F-5.2: READDIRPLUS File Handle Harvesting¶
Classification¶
- Severity: High
- CVSS Vector: Network / Low Complexity / Requires Directory Handle
- Affected Versions: NFSv3
- RFC Reference: RFC 1813 §3.3.17
- Prerequisite: Any valid directory handle
Summary¶
The NFSv3 READDIRPLUS procedure returns file handles for ALL entries in a directory in a single call. Since file handles are bearer tokens (possession = access), a single READDIRPLUS response hands the attacker ready-made access tokens for every file in the directory — without requiring per-file LOOKUP calls and without per-file access checks at enumeration time.
Technical detail¶
READDIRPLUS response¶
Per RFC 1813 §3.3.17:
"READDIRPLUS differs from READDIR in that it also returns the name, the file attributes, and file handle to each entry."
A single call returns, for EVERY directory entry: - name: Filename - fileid: Inode number - attributes: Full FATTR3 (uid, gid, mode, size, timestamps) - file handle: Complete opaque file handle for direct access
Security implications¶
- Mass handle harvesting: One READDIRPLUS on
/returns handles foretc/,home/,var/, etc. - No per-file access check: The server checks access to the DIRECTORY only, not to individual files
- Attribute leakage: File ownership (uid/gid), sizes, and permissions revealed for all entries
- Recursive enumeration: Each returned directory handle enables another READDIRPLUS
Handle harvesting walk¶
READDIRPLUS(export_root_handle)
→ etc/ (handle_etc, uid=0, mode=0755)
→ home/ (handle_home, uid=0, mode=0755)
→ var/ (handle_var, uid=0, mode=0755)
READDIRPLUS(handle_home)
→ alice/ (handle_alice, uid=1001, mode=0700)
→ bob/ (handle_bob, uid=1002, mode=0750)
# Now have handles for alice's and bob's directories
# Can use them with UID spoofing (F-1.1) for direct access
Comparison with READDIR¶
READDIR (the non-plus version) returns only names and fileids — no handles. An attacker must issue individual LOOKUP calls to get handles, which could be rate-limited or access-checked. READDIRPLUS eliminates this bottleneck entirely.
Impact¶
- Single call harvests bearer tokens for an entire directory
- Enables mass file access when combined with UID spoofing
- Reveals file metadata (ownership, permissions) for target selection
- No per-file access checks during enumeration
- Recursive enumeration maps the complete filesystem in seconds
Detection (nfswolf)¶
The scanner should: 1. Use READDIRPLUS to efficiently enumerate export contents 2. Report the number of handles harvested per call 3. Use harvested metadata (uid/gid) to identify high-value targets
Remediation¶
- Use NFSv4 with RPCSEC_GSS — per-operation authentication limits usefulness of stolen handles
- Network segmentation — limit who can reach NFS ports
- Accept the limitation — READDIRPLUS is core functionality, cannot be disabled without breaking NFSv3
- Use
all_squash— even with handles, all operations map to nobody