Re: NFS Security Question

From: Matthew Collins (pingu@zymurgy.org)
Date: 08/15/01


Date: Wed, 15 Aug 2001 12:10:05 +0100
From: Matthew Collins <pingu@zymurgy.org>
To: Rich Teer <richard.teer@rite-group.com>
Subject: Re: NFS Security Question
Message-ID: <20010815121005.A4301@keg.zymurgy.org>

On Tue, Aug 14, 2001 at 07:15:34PM -0700, Rich Teer wrote:
> On Tue, 14 Aug 2001, Ryan Russell wrote:
>
> > Anyway... All I have to do is invite Bob to log into my box, and his drive
> > mounts automatically, and I CD to it, because I'm root, yes?
>
> By default, root's UID gets mapped to nobody for NFS mounts, so if
> Bob's directory doesn't permit access to others, you still won't be
> allowed to cd to it, even though you're root.
>

While true this is pure semantics; you need authenticated NIS/NFS usage
as Darren describes. If I can get root I can just vipw, add bob locally
and su to bob to cd into his directory if its available to this machine.

Matt


Quantcast