With AUTH_SYS (the default for NFSv3), the server performs no real authentication: it trusts the UID and GID numbers the client puts on each request. A client with root (to create users or set IDs) simply becomes any user by matching their UID, then reads and writes that user's files on the export with their permissions.
mount -t nfs <target>:/export /mnt/nfs
ls -ln /mnt/nfs # see which UIDs own the files
# Create/switch to a local user with the target UID, then access as them
useradd -u 1005 victim && su victim -c 'cat /mnt/nfs/home/victim/.ssh/id_rsa'
Exploitation notes#
- This needs local root on the client (to set arbitrary UIDs), but no credential on the NFS server at all.
- Target UIDs that own interesting files: a developer's home directory, a service account's keys, root (which is where
no_root_squashmatters). - NFSv4 with Kerberos (
sec=krb5) defeats this, so check the export's security flavor; see NFSv4 and Kerberos.