Re: passwords within a small LAN: how?

From: Les Mikesell (lesmikesell_at_comcast.net)
Date: 08/02/03


Date: Sat, 02 Aug 2003 18:30:00 GMT


"Jingleheimer" <johnjacob@foobar.schmidt.com> wrote in message
news:3F2ACEF4.9030709@foobar.schmidt.com...
> >
> > It should be enough to have the same uid on the NFS client and NFS
> > server, as soon as the export is "rw", and you mount the export with the
> > right login/pass.
> >
>
> Yes---I find that it does work. But couldn't somebody set up a machine
> with the same uid and same login as a target user without knowing the
> password, then just connect to the network and access the target's files?

That is an issue with NFS in general regardless of the way you
handle authentication. For a small lan you can limit the hosts
that are allowed to connect to block unknown machines
but you still have the problem that anyone who can be root on his
own machine can pretend to be anyone else in the system since
root is allowed to su to anyone else.

---
  Les Mikesell
     lesmikesell@comcast.net


Relevant Pages

  • Re: NFS Security Question
    ... Subject: NFS Security Question ... Use sudo to give people root access. ... does not perform authentication of a UID, it merely believes that if a packet ...
    (Focus-SUN)
  • Re: Mount linux filesystem
    ... creates files as their own UID, ... to have 20 people logged into a single Windows machine at the same ... Even if multiple users were connecting from a single *nix box, ... If you have very simple needs, and a unix only environment, then NFS ...
    (comp.unix.sco.misc)
  • Re: NFS client on MacOS X
    ... I am trying to mount an NFS volume from a Linux-based NFS V2-3-4 ... Mac, as the client, and a Linux box running Knoppmyth as the server). ... uses UID numbers, not usernames, for access once the share is mounted. ...
    (comp.sys.mac.system)
  • Re: ZFS & NFS
    ... This is expected behaviour of NFS. ... It simply sets the UID of remote root to the value -1. ... a Solaris NFS server maps "root" access to ...
    (freebsd-stable)
  • Re: ZFS & NFS
    ... This is expected behaviour of NFS. ... It simply sets the UID of remote root to the value -1. ... a Solaris NFS server maps "root" access to ...
    (freebsd-stable)