June 6, 2016 By Larry Loeb 2 min read

Network file system (NFS) is a computer protocol that describes how to connect and access files via a network connection. It is used to store and share data, but early versions of the protocol do not provide or request user-based authentication.

Since the fourth version, NFS has been using Kerberos to improve authentication. Unfortunately, this version has not been widely implemented, leaving some holes that are catching the attention of experts — and cybercriminals.

NFS Servers Leak Data Like a Sieve

Security research firm Fortinet recently took a look at NFS, and its conclusions are rather worrisome. It found that “most servers on the Internet that have been linked to data leakage have been shown to use NFSv3.”

Fortinet used data from the website Shodan and found that 10 percent of NFS servers in the world are open for everyone to access with no need for a password. Some of these servers contained confidential data such as email backups, server logs and web source code.

This isn’t limited to just read-only access, either; Fortinet found that write access is often available as well.

Thousands of the exposed servers were located in the U.S. (18,843 servers), China (11,608), France (10,744), Germany (7,188) and Russia (5,269), the firm reported.

Mitigating the Risk

Fixing this problem can be a bit tricky. Fortinet strongly recommended upgrading NFS to version 4, but this isn’t possible for every organization.

If one of the earlier versions of NFS must be used, then there should be a specific white list of allowed IP addresses that can access the data. While the security firm noted that “this process can be tedious and time consuming,” it is a critical part of establishing “data security protocols that will prevent sensitive or confidential data from being accessible from the internet.”

Enabling the NFS application control signature on a system’s main gateway can also block all unexpected NFS connections from the outside to prevent data leakage.

Correct NFS configuration can be a pain for the system administrator, but saving a server from exploitation by cybercriminals will be worth it.

More from

How will the Merck settlement affect the insurance industry?

3 min read - A major shift in how cyber insurance works started with an attack on the pharmaceutical giant Merck. Or did it start somewhere else?In June 2017, the NotPetya incident hit some 40,000 Merck computers, destroying data and forcing a months-long recovery process. The attack affected thousands of multinational companies, including Mondelēz and Maersk. In total, the malware caused roughly $10 billion in damage.NotPetya malware exploited two Windows vulnerabilities: EternalBlue, a digital skeleton key leaked from the NSA, and Mimikatz, an exploit…

3 Strategies to overcome data security challenges in 2024

3 min read - There are over 17 billion internet-connected devices in the world — and experts expect that number will surge to almost 30 billion by 2030.This rapidly growing digital ecosystem makes it increasingly challenging to protect people’s privacy. Attackers only need to be right once to seize databases of personally identifiable information (PII), including payment card information, addresses, phone numbers and Social Security numbers.In addition to the ever-present cybersecurity threats, data security teams must consider the growing list of data compliance laws…

ICS CERT predictions for 2024: What you need to know

4 min read - As we work through the first quarter of 2024, various sectors are continuously adapting to increasingly complex cybersecurity threats. Sectors like healthcare, finance, energy and transportation are all regularly widening their digital infrastructure, resulting in larger attack surfaces and greater risk exposure.Kaspersky just released their ICS CERT Predictions for this year, outlining the key cybersecurity challenges industrial enterprises will face in the year ahead. The forecasts emphasize the persistent nature of ransomware threats, the increasing prevalence of cosmopolitical hacktivism, insights…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today