Skip to content

F-5.2: READDIRPLUS File Handle Harvesting

Classification

  • Severity: High
  • CVSS Vector: Network / Low Complexity / Requires Directory Handle
  • Affected Versions: NFSv3
  • RFC Reference: RFC 1813 §3.3.17
  • Prerequisite: Any valid directory handle

Summary

The NFSv3 READDIRPLUS procedure returns file handles for ALL entries in a directory in a single call. Since file handles are bearer tokens (possession = access), a single READDIRPLUS response hands the attacker ready-made access tokens for every file in the directory — without requiring per-file LOOKUP calls and without per-file access checks at enumeration time.

Technical detail

READDIRPLUS response

Per RFC 1813 §3.3.17:

"READDIRPLUS differs from READDIR in that it also returns the name, the file attributes, and file handle to each entry."

A single call returns, for EVERY directory entry: - name: Filename - fileid: Inode number - attributes: Full FATTR3 (uid, gid, mode, size, timestamps) - file handle: Complete opaque file handle for direct access

Security implications

  1. Mass handle harvesting: One READDIRPLUS on / returns handles for etc/, home/, var/, etc.
  2. No per-file access check: The server checks access to the DIRECTORY only, not to individual files
  3. Attribute leakage: File ownership (uid/gid), sizes, and permissions revealed for all entries
  4. Recursive enumeration: Each returned directory handle enables another READDIRPLUS

Handle harvesting walk

READDIRPLUS(export_root_handle)
  → etc/  (handle_etc,  uid=0, mode=0755)
  → home/ (handle_home, uid=0, mode=0755)
  → var/  (handle_var,  uid=0, mode=0755)

READDIRPLUS(handle_home)
  → alice/ (handle_alice, uid=1001, mode=0700)
  → bob/   (handle_bob,   uid=1002, mode=0750)

# Now have handles for alice's and bob's directories
# Can use them with UID spoofing (F-1.1) for direct access

Comparison with READDIR

READDIR (the non-plus version) returns only names and fileids — no handles. An attacker must issue individual LOOKUP calls to get handles, which could be rate-limited or access-checked. READDIRPLUS eliminates this bottleneck entirely.

Impact

  • Single call harvests bearer tokens for an entire directory
  • Enables mass file access when combined with UID spoofing
  • Reveals file metadata (ownership, permissions) for target selection
  • No per-file access checks during enumeration
  • Recursive enumeration maps the complete filesystem in seconds

Detection (nfswolf)

The scanner should: 1. Use READDIRPLUS to efficiently enumerate export contents 2. Report the number of handles harvested per call 3. Use harvested metadata (uid/gid) to identify high-value targets

Remediation

  1. Use NFSv4 with RPCSEC_GSS — per-operation authentication limits usefulness of stolen handles
  2. Network segmentation — limit who can reach NFS ports
  3. Accept the limitation — READDIRPLUS is core functionality, cannot be disabled without breaking NFSv3
  4. Use all_squash — even with handles, all operations map to nobody