Skip to content

F-5.10: Solaris NFS Server Detected via time_delta Fingerprint

Classification

  • Severity: Info
  • CVSS Vector: Network / Low Complexity / No Auth Required
  • Affected Versions: Solaris NFS servers (all versions)
  • RFC Reference: RFC 1813 Section 3.3.20 (FSINFO)
  • Prerequisite: NFSv3 access to the export

Summary

The FSINFO time_delta field reveals the server's timestamp granularity. A value of {0, 1000} (microsecond granularity) is characteristic of Solaris NFS servers, while Linux knfsd uses {0, 1} (nanosecond granularity). This passive OS fingerprint adjusts the attacker's escape strategy because Solaris NFS file handle formats differ from Linux, and Solaris-specific handle construction is required for filesystem escape.

Technical detail

FSINFO time_delta field

RFC 1813 Section 3.3.20 defines time_delta as:

nfstime3 time_delta;
/* The server's time granularity, in seconds and nanoseconds.
   Indicates the best accuracy the server can provide for
   file timestamps. */

The value is an nfstime3 struct with two fields: seconds (u32) and nseconds (u32). The nseconds field encodes the sub-second granularity:

nseconds value Granularity Typical server
1 Nanosecond Linux knfsd
1000 Microsecond Solaris NFS
1000000 Millisecond Some embedded NFS implementations

Why microsecond granularity identifies Solaris

Linux knfsd reports nanosecond granularity (time_delta = {0, 1}) because the kernel VFS uses struct timespec64 with nanosecond precision. Solaris uses microsecond-resolution timestamps internally, and its NFS server reports this as time_delta = {0, 1000}. This is a stable fingerprint across Solaris versions because it reflects the OS kernel's timestamp implementation, not a configurable NFS parameter.

Impact on escape strategy

Solaris NFS file handles differ from Linux in structure:

  • Solaris uses a different fsid_type encoding (device major/minor vs. UUID)
  • Inode number width and generation counter formats vary
  • The fh_auth_type field layout differs from Linux knfsd's FSID_NUM / FSID_UUID formats

When FileHandleAnalyzer constructs escape candidates, it must use Solaris-specific handle formats. Detecting the OS early via time_delta avoids wasting escape attempts with Linux-formatted handles against a Solaris server.

Exploitation

Automated (nfswolf)

nfswolf analyze <target>:/export
# F-5.10 fires when FSINFO reports time_delta = {0, 1000}.
# Evidence: time_delta={0, 1000}

Manual

# Issue an FSINFO RPC against the export root handle.
# Examine the time_delta field in the response.
# {0, 1000} = Solaris; {0, 1} = Linux

Impact

  • OS fingerprinting: Confirms the NFS server runs Solaris, narrowing the target OS without port scanning or banner grabbing
  • Escape strategy selection: Directs the file handle analyzer to use Solaris-specific handle formats, improving escape efficiency
  • Reconnaissance value: Solaris NFS servers are often legacy systems with older security configurations, weaker patching, and different default export settings

Limitations

  • Only distinguishes Solaris from Linux; other NFS implementations (NetApp, FreeBSD, Windows Services for NFS) may use different time_delta values not covered by this check
  • The fingerprint is passive and informational; it does not indicate a vulnerability by itself
  • Requires NFSv3 access to the export (FSINFO is an NFSv3 procedure)

Detection

nfswolf: nfswolf analyze calls FSINFO on the export root and compares time_delta against known OS fingerprints. The finding fires when time_delta = {0, 1000} (microsecond granularity).

Server-side: Not applicable. FSINFO is a normal protocol operation that cannot be suppressed without breaking NFS functionality.

Remediation

  1. Informational: No direct remediation required. This is an OS fingerprint, not a vulnerability.
  2. Reduce NFS exposure: If the Solaris server hosts sensitive exports, restrict access via IP-based ACLs or migrate to Kerberos authentication.
  3. Upgrade path: Consider migrating legacy Solaris NFS servers to a supported OS with current NFS security features (NFSv4.1+, RPCSEC_GSS, RPC-with-TLS).
Finding Relationship
F-2.1 Export escape: OS fingerprint determines which handle construction strategy to use
F-5.7 Case-insensitive filesystem detection: another FSINFO-based fingerprint
F-5.11 Filesystem link/symlink support: another FSINFO properties-based fingerprint