<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Nfs on Opscode</title><link>https://opscode.io/tags/nfs/</link><description>Recent content in Nfs on Opscode</description><generator>Hugo -- 0.164.0</generator><language>en-us</language><lastBuildDate>Tue, 16 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://opscode.io/tags/nfs/index.xml" rel="self" type="application/rss+xml"/><item><title>NFSv3: Open Says Me, No Sesame Required</title><link>https://opscode.io/posts/nfsv3-authsys-identity-spoofing/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://opscode.io/posts/nfsv3-authsys-identity-spoofing/</guid><description>NFSv3 with AUTH_SYS trusts whatever UID and GID the client claims. Where it serves home directories, an unprivileged user can become any other user: read their files, write to public SSH keys and shell rc files, and create SUID binaries owned by other users for user impersonation and potentially root escalation. In environments where home directories are centrally exported and mounted across many hosts, one foothold can become lateral movement across large portions of the infrastructure.</description></item></channel></rss>