View previous topic :: View next topic |
Author |
Message |
batistuta Veteran
data:image/s3,"s3://crabby-images/66e5c/66e5c234886f45e11b41308b8f65d2542e40feb1" alt="Veteran Veteran"
data:image/s3,"s3://crabby-images/ad831/ad831fd2eb1b4f306587ed0bffd4aaddbe3027e6" alt=""
Joined: 29 Jul 2005 Posts: 1384 Location: Aachen
|
Posted: Sat Jan 05, 2008 4:11 pm Post subject: [solved] mount -o loop as user |
|
|
Is there any way to mount a loop device as a user? I know I can allow that via the fstab, but that would be for a specific image. What about allowing to mount an arbitrary iso image as a user? This shouldn't be a security concern, because in theory you could burn the image and put it on your cd-rom drive and read it. So in terms of security I don't see a compromise. Thanx
Last edited by batistuta on Mon Jan 07, 2008 3:31 pm; edited 1 time in total |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
NeddySeagoon Administrator
data:image/s3,"s3://crabby-images/a49a9/a49a9a4fe0fe25e0741dcc999a03bccdab82f66e" alt="Administrator Administrator"
data:image/s3,"s3://crabby-images/d8dd4/d8dd4736dc8f2a6c0a1c8a1fd947722cbc66685b" alt=""
Joined: 05 Jul 2003 Posts: 54875 Location: 56N 3W
|
Posted: Sat Jan 05, 2008 5:13 pm Post subject: |
|
|
batistuta,
Allow the user the use of the mount command via sudo
sudo allows you to restrict who can do what as root _________________ Regards,
NeddySeagoon
Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail. |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
MostAwesomeDude Guru
data:image/s3,"s3://crabby-images/55cad/55cadf22bfc4066b9cbef86ab0e8bd0c53423b93" alt="Guru Guru"
Joined: 12 Aug 2007 Posts: 373
|
Posted: Sat Jan 05, 2008 7:43 pm Post subject: |
|
|
Imagine, if you will:
Code: | $ mount -o loop -t iso9660 malicious-cd-image.iso /sbin |
So yes, it is a security risk. There's no way around it, sorry. Just use sudo. |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
batistuta Veteran
data:image/s3,"s3://crabby-images/66e5c/66e5c234886f45e11b41308b8f65d2542e40feb1" alt="Veteran Veteran"
data:image/s3,"s3://crabby-images/ad831/ad831fd2eb1b4f306587ed0bffd4aaddbe3027e6" alt=""
Joined: 29 Jul 2005 Posts: 1384 Location: Aachen
|
Posted: Mon Jan 07, 2008 3:31 pm Post subject: |
|
|
@NeddySeagoon thanks for the hint... I was just looking for an easier way to do it, maybe by allowing any user to mount at a specific location.
@MostAwesomeDude Good point, didn't think about that
@NeddySeagoon (again): congratulations for your new position, you more than deserve it.
I'll closed as solved |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
|