Skip to content

F-5.4: Portmapper/RPC Service Enumeration

Classification

  • Severity: Low (Information Disclosure)
  • CVSS Vector: Network / Low Complexity / No Auth Required
  • Affected Versions: NFSv2, NFSv3 (NFSv4 does not require portmapper)
  • Service: rpcbind (port 111)
  • Prerequisite: Network access to port 111

Summary

NFSv3 depends on the ONC RPC portmapper service (rpcbind, port 111) to advertise the dynamic ports of supporting services (mountd, NLM, NSM, rquotad). This service freely provides detailed information about all registered RPC services, their versions, protocols, and ports — giving an attacker a complete service map without any authentication. Additionally, the mount daemon (mountd) reveals export lists, access controls, and currently connected clients.

Technical detail

RPC services in NFSv3 architecture

┌───────────────────────────────────────────────┐
│ Port 111: rpcbind (portmapper)                │
│   Reveals: All RPC services and their ports   │
├───────────────────────────────────────────────┤
│ Port dynamic: mountd                          │
│   Reveals: Exports, ACLs, connected clients   │
├───────────────────────────────────────────────┤
│ Port 2049: nfsd                               │
│   File operations (the actual data)           │
├───────────────────────────────────────────────┤
│ Port dynamic: NLM (lockd)                     │
│   File locking (cannot be Kerberized!)        │
├───────────────────────────────────────────────┤
│ Port dynamic: NSM (statd)                     │
│   Client/server status notifications          │
├───────────────────────────────────────────────┤
│ Port dynamic: rquotad                         │
│   Quota information                           │
└───────────────────────────────────────────────┘

Information available via rpcinfo

$ rpcinfo -p target
   program vers proto   port  service
    100000    4   tcp    111  portmapper
    100000    4   udp    111  portmapper
    100003    3   tcp   2049  nfs
    100003    4   tcp   2049  nfs
    100005    3   tcp    892  mountd
    100005    3   udp    892  mountd
    100021    4   tcp  43219  nlockmgr
    100021    4   udp  43219  nlockmgr
    100024    1   tcp  54123  status
    100024    1   udp  54123  status

Information available via mountd

$ showmount -e target
Export list for target:
/home/engineering   192.168.1.0/24
/srv/backups        *(rw)
/var/shared         workstation-1,workstation-2

$ showmount -a target
All mount points on target:
192.168.1.50:/home/engineering
192.168.1.51:/home/engineering
192.168.1.100:/srv/backups

What an attacker learns

Information Source Use
NFS versions supported rpcinfo Determine attack surface (v3 vs v4-only)
Service ports rpcinfo Bypass firewall rules targeting only 2049
Export paths mountd (showmount -e) Identify data targets
ACL entries mountd (showmount -e) IPs to spoof for access
Connected clients mountd (showmount -a) Active hosts to impersonate
OS fingerprint Version combinations Target OS-specific vulnerabilities
Lock manager port rpcinfo Potential lock-related attacks

OS fingerprinting via RPC

Pattern Likely OS
NFS v3 + v4.0 + v4.1 + v4.2 Linux (recent kernel)
NFS v3 + v4.1 only Windows Server
mountd reports subnets without mask FreeBSD
Only one TCP connection allowed HP-UX
"netapp" partner protocol in rpcinfo NetApp ONTAP

Exploitation

Full enumeration script

#!/usr/bin/env bash
set -euo pipefail

TARGET="${1:?Usage: $0 <target>}"

echo "=== RPC Services ==="
rpcinfo -p "$TARGET" 2>/dev/null || echo "Portmapper blocked"

echo -e "\n=== NFS Exports ==="
showmount -e "$TARGET" 2>/dev/null || echo "Mountd blocked or NFSv4-only"

echo -e "\n=== Connected Clients ==="
showmount -a "$TARGET" 2>/dev/null || echo "No clients or blocked"

echo -e "\n=== NFS Version Probe ==="
# Try NFSv3
rpcinfo -t "$TARGET" nfs 3 && echo "NFSv3: supported" || echo "NFSv3: not supported"
# Try NFSv4
rpcinfo -t "$TARGET" nfs 4 && echo "NFSv4: supported" || echo "NFSv4: not supported"

echo -e "\n=== Nmap Deep Scan ==="
nmap -sV -p 111,2049 --script=nfs-ls,nfs-showmount,nfs-statfs "$TARGET"

Using nfswolf

# Service discovery: portmapper DUMP, NFS version probes, export enumeration,
# connected clients, OS fingerprinting -- everything F-5.4 covers in one shot.
nfswolf scan target

# Security analysis: evaluates the scan results against all 62 findings,
# including F-5.4 (service enumeration exposure).
nfswolf analyze target

Impact

  • Attack surface mapping: Complete view of NFS infrastructure without authentication
  • Firewall bypass: Dynamic ports not always covered by firewall rules
  • Targeted attacks: Knowledge of exports, ACLs, and clients enables precise spoofing
  • Compliance exposure: Export paths may reveal sensitive directory names
  • Client enumeration: Identify targets for lateral movement

Detection

  • Run nfswolf scan against your own infrastructure to see exactly what an attacker sees via portmapper and mountd; nfswolf analyze flags the exposure as F-5.4
  • Monitor for rpcinfo and showmount queries from unexpected sources
  • Rate-limit portmapper queries
  • Log mount protocol access attempts

Remediation

  1. Firewall port 111 — block from untrusted networks:

    iptables -A INPUT -p tcp --dport 111 -s !192.168.1.0/24 -j DROP
    

  2. Use NFSv4 exclusively — no portmapper, no mountd, single port 2049

  3. Fix mountd/NLM ports — configure static ports for firewall rules:

    # /etc/nfs.conf
    [mountd]
    port=892
    [lockd]
    port=32803
    [statd]
    port=32769
    

  4. Disable unused services: If only NFSv4 is needed, disable mountd/rpcbind

  5. Network segmentation: Isolate NFS infrastructure from general network access