Re: NIS with local root

From: Systems Group (Isaac) (isaacsys@ee.ucr.edu)
Date: 01/30/03

  • Next message: Zow: "Re: NIS with local root"
    Date: Thu, 30 Jan 2003 08:39:25 -0800 (PST)
    From: "Systems Group (Isaac)" <isaacsys@ee.ucr.edu>
    To: Kevin Jackson <kevin.jackson@genaware.com>
    
    

    Not entirely true. root at @netgroup machines can change its uid and have
    access to the files.

    On Thu, 30 Jan 2003, Kevin Jackson wrote:

    > Not entirely true.
    > Its the NFS export options - i.e. root_squash that needs to be used.
    >
    > /export/home @netgroup(rw,root_squash)
    > /export/home adminpc(rw,no_root_squash)
    >
    > only adminpc's root can modify files.
    >
    > Kev
    >
    >
    > > If server mounts all the home dir, not automounts user dir upon logon
    > > then root can do everything.
    > >
    >
    >

    -- 
      Isaac Saldana
      Systems Administrator
      College of Engineering
      Department of Electrical Engineering
      University of California, Riverside
    


    Relevant Pages

    • Re: Rename root to avoid hacking?
      ... Those are remote attacks, ... root user by name, but I am absolutely certain that no system-local ones ... By using the UID instead of the username, ... ...reach exactly the same SMTP daemon welcome banner. ...
      (comp.os.linux.security)
    • Re[2]: accounting with ipfw (gid, uid riles)
      ... MS> The uid associated with a socket is the uid of the process which created ... it's still accounted to root. ... far, is adding alias interface, bind squid to this interface and count ...
      (FreeBSD-Security)
    • Re: Root is root no more
      ... > they required root access. ... > cchsu etc, cchsu being the first root uid account. ... > pwconv'd the file, added the passwd for these accounts, changed the $HOME ...
      (comp.unix.solaris)
    • Re: Question about SELinux and root privs
      ... "root" is just a normal user now, ... Yep, UID 0 of course, the username doesn't matter. ... > Well one of the points of SELinux seems to be there isn't any ... > account, and/or add/modify any privileges at will ... ...
      (comp.os.linux.security)
    • Re: error
      ... > and when i tried to log in i could not get into my account ... the system is only interested in your UID. ... the corresponding username it displays the UID. ... Use 'chown' as root to give your user the files you want back. ...
      (alt.os.linux.suse)