F-5.10: Solaris NFS Server Detected via time_delta Fingerprint¶
Classification¶
- Severity: Info
- CVSS Vector: Network / Low Complexity / No Auth Required
- Affected Versions: Solaris NFS servers (all versions)
- RFC Reference: RFC 1813 Section 3.3.20 (FSINFO)
- Prerequisite: NFSv3 access to the export
Summary¶
The FSINFO time_delta field reveals the server's timestamp granularity. A value of {0, 1000} (microsecond granularity) is characteristic of Solaris NFS servers, while Linux knfsd uses {0, 1} (nanosecond granularity). This passive OS fingerprint adjusts the attacker's escape strategy because Solaris NFS file handle formats differ from Linux, and Solaris-specific handle construction is required for filesystem escape.
Technical detail¶
FSINFO time_delta field¶
RFC 1813 Section 3.3.20 defines time_delta as:
nfstime3 time_delta;
/* The server's time granularity, in seconds and nanoseconds.
Indicates the best accuracy the server can provide for
file timestamps. */
The value is an nfstime3 struct with two fields: seconds (u32) and nseconds (u32). The nseconds field encodes the sub-second granularity:
| nseconds value | Granularity | Typical server |
|---|---|---|
| 1 | Nanosecond | Linux knfsd |
| 1000 | Microsecond | Solaris NFS |
| 1000000 | Millisecond | Some embedded NFS implementations |
Why microsecond granularity identifies Solaris¶
Linux knfsd reports nanosecond granularity (time_delta = {0, 1}) because the kernel VFS uses struct timespec64 with nanosecond precision. Solaris uses microsecond-resolution timestamps internally, and its NFS server reports this as time_delta = {0, 1000}. This is a stable fingerprint across Solaris versions because it reflects the OS kernel's timestamp implementation, not a configurable NFS parameter.
Impact on escape strategy¶
Solaris NFS file handles differ from Linux in structure:
- Solaris uses a different
fsid_typeencoding (device major/minor vs. UUID) - Inode number width and generation counter formats vary
- The
fh_auth_typefield layout differs from Linux knfsd'sFSID_NUM/FSID_UUIDformats
When FileHandleAnalyzer constructs escape candidates, it must use Solaris-specific handle formats. Detecting the OS early via time_delta avoids wasting escape attempts with Linux-formatted handles against a Solaris server.
Exploitation¶
Automated (nfswolf)¶
nfswolf analyze <target>:/export
# F-5.10 fires when FSINFO reports time_delta = {0, 1000}.
# Evidence: time_delta={0, 1000}
Manual¶
# Issue an FSINFO RPC against the export root handle.
# Examine the time_delta field in the response.
# {0, 1000} = Solaris; {0, 1} = Linux
Impact¶
- OS fingerprinting: Confirms the NFS server runs Solaris, narrowing the target OS without port scanning or banner grabbing
- Escape strategy selection: Directs the file handle analyzer to use Solaris-specific handle formats, improving escape efficiency
- Reconnaissance value: Solaris NFS servers are often legacy systems with older security configurations, weaker patching, and different default export settings
Limitations¶
- Only distinguishes Solaris from Linux; other NFS implementations (NetApp, FreeBSD, Windows Services for NFS) may use different
time_deltavalues not covered by this check - The fingerprint is passive and informational; it does not indicate a vulnerability by itself
- Requires NFSv3 access to the export (FSINFO is an NFSv3 procedure)
Detection¶
nfswolf: nfswolf analyze calls FSINFO on the export root and compares time_delta against known OS fingerprints. The finding fires when time_delta = {0, 1000} (microsecond granularity).
Server-side: Not applicable. FSINFO is a normal protocol operation that cannot be suppressed without breaking NFS functionality.
Remediation¶
- Informational: No direct remediation required. This is an OS fingerprint, not a vulnerability.
- Reduce NFS exposure: If the Solaris server hosts sensitive exports, restrict access via IP-based ACLs or migrate to Kerberos authentication.
- Upgrade path: Consider migrating legacy Solaris NFS servers to a supported OS with current NFS security features (NFSv4.1+, RPCSEC_GSS, RPC-with-TLS).
Related findings¶
| Finding | Relationship |
|---|---|
| F-2.1 | Export escape: OS fingerprint determines which handle construction strategy to use |
| F-5.7 | Case-insensitive filesystem detection: another FSINFO-based fingerprint |
| F-5.11 | Filesystem link/symlink support: another FSINFO properties-based fingerprint |