NFS 2049
1. rpcinfo
for NFS Enumeration:
rpcinfo
for NFS Enumeration:List RPC services running on a target (port 111, commonly used by NFS):
2. showmount
for NFS Share Discovery:
showmount
for NFS Share Discovery:Display all mountable shares on the target NFS server:
Display the connected hosts to the NFS server:
List directories shared via NFS:
List all mount points on the NFS server:
3. Metasploit NFS Auxiliary Scanner:
Use Metasploit NFS Mount scanner:
4. Potential Exploitation:
If you identify a share that is misconfigured (e.g., the NFS export is mounted with rw,no_root_squash
), you might be able to upload and execute a malicious shell.
Check for NFS shares with
rw,no_root_squash
: If the exported share allows read/write access (rw
) and disables root squashing (no_root_squash
), you can escalate privileges to the root user on the target system.Create a malicious shell and change ownership:
Last updated