Re: NFS4 authentification / fsuid

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Jan Engelhardt <jengelh@...>
Cc: Linux Kernel Mailing List <linux-kernel@...>
Date: Thursday, August 30, 2007 - 11:04 am

On Thu, 2007-08-30 at 16:42 +0200, Jan Engelhardt wrote:

With CIFS or other password based protocols (including RPCSEC_GSS) all
the root user needs in order to steal your identity is to grab a copy of
your password or a credential. It is not quite as trivial to do as
changing uid, but it is hardly rocket science if the compromised machine
is one that you log into regularly.


What I'm saying is that the superuser can pretty much do whatever it
takes to grab either your kerberos password (e.g. install a keyboard
listener), a stored credential (read the contents of your kerberos
on-disk credential cache), or s/he can access the cached contents of the
file by hunting through /dev/kmem.

IOW: There is no such thing as security on a root-compromised machine.

Trond

-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
NFS4 authentification / fsuid, Jan Engelhardt, (Thu Aug 30, 10:12 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 10:29 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 10:32 am)
Re: NFS4 authentification / fsuid, Jan Engelhardt, (Thu Aug 30, 10:42 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Aug 30, 11:12 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 11:04 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Aug 30, 5:44 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 6, 4:14 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Sep 6, 11:06 am)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Thu Sep 6, 7:30 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 7:35 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Thu Sep 6, 8:56 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 7:44 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Wed Sep 19, 1:16 am)
Re: NFS4 authentification / fsuid, , (Wed Sep 19, 12:38 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 20, 3:15 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Wed Sep 19, 8:16 am)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Wed Sep 19, 9:49 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Wed Sep 19, 10:12 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Wed Sep 19, 11:01 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 20, 3:03 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Fri Sep 7, 1:14 am)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Fri Sep 7, 1:47 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 7:48 pm)
Re: NFS4 authentification / fsuid, Bernd Eckenfels, (Fri Sep 7, 2:37 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 6, 4:29 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Sep 6, 11:11 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 7:12 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 7:21 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 7:32 pm)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Fri Sep 7, 11:34 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 7:27 pm)