Hello there,
when trying to boot another machine using the knoppix-terminalserver
with activated "secure-mode" (Flag for "Secure: Disable root access on
clients"), I still get complete root access on the network-booted
client-machine (sudo, root-console, ...).
The kernel-parameter "secure" is set, and the NFS-Share gets mounted (to
/cdrom) with the "nosuid" option. Unfortunatelly that does not really
achieve anything.
The cloop-device (mounted to /KNOPPIX) and the union-fs (at /UNIONFS)
get mounted without the option, so that all files retain their suid-flags.
I tried this with Knoppix-5.0.1-DE and Knoppix-4.0.2-DE. It's the same
in both cases.
Is this feature broken? Does it work for anyone else? Am I completely
missing something? Any hints?
Thanks,
Greg

Dell Precision T5820 Workstation 3.70GHz W-2135 No RAM/ GPU/ HDD/ OS
$179.98
Dell Precision Tower 7810 Xeon E5-2630 v3 @ 2.40GHz , 32GB Ram, NO HDD, NO OS
$239.99
Dell EMC PowerEdge R440 Xeon silver 4215 2.5GHz 16 GB ram 2x 550W PSU No HDD
$275.00
Intel Xeon Phi 5110P 60-Core 1.053GHz Coprocessor
$50.00
Genuine Intel Xeon W-2145 3.70Ghz 8 Cores LGA2066 CPU SR3LQ Tested USA SELLER
$94.94
Intel Xeon E5-2699 V4 2.20GHz 55M 22-CORES LGA2011-3 Server Processor 145W SR2JS
$84.49
Dell Precision T7820 2x Xeon Silver 4114 2.20GHz 950W No RAM GPU HDD 4x SATA
$350.48
INTEL XEON E5-2680V4 SR2N7 2.40GHZ CPU
$12.00
Dell PowerEdge FX2s + 8x FC430 Blades 16x E5-2630v4 160 Cores Rails No PSU/RAM
$699.00
Dell Precision T1700 Workstation Intel Xeon 16G Ram 256GG SSD Nvidia 600 Win 10
$109.99