Netatalk (afpd) is the AFP server shipped by many Linux distributions and NAS vendors. It has a recurring history of memory-corruption flaws in its parsing of AFP requests, several of them pre-authentication, that let an attacker run code on the server as the service account (often root on appliances). Because NAS devices expose AFP to the network and update slowly, these are high-value and long-lived.
Netatalk attack surface:
- Pre-authentication parsing of AFP request structures in afpd
- Spotlight and DSI request handling
- Reachable on port 548 wherever Netatalk serves AFP
Exploitation notes#
- Several Netatalk flaws are unauthenticated, so a reachable
afpdis exploitable without any credential. - NAS appliances run Netatalk as root and patch slowly, so these escapes commonly yield root on storage devices.
- Fingerprint the Netatalk version through the server info response before selecting a technique.