NFS client and untrusted server

2017-11-24 Thread Chris
All, I want to backup a DMZ-server to an internal backup server. Is it reasonable to setup an NFS-server in the DMZ and mount it from the inside server using the read-only, noexec and nosuid options? Could an attacker gain access to the internal server this way? Does anyone use such a setup? in

Re: NFS client and untrusted server

2017-11-24 Thread Roberto C . Sánchez
On Fri, Nov 24, 2017 at 10:28:27PM +0100, Chris wrote: > All, > > I want to backup a DMZ-server to an internal backup server. > > Is it reasonable to setup an NFS-server in the DMZ and mount it from > the inside server using the read-only, noexec and nosuid options? Could > an attacker gain acces

Re: NFS client and untrusted server

2017-11-24 Thread Chris
On Fri, 24 Nov 2017 21:44:56 -0500 Roberto C. Sánchez wrote: > NFS is a very old protocol that very likely has as yet undiscovered > vulnerabilities. I would expect that the likelihood of there being > even a theoretical vulnerability that would allow a malicous user on > the server to gain acces