F-5.4: Portmapper/RPC Service Enumeration¶
Classification¶
- Severity: Low (Information Disclosure)
- CVSS Vector: Network / Low Complexity / No Auth Required
- Affected Versions: NFSv2, NFSv3 (NFSv4 does not require portmapper)
- Service: rpcbind (port 111)
- Prerequisite: Network access to port 111
Summary¶
NFSv3 depends on the ONC RPC portmapper service (rpcbind, port 111) to advertise the dynamic ports of supporting services (mountd, NLM, NSM, rquotad). This service freely provides detailed information about all registered RPC services, their versions, protocols, and ports — giving an attacker a complete service map without any authentication. Additionally, the mount daemon (mountd) reveals export lists, access controls, and currently connected clients.
Technical detail¶
RPC services in NFSv3 architecture¶
┌───────────────────────────────────────────────┐
│ Port 111: rpcbind (portmapper) │
│ Reveals: All RPC services and their ports │
├───────────────────────────────────────────────┤
│ Port dynamic: mountd │
│ Reveals: Exports, ACLs, connected clients │
├───────────────────────────────────────────────┤
│ Port 2049: nfsd │
│ File operations (the actual data) │
├───────────────────────────────────────────────┤
│ Port dynamic: NLM (lockd) │
│ File locking (cannot be Kerberized!) │
├───────────────────────────────────────────────┤
│ Port dynamic: NSM (statd) │
│ Client/server status notifications │
├───────────────────────────────────────────────┤
│ Port dynamic: rquotad │
│ Quota information │
└───────────────────────────────────────────────┘
Information available via rpcinfo¶
$ rpcinfo -p target
program vers proto port service
100000 4 tcp 111 portmapper
100000 4 udp 111 portmapper
100003 3 tcp 2049 nfs
100003 4 tcp 2049 nfs
100005 3 tcp 892 mountd
100005 3 udp 892 mountd
100021 4 tcp 43219 nlockmgr
100021 4 udp 43219 nlockmgr
100024 1 tcp 54123 status
100024 1 udp 54123 status
Information available via mountd¶
$ showmount -e target
Export list for target:
/home/engineering 192.168.1.0/24
/srv/backups *(rw)
/var/shared workstation-1,workstation-2
$ showmount -a target
All mount points on target:
192.168.1.50:/home/engineering
192.168.1.51:/home/engineering
192.168.1.100:/srv/backups
What an attacker learns¶
| Information | Source | Use |
|---|---|---|
| NFS versions supported | rpcinfo | Determine attack surface (v3 vs v4-only) |
| Service ports | rpcinfo | Bypass firewall rules targeting only 2049 |
| Export paths | mountd (showmount -e) | Identify data targets |
| ACL entries | mountd (showmount -e) | IPs to spoof for access |
| Connected clients | mountd (showmount -a) | Active hosts to impersonate |
| OS fingerprint | Version combinations | Target OS-specific vulnerabilities |
| Lock manager port | rpcinfo | Potential lock-related attacks |
OS fingerprinting via RPC¶
| Pattern | Likely OS |
|---|---|
| NFS v3 + v4.0 + v4.1 + v4.2 | Linux (recent kernel) |
| NFS v3 + v4.1 only | Windows Server |
| mountd reports subnets without mask | FreeBSD |
| Only one TCP connection allowed | HP-UX |
| "netapp" partner protocol in rpcinfo | NetApp ONTAP |
Exploitation¶
Full enumeration script¶
#!/usr/bin/env bash
set -euo pipefail
TARGET="${1:?Usage: $0 <target>}"
echo "=== RPC Services ==="
rpcinfo -p "$TARGET" 2>/dev/null || echo "Portmapper blocked"
echo -e "\n=== NFS Exports ==="
showmount -e "$TARGET" 2>/dev/null || echo "Mountd blocked or NFSv4-only"
echo -e "\n=== Connected Clients ==="
showmount -a "$TARGET" 2>/dev/null || echo "No clients or blocked"
echo -e "\n=== NFS Version Probe ==="
# Try NFSv3
rpcinfo -t "$TARGET" nfs 3 && echo "NFSv3: supported" || echo "NFSv3: not supported"
# Try NFSv4
rpcinfo -t "$TARGET" nfs 4 && echo "NFSv4: supported" || echo "NFSv4: not supported"
echo -e "\n=== Nmap Deep Scan ==="
nmap -sV -p 111,2049 --script=nfs-ls,nfs-showmount,nfs-statfs "$TARGET"
Using nfswolf¶
# Service discovery: portmapper DUMP, NFS version probes, export enumeration,
# connected clients, OS fingerprinting -- everything F-5.4 covers in one shot.
nfswolf scan target
# Security analysis: evaluates the scan results against all 62 findings,
# including F-5.4 (service enumeration exposure).
nfswolf analyze target
Impact¶
- Attack surface mapping: Complete view of NFS infrastructure without authentication
- Firewall bypass: Dynamic ports not always covered by firewall rules
- Targeted attacks: Knowledge of exports, ACLs, and clients enables precise spoofing
- Compliance exposure: Export paths may reveal sensitive directory names
- Client enumeration: Identify targets for lateral movement
Detection¶
- Run
nfswolf scanagainst your own infrastructure to see exactly what an attacker sees via portmapper and mountd;nfswolf analyzeflags the exposure as F-5.4 - Monitor for
rpcinfoandshowmountqueries from unexpected sources - Rate-limit portmapper queries
- Log mount protocol access attempts
Remediation¶
-
Firewall port 111 — block from untrusted networks:
-
Use NFSv4 exclusively — no portmapper, no mountd, single port 2049
-
Fix mountd/NLM ports — configure static ports for firewall rules:
-
Disable unused services: If only NFSv4 is needed, disable mountd/rpcbind
-
Network segmentation: Isolate NFS infrastructure from general network access