Re: NFS Over Private Network

From: John Kinsella (jlk_at_thrashyour.com)
Date: 03/26/04

  • Next message: dreamwvr_at_dreamwvr.com: "Re: NFS Over Private Network"
    Date: Thu, 25 Mar 2004 21:38:40 -0800
    To: Randy Williams <randyw@techsource.com>
    
    

    On Thu, Mar 25, 2004 at 11:31:20AM -0500, Randy Williams wrote:
    > I may be off the mark here, but if your NFS configuration isolates the NFS
    > shares to a significant degree (hosts, users, etc) then only the NFS daemon
    > would be the weak spot (within the scope of NFS of course, if the host NFS
    > server is compromised via a security weakness, then this goes out the
    > window).

    I think that's what they were talking about, the protocol being the
    weakness. Firewall the hell out of on the front, either on the box or
    next hop. Remember people, security is a multi layer thing - gotta
    look patches/hardening/applications/network.

    > Or, thinking out loud, would the "mount" command betray you, as it would
    > publish all directories/mount points being published on the target machine.
    >
    > Is there any way to prevent mount, iostat, netstat or any other I/O
    > measurement from giving the mount away?

    Think: "chmod go-rwx" (usually works, not always)

    But a little more general - you're thinking local to the box. If
    somebody gets on your box, they got alot better odds at getting root
    than somebody attempting a remote compromise (usually).

    John


  • Next message: dreamwvr_at_dreamwvr.com: "Re: NFS Over Private Network"

    Relevant Pages

    • NFS server not responding / alive again
      ... The mail cluster consists of ten i386 hosts running a variety of FreeBSD ... The NFS server is a Network Appliance ... The network interfaces on the clients and servers all operate at Fast Ethernet ...
      (freebsd-net)
    • SUMMARY: NFS vers4 uid problem
      ... am trying to share the filesystem /export/home from hostS and ... mount it on hostO. ... I am having a problem with NFS version 4. ...
      (SunManagers)
    • Avoiding NFS clients Hang when NFS server dies
      ... of disks served on other tru64 hosts and Linux. ... hosts hang with a df. ... mount -t nfs HOSTA:/dirAAA /HOSTA/dirAAA ...
      (Tru64-UNIX-Managers)
    • Re: Accessing NFS from OS X. Was: NFS how to
      ... >>with Unix underneath these days NFS should work better on Mac OS X ... While to a user Mac OS X appears to be Unix, to an Administrator, there are ... # nidump hosts> hosts.txt ...
      (comp.os.vms)
    • RE: NFS Over Private Network
      ... I may be off the mark here, but if your NFS configuration isolates the NFS ... Is there any way to prevent mount, iostat, netstat or any other I/O ... then a private network between two machines will serve ... > connectivity via ping etc between the hosts. ...
      (Focus-SUN)