mirror of
https://github.com/samba-team/samba.git
synced 2024-12-28 07:21:54 +03:00
da99e3a724
Igor Mammedov pointed out that reverse resolving an IP address to get the hostname portion of a principal could open a possible attack vector. If an attacker were to gain control of DNS, then he could redirect the mount to a server of his choosing, and fix the reverse resolution to point to a hostname of his choosing (one where he has the key for the corresponding cifs/ or host/ principal). That said, we often trust DNS for other reasons and it can be useful to do so. Make the code that allows trusting DNS to be enabled by adding --trust-dns to the cifs.upcall invocation. Signed-off-by: Jeff Layton <jlayton@redhat.com> |
||
---|---|---|
.. | ||
cifs_spnego.h | ||
cifs.upcall.c | ||
mount.cifs.c | ||
mount.h | ||
mtab.c | ||
umount.cifs.c |