Skip to content

F-3.2: Portmapper UDP Amplification (DDoS Reflection)

Classification

  • Severity: Medium (for the NFS server owner) / High (for the DDoS target)
  • CVSS Vector: Network / Low Complexity / No Auth Required
  • Affected Versions: Any system exposing UDP port 111 (rpcbind/portmapper)
  • CVE: CVE-2013-5211 (related NTP amplification class)
  • Prerequisite: UDP port 111 reachable from the internet

Summary

The portmapper service (rpcbind, port 111/UDP) responds to small DUMP queries with large replies listing all registered RPC programs. Because UDP headers can be spoofed, an attacker sends forged requests with the victim's IP as source. The portmapper responds to the victim, amplifying traffic 7-28x. This was first observed in large-scale DDoS campaigns in 2015.

Technical detail

Amplification factor

Request Response Factor
68 bytes (DUMP v2) 486–1,930 bytes 7.1x – 28.4x
Average observed in attacks 1,348 bytes 19.8x

Attack flow

Attacker → Portmapper (UDP/111):
  Source: VICTIM_IP (spoofed)
  Payload: RPC CALL, Program=100000 (Portmap), Version=2, Procedure=4 (DUMP)
  Size: 68 bytes

Portmapper → Victim:
  Full list of registered RPC programs (NFS, mountd, NLM, NSM, etc.)
  Size: 486–1,930 bytes

Wire format (from Metasploit portmap_amp module)

00 00 00 00          # Message Type: CALL
00 00 00 02          # RPC Version: 2
00 01 86 a0          # Program: Portmap (100000)
00 00 00 02          # Program Version: 2
00 00 00 04          # Procedure: DUMP (4)
00 00 00 00          # Credentials: AUTH_NULL
00 00 00 00          # Credentials Length: 0
00 00 00 00          # Verifier: AUTH_NULL
00 00 00 00          # Verifier Length: 0

Three amplification variants

Metasploit tests three RPC calls: 1. DUMP v2 (rpcinfo -T udp -p) — lists program/version/port/protocol 2. DUMP v3 (rpcinfo -T udp -s) — lists program/version/netid/address/owner 3. GETSTAT v4 (rpcinfo -T udp -m) — statistics per program

Each returns a different amplification factor depending on how many RPC programs are registered.

Impact

  • For the NFS server owner: Their portmapper is weaponized as a DDoS reflector
  • For the victim: Receives amplified UDP flood from many reflectors simultaneously
  • For the pentester: Indicates the NFS server has UDP portmapper exposed — likely misconfigured

Relevance to NFS pentesting

An exposed UDP portmapper indicates: 1. The server is reachable and running RPC services 2. NFS is likely available (the DUMP response reveals all services) 3. The server may have weak network-level access controls 4. This is a finding worth reporting even if NFS itself is not directly exploitable

Detection (nfswolf)

The scanner should: 1. Test if UDP port 111 responds to DUMP requests 2. Measure the response amplification factor 3. Flag servers with >10x amplification as potential DDoS reflectors 4. Report this as an informational finding

Remediation

  1. Block UDP/111 from the internet — portmapper should never be internet-facing
  2. Disable UDP transport: rpcbind -w or configure /etc/sysconfig/rpcbind with no-UDP
  3. Firewall rules: Restrict port 111 to trusted subnets only
  4. Remove rpcbind entirely if NFS is not needed: apt remove rpcbind
  5. Rate-limit UDP responses on network devices