Re: Bug/security hole in NFS cache (1.3.68)

Jens Glaser (jens@warez.rhoen.de)
Sun, 25 Feb 1996 02:35:22 +0100 (MET)


Hi & Ho,

On Fri, 23 Feb 1996, Robert H. de Vries wrote:
> It seems that the NFS cache keeps its data without regard of who
> requested it the first time.
> You have to export the file system in such a way that root on the
> mounting computer has no root privileges on the exporting computer as
> given by the -root option in /etc/exports.
> If you read a file as root without read permission, you get a file with NUL
> characters only. If you read that same file with another UID with the
> right permissions you see the same contents.
> On the other hand if you read that file first as someone with read
> privileges and read the file afterwards by root the file is OK.

When you own root privileges on the mounting computer it is no problem
at all to quickly set up a user with the appropriate UID/GID in order
to read files on a NFS.

Regards, Jens

--
Jens Glaser  fon +49-661-48320  IN Kompetent e.V Internet surrounded by Nature
<A HREF="http://www.rhoen.de/users/jens.glaser.html"> jens@warez.rhoen.de </A>