Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Vuln-Dev
[Top] [All Lists]

Re: Changes to the filesystem while find is running - comments?

Subject: Re: Changes to the filesystem while find is running - comments?
Date: Wed, 24 Nov 2004 05:59:38 +1100 (EST)
James,

Hmm... It would not descend into just-now-changed automounts (and it may
not be able to get back out of them), but it should be able to traverse
reasonably long-lived mounts.

The problem is though that when you chdir() into an automount mount
point, automount aill automatically mount it for you.  Hence if an
automount filesystem wasn't already mounted, if you chdir() into it it
immediately becomes a "just-now-changed" mount point.  That's the
essensce of the problem I am trying to solve.

I think find should never cause an automount to "trigger" and cause it to
be mounted. It is OK to traverse if it was mounted to start with; is surely
not OK to traverse if it wasn't already mounted. Maybe your problem is
sidestepped by this principle?

[Right now cannot think of examples where find causing automounts to
trigger would be an obvious security or performance issue.]

To prevent find from causing an automount to trigger, maybe you could
somehow detect the presence of the mount point, check its status, and
(after a warning) not descend if it wasn't mounted. [I use the Debian
autofs package; this uses a normally empty directory, which is populated
with mounted directories when in use. Are we talking about the short time
between the mkdir of the mountpoint and the mount?]

Cheers,

Paul Szabo - psz@maths.usyd.edu.au  http://www.maths.usyd.edu.au:8000/u/psz/
School of Mathematics and Statistics  University of Sydney   2006  Australia

<Prev in Thread] Current Thread [Next in Thread>