Port 111-2049 (RPC/NFS)
Network file sharing(nfs)
Show Mountable NFS Shares
Mount a share
NFS misconfigurations
If you find some directory that is configured as no_root_squash/no_all_squash you may be able to privesc.
scan
rpcinfo 111
installation
rpcdump
by impacket
nmap
mount the nfs
vulnerabilidad
chequear β/etc/exportsβ si tiene no_root_squash o no_all_squash y tenemos permisos de escritura se puede crear un ejecutable con setuid ej:
nfshell
install https://github.com/NetDirect/nfsshell
use
Last updated