19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Threats Catalogue Deliberate Acts Remarks<br />

____________________________________________________________________ .........................................<br />

T 3.10 Incorrect export of file systems under UNIX<br />

Exported disks can be mounted from any computer whose name is specified in<br />

files /etc/exports or /etc/dfs/dfstab. <strong>The</strong> user of such a computer can assume<br />

any UID and GID. As long as directories have not been exported with the<br />

option root=, UID 0 (root) constitutes an exception which, on access to an<br />

NFS server, is normally mapped to a different UID (e.g. to the UID of the user<br />

nobody or anonymous). Hence only files which belong to root can be<br />

protected.<br />

<strong>The</strong>re are no adequate protective measures available in protected<br />

environments for the use of the NFS protocols for the export of file systems or<br />

the distribution of system files using NIS. Such use therefore constitutes a<br />

threat to the integrity of the systems.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!