 |
08-18-2003, 02:47 PM
|
#1 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Sunny, smogy Southern California
Posts: 5,350
| » 
mount NTFS as non-root user? -security?
The following /etc/fstab entry allows me to mount NTFS partition(s) as non-root, is there a major security risk?
/dev/**** /mnt/windows auto ro,noauto,user,uid=***,gid=***,umask=007, 0 0
|
| |
08-18-2003, 10:38 PM
|
#2 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Chicago, IL
Posts: 2,403
|
hey ya CMonster - is users using the computer can be trusted then no, if there is data on the NTFS that should not fall into anyone elses hands then no, although i would get rid of the /dev/**** and put the /dev/hdX in - that does look like a security risk (i am not positive) in that one can attempt to mount an ntfs partion at any device file.
__________________
I don't use Linux because I hate Windows (which I do) I use Linux because I like it.
play mtrek! telnet://mtrek.com:23
Odds are very good there are several spelling mistakes in this post.
|
| |
08-19-2003, 02:34 AM
|
#3 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Sunny, smogy Southern California
Posts: 5,350
|
pb.... you do know the *** were just for example so that someone else could put in the appropriate values and use it on their systems as well....?
the actual for my system is:
/dev/sda1 /mnt/windows auto ro,noauto,user,uid=500,gid=100,umask=007, 0 0
|
| |
08-19-2003, 02:49 PM
|
#4 (permalink)
| | Registered User
Join Date: Oct 2002 Location: Scotland, UK
Posts: 2,946
|
Well, So long as you have the owner and group secure, then it should be ok, you are blocking anyone else reading the files, but I'm not sure if they could get into the directories and look at the structure. Maybe 227 would be better as you're mounting it read-only anyway, but as long as the accounts on the computer are ok, then there isn't a problem. For example on my system I mount the FAT32 partitions umask=0 as I'm the only one who uses it, and there's no servers/open ports running, and when there is, they're not accessible from outside my network (or by my gateway machine)
__________________
_____
NuKeS
|
| |
08-20-2003, 01:54 AM
|
#5 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Sunny, smogy Southern California
Posts: 5,350
|
k -thanks for the input
|
| |
08-20-2003, 02:44 PM
|
#6 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Chicago, IL
Posts: 2,403
| Quote: Originally posted by CMonster pb.... you do know the *** were just for example so that someone else could put in the appropriate values and use it on their systems as well....?
the actual for my system is:
/dev/sda1 /mnt/windows auto ro,noauto,user,uid=500,gid=100,umask=007, 0 0 | doh!!.... nope...
__________________
I don't use Linux because I hate Windows (which I do) I use Linux because I like it.
play mtrek! telnet://mtrek.com:23
Odds are very good there are several spelling mistakes in this post.
|
| |
08-20-2003, 04:55 PM
|
#7 (permalink)
| | Banned
Join Date: Aug 2003
Posts: 89
|
you using redhat? in suse its mounted on all users...
|
| | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | | | Thread Tools | | | | Display Modes | Linear Mode |
Posting Rules
| You may not post new threads You may not post replies You may not post attachments You may not edit your posts HTML code is Off | | | | Most Active Discussions  | | | | | Recent Discussions  | | | | | |