[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: nfs e sudo: furo de segurança???




Do NFS Administration Guide da Sun

http://docs.sun.com/app/docs/doc/802-1963/6i5v8k26q?a=view

Secure NFS
The NFS environment is a powerful and convenient way to share file systems on a network of different computer architectures and operating systems. However, the same features that make sharing file systems through NFS operation convenient also pose some security problems. An NFS server authenticates a file request by authenticating the computer making the request, but not the user when using UNIX authentication. When using UNIX authentication, a client user can run su and impersonate the owner of a file. If DES authentication is used, the NFS server will authenticate the user, making this sort of impersonation much harder.



André Carezia wrote:
Thadeu Penna wrote:

Não, mas quando se trata de Linux e NFS. Solaris tem o secure-nfs.

Mas o sNFS continua sendo feito para autenticar *máquinas*, não
usuários. A autenticação é mais robusta, pois se baseia em criptografia
de chave pública (DES).

Somente o "root" pode montar compartilhamentos sNFS. Um usuário "root"
na máquina-cliente, usando "su", continua tendo acesso completo a
qualquer arquivo pertencente a qualquer usuário que esteja na base de
dados (/etc/passwd ou NIS).



--
 ___                  _                 .''`.
  | |_  _. _| _      |_) _ ._ ._  _.   : :'  :
  | | |(_|(_|(/_|_|  |  (/_| || |(_|   `. `'`
                    Linux User #50500    `-
Prof.Adjunto - Instituto de Física  ---Debian-
Universidade Federal Fluminense     Alpha/i386



Reply to: