Re: Samba Remote Zero-Day Exploit

看板Bugtraq作者時間16年前 (2010/02/09 10:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串11/12 (看更多)
Dear Kingcope, The samba server follows symlinks by default. There are options ("follow symlinks", "wide links") for turning it off: http://www.samba.org/samba/docs/using_samba/ch08.html#samba2-CHP-8-SECT-1.2 http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#FOLLOWSYMLINKS http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#WIDELINKS The "problem" at your installation seems a mis-configuration of your server: please ask the admin to set "secure" options. (Some samba installations, like mine, wish to allow same access as a UNIX login would allow. Some shares like [home] are provided for ease of use, users are encouraged to create symlinks to other "interesting" places e.g. NFS-mounted directories.) Cheers, Paul Paul Szabo psz@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of Sydney Australia
文章代碼(AID): #1BSC7UVX (Bugtraq)
討論串 (同標題文章)
文章代碼(AID): #1BSC7UVX (Bugtraq)