TCLUG Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TCLUG:12807] bad day (more details)



On Mon, 24 Jan 2000, Scott wrote:

> 
>      I've been told several times that NFS is rather
> insecure, though no one has ever mentioned what exactly the
> problems are with it.  

The big problem is that NFS is host-based, and hostnames are easy to
spoof. If you are allowing root equivalency as well, then you might as
well go home. All you would have to do would be to find some way of
convincing the machine that you are who you say you are, and it will let
you mount the drive.


 > Maybe you want to look and see if
> wind0ze boxes support Coda.  And what ftp daemon were you
> running?  wu-ftp is the default, but some people like
> proftpd, and I know that one had security issue too awhile
> back. 
> 
> Scott
> -- 
> I love you more than anything in this world.
> I don't expect that will last.
>  -Elvis Costello
> 
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: tclug-list-unsubscribe@mn-linux.org
> For additional commands, e-mail: tclug-list-help@mn-linux.org
> 
> 

___________________________________________________________________________
			HELP!  MY TYPEWRITER IS BROKEN!
					-- e. e. cummings

++ Dan Debertin
++ Systems Administrator
++ Bitstream Underground, Inc.
++ danield@bitstream.net
++ (612)321-9290