[one-users] Attributes SOURCE (DISK section) and FILES (CONTEXT section) in OpenNebula 3.2

2012-01-18 Thread Ruben Diez
Hi: We just migrate to OpenNebula 3.2 and we have found that some users can't instantiate their VMs... After consult at: http://opennebula.org/documentation:rel3.2:template#disks_section and http://opennebula.org/documentation:rel3.2:template#context_section We know that the use of

Re: [one-users] Attributes SOURCE (DISK section) and FILES (CONTEXT section) in OpenNebula 3.2

2012-01-18 Thread Ruben S. Montero
Hi, First, let me briefly explain the rationale behind this. Both parameters (SOURCE, FILES in CONTEXT) lets ANY user to access ANY file that the oneadmin UNIX account can access. A simple and direct exploit is to put DISK = [ SOURCE = /var/lib/one/one.db ] (or equivalently in CONTEXT) and