RE: Checkpassword 0.90 + Redhat 9.0

"Adam Aube" <[email protected]> Wed, 2 Jul 2003 13:35:54 -0400
Newsgroups gmane.comp.djb.checkpassword
Message-ID <[email protected]>
> Granted, I don't know the internals of this program, but I thought all 
> it does was check the username/password against /etc/passwd and 
> /etc/shadow, and if I make those available to the qmaild user, I don't 
> see how or why checkpassword would need to change uid to root.

/etc/shadow is readable only by root for a reason - to protect the 
encrypted passwords it holds.

You could try making checkpassword suid root instead. Granted, that has 
its own set of security risks, but probably fewer than making 
/etc/shadow readable by users other than root.

Adam
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.237 / Virus Database: 115 - Release Date: 3/7/2001