Re: NIS with local root

From: Wallwork, Nathan (nwallwo@pnm.com)
Date: 01/31/03

  • Next message: Kevin Jackson: "Re: NIS with local root"
    Date: Fri, 31 Jan 2003 14:02:57 -0700 (MST)
    From: "Wallwork, Nathan" <nwallwo@pnm.com>
    To: Kevin Jackson <kevin.jackson@genaware.com>
    
    

    On Fri, 31 Jan 2003, Kevin Jackson wrote:
    > If you mean from "if they have physical access to the box and are
    > determined, they'll get root anyway" you mean exploit some unpatched
    > service on the system -- then you may aswell forget about and type of NFS
    > "squash" option altogether! ...as we are in a different territory now.
    > See other securityfocus.com mailing lists on that one! ;-)

    No, if someone has physical access to a PC they can turn it off,
    open the case, short the jumper to clear the BIOS, boot from a
    floopy or CD and get root. Securing the services and network won't
    help if you allow untrusted users to have unsupervised access [which
    is eventually going to happen at some point in any classroom or lab]
    to the hardware.

    With that in mind, it makes sense to build a solution in which a
    person with root access to a machine on the network still cannot
    modify another users files.

    NFS doesn't get you that.



    Relevant Pages

    • Re: to allow root logins or not?
      ... Physical Access means, me being in very ... I recently did a clean install with root logins disabled. ... is passwordless BIOS setup, ... GAPING HOLE in theory on machine security as an attack on yourself. ...
      (Debian-User)
    • Re: security for a home system
      ... useless since physical access to the box means that they can get root ... You can make that tricky with a Master lock using the lock loop on the case ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: Linux for Kids
      ... If he has physical access to the machine, he has root, although ordinary ... The situation with drivers hasn't improved much. ... It's better to build a whole new system, if you have the resources to do ...
      (comp.os.linux)
    • Re: Single User Mode and Root
      ... M> Ian Northeast wrote: ... M>>>> so that single user mode doesn't have root privledges. ... M> need root shell and they're known. ... You cant protect a machine from people with physical access. ...
      (comp.os.linux.misc)
    • Re: security for a home system
      ... but someone on a recent thread argued that securing the bios is ... useless since physical access to the box means that they can get root ... Why bother to rsync instead of just nfs mounting the backup repository? ...
      (Debian-User)