Re: SUID Perl easy to hack

Torsten Mueller <[email protected]> Fri, 21 Jan 2005 14:48:03 +0100
Newsgroups gmane.mail.neomail.general
Message-ID <[email protected]>
Hi,

Tod D. Ihde schrieb:
> support wrote:
> 
>> Hi,
>>
>> Warning suidperl is a highly easy and simple hackable exploit.
...

> Richard,
> 
>  A couple of things...
...
>  Neomail does not need SUID perl unless your setup is such that it 
> requires it, that's why the install asks if you want it SUID or not. 
> Don't like or trust SUID perl? Don't run neomail SUID! Yes, you might 
> have to massage your server some to make everything play nice, but 
> that's almost always the case when adding non-vendor-supplied software 
> to a server (at least, in my experience, YMMV).

Full Ack to Tod.
IMO neomail only needs suidperl to be able to access the mailspools.
If someone needs a non suidperl neomail (i think most of us would
at least prefer it) it would only be necessary to give neomail
access to the mailspools. Depending of the MTA this can be an
easy or not easy task. In todays world most users don't get
a shell account on machines, many setups are "virtual accounts".
In such a setup it's possible to instruct the MTA to save the
spool with different permissions or ownerships.
... But only my 2 cents.

Torsten


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl