Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Our Archives > General Archives > Servers > Security Hole in OS X Server!

 
Security Hole in OS X Server!
Thread Tools
wormman
Guest
Status:
Nov 23, 1999, 02:19 AM
 
I have found what appears to be a security hole in OS X Server. When I connect to my server with privileges to directories that no-other user can see (except administrator). I then unmount the volume and reconnect as guest (guest has one folder nested with no privileges). Guest lets me mount the root file system just as I was the administrator, I can read files I can write files.

The file creator is set to nobody (I checked with "ls -l"). I triple checked all my permissions.

While the guest has the drive mounted, after a short period of time the server realizes something is wrong and all the lock folders start to appear then the user is promptly disconnected.

What's the deal, this doesn't make me feel like my server is too secure. Please if anyone can tell me if they have had similar experiences it would help me track down the issue.

I have the newest version of "AppleShare" running on the client and the most recent update to OS X Server running.

Maybe some of you can try this out on your networks to see if you have the same problems.

-Wormman
     
 
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 10:05 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2