/proc doesn't work with Samba

Dan Kaminsky effugas at best.com
Thu Jun 24 20:54:14 GMT 1999


> 
> On Thu, 24 Jun 1999, Dan Kaminsky wrote:
> 
> > You can't share the proc file system in Samba.  Can this be fixed?
> > 
> 
> It is totally correct... /proc is not quite a standard file system. Some
> serious security implications exist if you could share it.

Like if you could share /etc?  Oh wait, you can :-)
 
> All the files in /proc is "special" files something like devices in /dev
> and this is local to the machine and also contains "priviledged"
> information about the machine. It should not be shared and if shared it
> should not allow you to get to the contents of those files.

It's not the place of the file sharing architecture to define which files
are "too important" to allow remote access to.  Is /proc a serious
security risk if the nobody user can read it?  I mean, there's no reason
that you can't set the access user on the /proc share to "nobody".   



More information about the samba-technical mailing list