[Gllug] NFS NIS

gllug at codex.net gllug at codex.net
Fri Sep 28 10:32:48 UTC 2001


On 28 Sep 2001, Ian Norton wrote:

> one issue i have had with NFS and NIS is this,
> 
> i could walk in, plug in my laptop and elect for it to use ypbind, it
> binds to my nis domain, and finishes booting,

or, you can look at it as a cool feature.


> i then su, mount the /home on the laptop, (at current exports are for
> specific hosts only but ip spoofing is fairly simple)
> 
> then su to a user give by nis, bang, i can read/write the nfs share!
> (the person doing this could be anyone with root on thier own laptop)

you need to use NIS+.  and unless things have changed recently, the server
only runs on solaris.


-- 


PGP key:  http://codex.net/pgp/pgp.asc


-- 
Gllug mailing list  -  Gllug at linux.co.uk
http://list.ftech.net/mailman/listinfo/gllug




More information about the GLLUG mailing list