RE: LKM Trojan
LULANI Olsi <[email protected]>
| Newsgroups | gmane.linux.redhat.release.enigma |
|---|---|
| Message-ID | <[email protected]> |
The NFS connection is not in an insecured network. There should be a separate NIC that will connect the web content machine. The topology will be something like this: <web Content-NFS server>------Back LAN------<Web server>-------World LAN. Exporting read-only the content via NFS in such a way is no security threat. There is not username/password check as the content is public via Internet. Databases must hold the confidential data, and must provide the access control to the content. Sincerely Mr. Olsi Lulani -----Original Message----- From: Eric Koldeweij [mailto:[email protected]] Sent: Friday, February 28, 2003 4:34 PM To: [email protected] Subject: Re: LKM Trojan I strongly oppose the use of NFS (or any rpc-related service) in an insecure network, even more strongly when one of the machines is already compromised. NFS should really only be used in completely trusted environments. Besides that I agree to the method mentioned. Eric. LULANI Olsi wrote: >It is clear that it is inevitable that you are going to format the server >sooner or later. My suggestion is that you move the web contect in another >machine, Just the web content. Export the data via NFS and mount them >read-only in the web server. The idea is to isolate web engine and the web >content. It is easier to replace an empty web server than a loaded web >server. Move the content to such a machine carefully checking it, and when >the migration is over reinstall the web server. > >Sincerely >Mr. Olsi Lulani > > > _______________________________________________ enigma-list mailing list [email protected] https://listman.redhat.com/mailman/listinfo/enigma-list