Great Circle Associates Firewalls
(November 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: mountd Security
From: Phil Howard <phil @ colt . milepost . com>
Date: Fri, 3 Nov 1995 20:43:04 -0600 (CST)
To: morph_1 @ netaxs . com (W0W! @ # ELYTENESS# @ !)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <Pine . SUN . 3 . 91 . 951103035258 . 25231A-100000 @ unix3 . netaxs . com> from "!" at Nov 3, 95 04:06:59 am

> Well the firewall itself isn't in question, it's the fact that mountd is
> running between the machines that have users on them inside the firewall,
> is there any security problem with running mountd that can be locally 
> exploited? If there is then i would just disable the daemon; not exporting
> anything nesc at this point. Limiting access would work too, but first
> I wanted to establish if much of a risk exists. 
> As far as what's being exported goes, it's only (rw) filesystems to the 
> machines inside the firewall.

Your inside users could take advantage of the mountd.  Maybe they won't.
If you trust those users, then you don't need to worry about them.  IP
addresses can be faked.  Userids can be faked from machines where someone
has root access or physical machine access.

Security comes from a combination of trust and distrust that is correctly
attributed.  If you know correctly who you can trust and who you cannot
trust, you will do the right thing, given the right information.

I have found a situation where I was exporting a filesystem ro to all hosts
and rw to two hosts.  However, it turned out that all hosts had rw.  I do
not know what was wrong, and because it wasn't anything important, I just
removed it all and never investigated.


Follow-Ups:
References:
Indexed By Date Previous: defending against sequence number attacks
From: smb @ research . att . com
Next: Re: Replacing From: field
From: smoot @ tic . com
Indexed By Thread Previous: Re: mountd Security
From: "W0W! @ # ELYTENESS# @ !" <morph_1 @ netaxs . com>
Next: Re: mountd Security
From: "W0W! @ # ELYTENESS# @ !" <morph_1 @ netaxs . com>

Google
 
Search Internet Search www.greatcircle.com