F-5.6: Metadata Disclosed on Access Denial¶
Classification¶
- Severity: Low
- CVSS Vector: Network / Low Complexity / Low Privileges Required
- Affected Versions: NFSv3
- RFC Reference: RFC 1813 §3.3 (post_op_attr on failure responses)
- Prerequisite: Valid file handle for a file the attacker cannot read
Summary¶
When an NFSv3 LOOKUP or READ fails with NFS3ERR_ACCES or NFS3ERR_PERM, the server returns post_op_attr in the failure response containing full file attributes: uid, gid, mode, size, and timestamps. RFC 1813 "strongly encourages" this behavior to improve client caching. The result is that access-denied responses leak metadata about files the caller cannot read, enabling targeted credential selection.
Technical detail¶
post_op_attr in Failure Responses¶
RFC 1813 §3.3 defines post_op_attr as an optional fattr3 returned alongside the NFS status code. The spec encourages servers to include it on failure:
"It is expected that servers will make their best efforts to return post-operation attributes."
Linux knfsd (fs/nfsd/nfs3xdr.c) always returns post_op_attr on access denial. The returned fattr3 includes:
| Field | Security Value |
|---|---|
uid |
File owner — first identity to try in the credential ladder |
gid |
File group — candidate for auxiliary GID injection (F-1.3) |
mode |
Permission bits — reveals whether owner, group, or other access is set |
size |
File size — confirms file is non-empty and worth exfiltrating |
fileid |
Inode number — useful for handle construction (F-2.1) |
atime/mtime |
Timestamps — indicates when the file was last accessed or modified |
Attack chain¶
- Attempt LOOKUP on a target path (e.g.,
etc/shadow) with any credential - Server returns NFS3ERR_ACCES with
post_op_attrcontaining uid=0, gid=42, mode=0640 - Attacker now knows: shadow is owned by root:shadow, group-readable
- Craft AUTH_SYS credential with gid=42 in auxiliary groups
- READ succeeds — file exfiltrated
Metadata from LOOKUP vs READ failures¶
Both LOOKUP and READ failure responses carry post_op_attr:
- LOOKUP failure: returns
dir_attributes(parent directory metadata) — leaks directory ownership - READ failure: returns
file_attributes— leaks the target file's metadata directly
Impact¶
- File ownership and permissions disclosed without read access
- Enables targeted credential selection (try the file's owner UID first)
- Reduces brute-force search space for UID/GID spraying
- Confirms file existence and non-zero size before investing in credential escalation
Detection (nfswolf)¶
The analyzer's probe_file_access() function harvests post_op_attr from NFS3ERR_ACCES and NFS3ERR_PERM denial responses. Leaked metadata is deduplicated by (operation, path) and reported as finding F-5.6 with the full attribute set as evidence.
Remediation¶
- Use sec=krb5p — Kerberos with privacy protection prevents credential spoofing entirely
- Server configuration — Some NFS servers can be configured to omit
post_op_attron failure, though this is non-standard and may break clients that rely on it for cache consistency - Restrict export scope — Minimize the number of sensitive files reachable from exported paths
- Enable root_squash — Prevents the disclosed owner UID=0 from being directly usable