Skip to content

F-5.6: Metadata Disclosed on Access Denial

Classification

  • Severity: Low
  • CVSS Vector: Network / Low Complexity / Low Privileges Required
  • Affected Versions: NFSv3
  • RFC Reference: RFC 1813 §3.3 (post_op_attr on failure responses)
  • Prerequisite: Valid file handle for a file the attacker cannot read

Summary

When an NFSv3 LOOKUP or READ fails with NFS3ERR_ACCES or NFS3ERR_PERM, the server returns post_op_attr in the failure response containing full file attributes: uid, gid, mode, size, and timestamps. RFC 1813 "strongly encourages" this behavior to improve client caching. The result is that access-denied responses leak metadata about files the caller cannot read, enabling targeted credential selection.

Technical detail

post_op_attr in Failure Responses

RFC 1813 §3.3 defines post_op_attr as an optional fattr3 returned alongside the NFS status code. The spec encourages servers to include it on failure:

"It is expected that servers will make their best efforts to return post-operation attributes."

Linux knfsd (fs/nfsd/nfs3xdr.c) always returns post_op_attr on access denial. The returned fattr3 includes:

Field Security Value
uid File owner — first identity to try in the credential ladder
gid File group — candidate for auxiliary GID injection (F-1.3)
mode Permission bits — reveals whether owner, group, or other access is set
size File size — confirms file is non-empty and worth exfiltrating
fileid Inode number — useful for handle construction (F-2.1)
atime/mtime Timestamps — indicates when the file was last accessed or modified

Attack chain

  1. Attempt LOOKUP on a target path (e.g., etc/shadow) with any credential
  2. Server returns NFS3ERR_ACCES with post_op_attr containing uid=0, gid=42, mode=0640
  3. Attacker now knows: shadow is owned by root:shadow, group-readable
  4. Craft AUTH_SYS credential with gid=42 in auxiliary groups
  5. READ succeeds — file exfiltrated

Metadata from LOOKUP vs READ failures

Both LOOKUP and READ failure responses carry post_op_attr:

  • LOOKUP failure: returns dir_attributes (parent directory metadata) — leaks directory ownership
  • READ failure: returns file_attributes — leaks the target file's metadata directly

Impact

  • File ownership and permissions disclosed without read access
  • Enables targeted credential selection (try the file's owner UID first)
  • Reduces brute-force search space for UID/GID spraying
  • Confirms file existence and non-zero size before investing in credential escalation

Detection (nfswolf)

The analyzer's probe_file_access() function harvests post_op_attr from NFS3ERR_ACCES and NFS3ERR_PERM denial responses. Leaked metadata is deduplicated by (operation, path) and reported as finding F-5.6 with the full attribute set as evidence.

Remediation

  1. Use sec=krb5p — Kerberos with privacy protection prevents credential spoofing entirely
  2. Server configuration — Some NFS servers can be configured to omit post_op_attr on failure, though this is non-standard and may break clients that rely on it for cache consistency
  3. Restrict export scope — Minimize the number of sensitive files reachable from exported paths
  4. Enable root_squash — Prevents the disclosed owner UID=0 from being directly usable