Re: NFS Security Question

From: Rich Teer (richard.teer@rite-group.com)
Date: 08/15/01


Date: Tue, 14 Aug 2001 19:15:34 -0700 (PDT)
From: Rich Teer <richard.teer@rite-group.com>
To: Ryan Russell <ryan@securityfocus.com>
Subject: Re: NFS Security Question
Message-ID: <Pine.GSO.4.33.0108141913400.13926-100000@mars.rite-group.com>

On Tue, 14 Aug 2001, Ryan Russell wrote:

> Anyway... All I have to do is invite Bob to log into my box, and his drive
> mounts automatically, and I CD to it, because I'm root, yes?

By default, root's UID gets mapped to nobody for NFS mounts, so if
Bob's directory doesn't permit access to others, you still won't be
allowed to cd to it, even though you're root.

--
Rich Teer

President, Rite Online Inc.

Voice: +1 (250) 979-1638 URL: http://www.rite-online.net



Relevant Pages

  • Re: NFS Security Question
    ... Subject: NFS Security Question ... All I have to do is invite Bob to log into my box, ... help if you are root (in the traditional maning of having full-control ... restricted root accss (say, shared compute servers that access an NFS ...
    (Focus-SUN)
  • Re: NFS Security Question
    ... Subject: NFS Security Question ... > On Tue, 14 Aug 2001, Ryan Russell wrote: ... All I have to do is invite Bob to log into my box, ... > allowed to cd to it, even though you're root. ...
    (Focus-SUN)
  • NFS Security Question
    ... Subject: NFS Security Question ... I have been looking for information on securing NFS with respect to root su ... in as "bob" and has all the permissions associated with the "bob" ...
    (Focus-SUN)
  • Re: NFS Security Question
    ... Subject: NFS Security Question ... On Tue, 14 Aug 2001, Darren Moffat wrote: ... > The only solution in this case is to use NFS with RPC security stronger ... If I'm sitting in front of my desktop Sparc, I can always get root. ...
    (Focus-SUN)
  • Re: NFS Security Question
    ... Subject: NFS Security Question ... You might want to try giving sudo ... > access and restrict permissions from there. ... > root is root and root can do anything. ...
    (Focus-SUN)