Subject: Re: nfs - export file
To: Todd Vierling <tv@wasabisystems.com>
From: Nathan J. Williams <nathanw@MIT.EDU>
List: port-i386
Date: 09/27/2001 14:23:44
Todd Vierling <tv@wasabisystems.com> writes:

> : Any Unix vendor who claims otherwise about their NFS implementation is
> : misrepresenting themselves.
> 
> Then what do you have to say about Solaris?

"Sun is misrepresenting themselves."

> You may know more than I about the internal implementation of NFS on
> Solaris 2, but *ignoring* the prospect of packet sniffers for a
> moment, Solaris does indeed provide for differing hosts and options
> per exported tree, not per host mountpoint.

1. Ignoring packet sniffers is not possible. At this point in time,
   ignoring packet sniffers should be considered criminal negligence.

2. Read my example later in the thread. Even without packet sniffing,
   the differing options per tree can be exploited to obtain access to
   the entire filesystem containing the exported tree with the least
   restrictive options of any of the exported trees.

        - Nathan