Re: NIS with local root

From: Kevin Jackson (kevin.jackson@genaware.com)
Date: 01/30/03

  • Next message: Systems Group (Isaac): "Re: NIS with local root"
    From: Kevin Jackson <kevin.jackson@genaware.com>
    To: focus-linux@securityfocus.com
    Date: Thu, 30 Jan 2003 16:47:56 +0000
    
    

    Yes - root can still su to the user and then modify the files using the
    half-baked idea I gave (which is good practice anyway!) --

    but surely in such a situation where NIS and NFS is employed -- you won't be
    giving out root passwords to normal untrusted users anyway?!
    I know sometimes it can't be avoided in some situations -- if that's the case
    then you may want to look at alternatives - NIS+ was mentioned.

    ... and I'll shut up now (and hoping people will stop replying personally
    saying:

    yes, but he can su - user and modify the files that way

    !!!)

    ;-)

    Kev

    On Thursday 30 January 2003 9:31 am, Kevin Jackson tapped frantically at the
    keyboard:
    > Not entirely true.
    > Its the NFS export options - i.e. root_squash that needs to be used.

    -- 
    Kevin Jackson
    Systems Administrator                        Locate, Enquire, Empower
    GenaWare Limited                              www.genaware.com
    Adamson House
    Towers Business Park
    Wilmslow Road
    Manchester M20 2YY
    United Kingdom
    Email: kevin.jackson@genaware.com
    Tel: +44.161.955.4376
    Fax: +44.161.955.4305
    ------------------------------------------------------------------------
    PRIVILEGED - PRIVATE AND CONFIDENTIAL
    This email and any files transmitted with it are intended solely for the
    use of the addressee(s) and may contain information which is
    confidential or privileged. If you receive this email and you are not
    the addressee (or responsible for delivery of the email to the
    addressee), please disregard the contents of the email, delete the email
    and notify the author immediately.
    Before opening or using any attachments, please scan them for viruses
    and defects. We do not accept any liability for loss or damage, which
    may arise from your receipt of this e-mail. Our liability is limited to
    re-supplying any affected attachments.
    


    Relevant Pages

    • Re: NIS with local root
      ... only adminpc's root can modify files. ... Our liability is limited to ... re-supplying any affected attachments. ...
      (Focus-Linux)
    • Re: getaffinity/setaffinity and cpu sets.
      ... The notion would be that you can create a new numbered cpuset with cpuset. ... You can modify or inspect its affinity with get/setaffinity above and the CPU_WHICH_SET argument. ... This set would not be modifiable by user processes or by processes in a jail. ... Another option would be to expel the offending thread from the set that is in violation and reparent it to the real system root along with a syslog message or similar. ...
      (freebsd-arch)
    • Re: Why Ext2/3 needs immutable attribute?
      ... What I am curious is if an intruder has root access, ... > have many ways to turn off the immutable protection and modify files. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: File permissions problem
      ... Files not in /home usually belong to root (the administration account), ... From Nautilus ... modify or delete any files there, so use with caution if you do not know ...
      (Ubuntu)
    • Subject: Re: Execute script every time a specified user logs in (FreeB SD 6.1)
      ... source another file (containing the commands which X can't modify). ... This is inelegant in that it has a general and widely used file look for special cases, ... Also the script must be run as root. ...
      (freebsd-questions)