MS-DFS referral.

Shirish Kalele kalele at veritas.com
Wed Oct 29 22:12:11 GMT 2003


The patch looks good. 

Speed is really the only reason the paths were being restricted to
lowercase; I didn't think ppl would be that concerned with case in their
dfs topology. 

Anyway, the next step would be to use the results of RESOLVE_DFSPATH all
over to prevent unix_convert being called twice for local pathnames.

Thanks,
Shirish

On Wed, Oct 29, 2003 at 09:06:05PM +0000, Jeremy Allison wrote:
> On Wed, Oct 29, 2003 at 12:59:14PM -0800, Shirish Kalele wrote:
> > Sorry, Jeremy, given that there's no spec, the old what-ms-does-is-correct
> > rule will have to apply here. But you're right that this seems like a
> > security flaw, allowing a view into the dfs topology with no
> > authorization.
> 
> Thanks. BTW: if you could take a look at the bugfix I'd appreciate it.
> This is originally your code, I just changed it to use the standard
> unix_convert directory lookups to cope with arbitrary case in dfs
> paths.
> 
> Jeremy.



More information about the samba-technical mailing list