Re: NFS Security Question

From: Casper Dik (Casper.Dik@Sun.COM)
Date: 08/15/01


Message-Id: <200108151721.TAA03377@romulus.Holland.Sun.COM>
To: Ryan Russell <ryan@securityfocus.com>
Subject: Re: NFS Security Question 
Date: Wed, 15 Aug 2001 19:21:56 +0200
From: Casper Dik <Casper.Dik@Sun.COM>


>Anyway... All I have to do is invite Bob to log into my box, and his drive
>mounts automatically, and I CD to it, because I'm root, yes?

No filesystem is going to prevent the latter. Nor will Kerberos
help if you are root (in the traditional maning of having full-control
over the system) when Bob logs into your system.

When someone gives your kernel some access tokens, root will have accss.

Secure RPC, Kerberos, and others only work well if you either have
restricted root accss (say, shared compute servers that access an NFS
resource) or restrict poeople's logins to their desktops.

Casper



Relevant Pages

  • Re: NFS Security Question
    ... Subject: NFS Security Question ... > On Tue, 14 Aug 2001, Ryan Russell wrote: ... All I have to do is invite Bob to log into my box, ... > allowed to cd to it, even though you're root. ...
    (Focus-SUN)
  • Re: NFS Security Question
    ... Subject: NFS Security Question ... On Tue, 14 Aug 2001, Ryan Russell wrote: ... All I have to do is invite Bob to log into my box, ... even though you're root. ...
    (Focus-SUN)
  • NFS Security Question
    ... Subject: NFS Security Question ... I have been looking for information on securing NFS with respect to root su ... in as "bob" and has all the permissions associated with the "bob" ...
    (Focus-SUN)
  • Re: Toxemia - the root cause of disease
    ... you can not treat the root cause. ... The most amazing thing, mix a metal with an acid, and the Acid is ... is taken out of their bones to neutralise excess acids. ... So I don't need a chemistry class to tell me that bob. ...
    (misc.health.alternative)
  • way to duplicate logs?
    ... Now from where I am looking, I see time in the logs go backwards. ... Dec 7 19:01:03 additional su: bob to root on /dev/ttyp0 ... The date on the box should not have changed during that reboot, ...
    (FreeBSD-Security)