Re: Samba

From: Edward Monteiro (monteiro_edward_at_hotmail.com)
Date: 11/28/03

  • Next message: Jimi Thompson: "Re: McAfee Anti Virus V4.5.1 SP1"
    To: "Depp, Dennis M." <deppdm@ornl.gov>, "Jack Solomon" <solzjack43@hotmail.com>, <security-basics@securityfocus.com>
    Date: Fri, 28 Nov 2003 12:21:23 -0300
    
    

    Jack,

    Go to http://us1.samba.org/samba/docs/Samba-HOWTO-Collection.pdf , page 39 ,
    and see Server Types and security modes.

    Edward
    monteiro_edward@hotmail.com
    Brasil este é o lugar.

    ----- Original Message -----
    From: "Depp, Dennis M." <deppdm@ornl.gov>
    To: "Jack Solomon" <solzjack43@hotmail.com>;
    <security-basics@securityfocus.com>
    Sent: Thursday, November 27, 2003 5:06 PM
    Subject: RE: Samba

    Not sure as I don't consider SAMBA to have a lot of security concerns.
    I would also look at who has security concerns with SAMBA. If it is a
    Windows Admin, I would be skeptical. If it is a Unix admin I would
    listen more closely. Keep in mind the older versions only support
    NTLMv2 and if it is not configured properly, it could use NTLM. I'm not
    sure if the new versions are setup to use Kerberos or not. I'm also not
    sure if the SAMBA server updates its password when used with a Windows
    domain or not. SAMBA is probably more secure than many of the NAS
    devices that are currently available, particularly the ones running a
    proprietary OS.

    Denny

    -----Original Message-----
    From: Jack Solomon [mailto:solzjack43@hotmail.com]
    Sent: Thursday, November 27, 2003 10:17 AM
    To: security-basics@securityfocus.com
    Subject: Samba

    what are the security concerns over Samba? Someone told me that its a
    real
    bad idea security-wise but noone can tell me why...

    Jack

    _________________________________________________________________
    Use MSN Messenger to send music and pics to your friends
    http://www.msn.co.uk/messenger

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Jimi Thompson: "Re: McAfee Anti Virus V4.5.1 SP1"

    Relevant Pages

    • [UNIX] Security Bugfix for Samba (SMB/CIFS Overflow)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... running a Samba server. ... The above will only allow SMB connections from 'localhost' (your own ... Fix delete on close semantics to match W2K. ...
      (Securiteam)
    • [UNIX] Buffer Overflow in Samba allows remote root compromise
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... off of the Samba source tree, and aims at being a substitute for a Windows ... A buffer overflow vulnerability in the Samba daemon allows an attacker to ...
      (Securiteam)
    • Re: CIFS on VMS, multi-user share per user security setup question
      ... and 'connects as another user' to log in to the samba ... When I added new sets of ACEs for the CIFS identifiers of each of the ... any other account had created. ... Another item is attempting to modify the security profile from the ...
      (comp.os.vms)
    • [UNIX] Samba Server Multiple Vulnerabilities
      ... Get your security news from a reliable source. ... Samba Server Multiple Vulnerabilities ... Buffer overrun in NSS host lookup Winbind library on Solaris: ...
      (Securiteam)
    • Re: Samba gives root rw access, but others only ro. Windows OK
      ... smb.conf until I had the security I needed. ... samba shares from the client. ... load printers = yes ... # Browser Control Options: ...
      (alt.os.linux.redhat)