NFSv4 changed the model: it uses a single port (2049, no separate portmapper), string-based user and group names mapped by idmapd, and a per-export security flavor. With sec=sys (AUTH_SYS) it is still the trust-the-client model, vulnerable to UID spoofing. With sec=krb5 it requires Kerberos tickets and authenticates the user; krb5i adds integrity and krb5p encryption.
# NFSv4 mounts on 2049 directly; check the server's accepted security flavors
mount -t nfs4 -o sec=sys <target>:/ /mnt/nfs # if sec=sys is allowed, UID spoofing applies
showmount -e <target> 2>/dev/null # v3 compatibility may still list exports
Exploitation notes#
- If an export lists multiple flavors (
sysandkrb5), a client can often choosesec=sysand bypass Kerberos entirely; this downgrade is the key attack. - Under real Kerberos (
krb5), access needs a valid ticket, so the attack shifts to obtaining one (keytabs, ticket theft) rather than UID tricks. idmapdname mapping means owners appear asuser@domain; mismatched domains can cause files to map tonobody, a hint the export expects a specific realm.