NFS exports server directories to clients that mount them. Its classic weakness is the trust model: with AUTH_SYS, the server trusts the UID and GID the client sends, so a client that controls its own UIDs can impersonate any user, and the no_root_squash export option lets a client's root be root on the server's files. Enumeration through the portmapper reveals what is exported and to whom.
Subtopics#
- Enumeration: discovering exports and their access.
- no_root_squash abuse: writing files as root on the server.
- UID and GID spoofing: impersonating users under AUTH_SYS.
- NFSv4 and Kerberos: the NFSv4 model and sec=krb5.