home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.sun.admin
- Path: sparky!uunet!bellahs!gfong
- From: gfong@bellahs.com (Gary Fong RD)
- Subject: NIS security hole or something?
- Message-ID: <1992Sep15.002925.6205@bellahs.com>
- Organization: Bell Atlantic Healthcare Systems
- Distribution: usa
- Date: Tue, 15 Sep 1992 00:29:25 GMT
- Lines: 33
-
-
- Sun Experts
-
- Machine(s): Sun 4/40, Sun 4/670
- OS: SunOS 4.1.2
- Topology: Fileserver Sun 4/670
- NFS Nodes Sun 4/40
-
- Background:
-
- Using NIS
- Allow a user root access to their own Sun machine (but not server)
- All users' home directory is on server
-
- Problem:
-
- User can modify own /etc/passwd, add an identical entry for some existing
- user (obtained from NIS master server's /etc/passwd) without of course the
- password string, login as that user and modify that user's files.
-
- This doesn't seem to work fortunately for root. But for all the ordinary
- users, it does.
-
- Questions:
-
- How do we prevent this?
-
- Can user somehow get root access to server or any other machine?
-
- I've read the manuals including O'Riley's _NFS and NIS_ but can't seem to
- locate anything specific.
-
- Gary
-