»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 08-18-2003, 02:47 PM   #1 (permalink)
Registered User
 
CMonster's Avatar
 
Join Date: Oct 2001
Location: Sunny, smogy Southern California
Posts: 5,350
CMonster is on a distinguished road
mount NTFS as non-root user? -security?

The following /etc/fstab entry allows me to mount NTFS partition(s) as non-root, is there a major security risk?



/dev/**** /mnt/windows auto ro,noauto,user,uid=***,gid=***,umask=007, 0 0

CMonster is offline   Reply With Quote
Old 08-18-2003, 10:38 PM   #2 (permalink)
Registered User
 
pbharris's Avatar
 
Join Date: Oct 2001
Location: Chicago, IL
Posts: 2,403
pbharris is on a distinguished road
Send a message via ICQ to pbharris Send a message via AIM to pbharris Send a message via Yahoo to pbharris
hey ya CMonster - is users using the computer can be trusted then no, if there is data on the NTFS that should not fall into anyone elses hands then no, although i would get rid of the /dev/**** and put the /dev/hdX in - that does look like a security risk (i am not positive) in that one can attempt to mount an ntfs partion at any device file.
__________________
I don't use Linux because I hate Windows (which I do) I use Linux because I like it.
play mtrek! telnet://mtrek.com:23
Odds are very good there are several spelling mistakes in this post.
pbharris is offline   Reply With Quote
Old 08-19-2003, 02:34 AM   #3 (permalink)
Registered User
 
CMonster's Avatar
 
Join Date: Oct 2001
Location: Sunny, smogy Southern California
Posts: 5,350
CMonster is on a distinguished road
pb.... you do know the *** were just for example so that someone else could put in the appropriate values and use it on their systems as well....?

the actual for my system is:



/dev/sda1 /mnt/windows auto ro,noauto,user,uid=500,gid=100,umask=007, 0 0
CMonster is offline   Reply With Quote
Old 08-19-2003, 02:49 PM   #4 (permalink)
Registered User
 
nukes's Avatar
 
Join Date: Oct 2002
Location: Scotland, UK
Posts: 2,946
nukes is on a distinguished road
Send a message via AIM to nukes Send a message via Yahoo to nukes
Well, So long as you have the owner and group secure, then it should be ok, you are blocking anyone else reading the files, but I'm not sure if they could get into the directories and look at the structure. Maybe 227 would be better as you're mounting it read-only anyway, but as long as the accounts on the computer are ok, then there isn't a problem. For example on my system I mount the FAT32 partitions umask=0 as I'm the only one who uses it, and there's no servers/open ports running, and when there is, they're not accessible from outside my network (or by my gateway machine)
__________________
_____
NuKeS
nukes is offline   Reply With Quote
Old 08-20-2003, 01:54 AM   #5 (permalink)
Registered User
 
CMonster's Avatar
 
Join Date: Oct 2001
Location: Sunny, smogy Southern California
Posts: 5,350
CMonster is on a distinguished road
k -thanks for the input
CMonster is offline   Reply With Quote
Old 08-20-2003, 02:44 PM   #6 (permalink)
Registered User
 
pbharris's Avatar
 
Join Date: Oct 2001
Location: Chicago, IL
Posts: 2,403
pbharris is on a distinguished road
Send a message via ICQ to pbharris Send a message via AIM to pbharris Send a message via Yahoo to pbharris
Quote:
Originally posted by CMonster
pb.... you do know the *** were just for example so that someone else could put in the appropriate values and use it on their systems as well....?

the actual for my system is:



/dev/sda1 /mnt/windows auto ro,noauto,user,uid=500,gid=100,umask=007, 0 0
doh!!.... nope...
__________________
I don't use Linux because I hate Windows (which I do) I use Linux because I like it.
play mtrek! telnet://mtrek.com:23
Odds are very good there are several spelling mistakes in this post.
pbharris is offline   Reply With Quote
Old 08-20-2003, 04:55 PM   #7 (permalink)
Banned
 
Join Date: Aug 2003
Posts: 89
tedroddy666 is on a distinguished road
Send a message via AIM to tedroddy666
you using redhat? in suse its mounted on all users...
tedroddy666 is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 10:34 PM.