Brief description: Exporting an NFS volume makes it writeable
Full description: Unless access is restricted to specific systems, an NFS file system is available to any host. Unless it is marked read-only, it is writeable by any user except root .
Components: NFS
Systems: Any system running a version of NFS
Effect(s) of exploiting: Attacker can alter or create files on the file system.
Detecting the hole:
showmount -e host
with host being the name of the
target host.
Fixing the hole:
Other information:
NFS access control
PA Classification(s):
RISOS Classification(s):
DCS Classification(s):
Attack: Mount the file system and create a file.
Advisories:
Related Vulnerabilities:
Reporting: in ( )