mount

From: undef (ls@blackout.ru)
Date: 12/27/01


Date: Thu, 27 Dec 2001 17:21:11 +0000
From: undef <ls@blackout.ru>
To: vuln-dev@securityfocus.com


Hello list.

Sorry if this is offtopic.

I tested all this on FreeBSD and Linux boxes.

%uname -a
FreeBSD xxx.xxx 4.4-RELEASE FreeBSD 4.4-RELEASE #1: Mon Dec 17 20:22:26 GMT 2001

%uname -a
Linux xxx.xxx 2.4.5 #6 Fri Jun 22 01:38:20 PDT 2001 i586 unknown

I found that one could mount any device to some mount point which already have something
mounted to it. It is possible some device (physical or virtual through vinum or NFS) to /.
When two devices are mounted to one mount point you could see contents of the last mounted device.
When you umount that last device you will see contents of the first mounted device.

I think in some cases it can help intruder to replace system files, or hide data, or something else.
Yes, i know, mount command can only be used by root. But anyway.

-- 
undef



Relevant Pages

  • Re: /var on a USB disk
    ... the /dev/sdX entries are dynamically changed as I plug in an another ... The fstab entry is based on the disk uuid: ... difference to any currently mounted device. ... $ mount | grep sda6 ...
    (Ubuntu)
  • Re: 2.6.0, cdrom still showing directories after being erased
    ... I think cdrecord should be hacked to complain loudly if the device is ... , blanking a mounted device is ... send the line "unsubscribe linux-kernel" in ...
    (Linux-Kernel)
  • Re: DD not working
    ... Jacques B. wrote: ... You can mount something on top of a currently mounted device ... device mounted at that mount point until after you unmount the last ...
    (Fedora)
  • Re: DD not working
    ... You can mount something on top of a currently mounted device ... device mounted at that mount point until after you unmount the last ... not apply so I won't go there and further confuse things). ...
    (Fedora)
  • Re: USB stick access freezing up system?
    ... average but it is choking on "blackhat" networks which have thousands ... would expect the application to fail, but the stick is just a mount in ... Does this mean that if a non RAIDed drive fails a ... FreeBSD box will reboot, ...
    (comp.unix.bsd.freebsd.misc)