Re: SUID Perl easy to hack
"Tod D. Ihde" <[email protected]> Fri, 21 Jan 2005 00:21:27 -0600
| Newsgroups | gmane.mail.neomail.general |
|---|---|
| Message-ID | <[email protected]> |
support wrote: > Hi, > > Warning suidperl is a highly easy and simple hackable exploit. > > You are endangering your server or hosting providers server by > installing this perl access. > > We are waiting for neomail to release a secure non hackable (easy hack) > version of neomail as we have many clients that like the functions, but > since this neomail is on the top of the easy hack to root on a server we > cannot use and will not recommend such to any user. > > I hope neomail catches up with the times and patches the easy exploits. > > Richard Richard, A couple of things... It's customary when replying to a message that's part of a digest to change the subject, so we know what you're replying to. The SUID perl exploit you're referring to has been known about (and corrected) for 5 years now (unless you're referring to something much newer, but I can't be sure, since you failed to cite any reference materials). I'm _assuming_ you're talking about this one: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=15630 (sperl 5.00503) or this one ( http://msgs.securepoint.com/cgi-bin/get/bugtraq0008/102.html ) or perhaps this one ( http://www.linuxsecurity.com/content/view/102504/111/ )... All of those are from 2000. There is _always_ a risk when you run SUID software. That's the nature of 'set UID', you're trusting that the code you're running is bug free, and allowing it to run as someone else. I was unable to find _any_ exploit for neomail via google (and I'm usually pretty good at research), nor have I ever heard of an exploit for neomail. Can you dig up any documentation to back up your claim that neomail is insecure? (Yes, passwords are transmitted cleartext, if you use http instead of https. That's your fault, not neomail's). Neomail does not need SUID perl unless your setup is such that it requires it, that's why the install asks if you want it SUID or not. Don't like or trust SUID perl? Don't run neomail SUID! Yes, you might have to massage your server some to make everything play nice, but that's almost always the case when adding non-vendor-supplied software to a server (at least, in my experience, YMMV). The other nice thing about open source is, you don't have to wait - if you feel that neomail could be made better, make the changes yourself, and you can even send them back upstream to be included in the next version. But please, please PLEASE... don't go making (damaging or otherwise) claims that you don't (or can't) back up with real data. Please. Tod. ps. Oh, hi everyone. I've crawled back out of my shell. :) ------------------------------------------------------- This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting Tool for open source databases. Create drag-&-drop reports. Save time by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc. Download a FREE copy at http://www.intelliview.com/go/osdn_nl