."

The response includes: - Export path: Full server-side directory path (e.g., /home/engineering) - Allowed hosts: IP addresses, hostnames, subnets, wildcards - Auth flavors (NFSv3): AUTH_SYS, krb5, krb5i, krb5p per export

What an attacker learns

$ showmount -e target
Export list for target:
/home/engineering   192.168.1.0/24
/srv/backups        *
/data/sensitive     admin-host.internal

From this: - /srv/backups is accessible from anywhere (wildcard) → immediate target - /home/engineering is accessible from the /24 → spoof an IP in that range - /data/sensitive is restricted to one host → target that host for pivot - Directory names hint at content types

Connected client enumeration

MOUNT also supports listing currently connected clients:

$ showmount -a target
192.168.1.50:/home/engineering
192.168.1.100:/srv/backups

This reveals active NFS client IPs — targets for IP spoofing or lateral movement.

Impact

  • Complete export topology revealed without authentication
  • ACL details enable targeted IP spoofing
  • Directory paths reveal organizational structure and data classifications
  • Connected client list identifies targets for lateral movement

Detection (nfswolf)

nfswolf's scanner: 1. Call MNTPROC_EXPORT to enumerate all exports 2. Parse ACLs for wildcards, broad subnets, and stale hosts 3. Call MNTPROC_DUMP to enumerate connected clients

Remediation

  1. Use NFSv4 only — no MOUNT protocol, no showmount
  2. Firewall mountd port to restrict who can enumerate exports
  3. Restrict port 111 — prevents discovering mountd's dynamic port
  4. Fix mountd port for consistent firewall rules: [mountd] port=892 in /etc/nfs.conf