Re: Problems with Neomail

Miguel! <[email protected]> Fri, 21 Jan 2005 19:09:19 -0600 (CST)
Newsgroups gmane.mail.neomail.general
Message-ID <[email protected]>
Hi everyone again and thanks for your help !

I installed with success NeoMail version 1.24

But i have problems with this :(.

When i send a mail to my account and i login in this
An error is found :(

The server encountered an internal error or
misconfiguration and was unable to complete your
request.
Please contact the server administrator,
[email protected] and inform them of the time
the error occurred, and anything you might have done
that may have caused the error.

When i erase the message by outlook, my neomail login
is success. But when i compose a new email or try to
change from inbox to send-mail folder the next error
appears:

Software error:
Insecure dependency in open while running setuid at
/home/www/cgi-bin/neomail.pl line 2773.

For Neomail worked i had to make a chmod 4755 on
neomail.pl and neomail-prefs.pl, and a chmod 755 on
checklogin.pl, and only with this changes NeoMail
runs!!!!

Any Idea for having success :( ?, thanks for your
advices!!!,

Miguel !







 --- "Tod D. Ihde" <[email protected]>
escribi=F3:=20
> support wrote:
> > Hi,
> >=20
> > Warning suidperl is a highly easy and simple
> hackable exploit.
> >=20
> > You are endangering your server or hosting
> providers server by=20
> > installing this perl access.
> >=20
> > We are waiting for neomail to release a secure non
> hackable (easy hack)=20
> > version of neomail as we have many clients that
> like the functions, but=20
> > since this neomail is on the top of the easy hack
> to root on a server we=20
> > cannot use and will not recommend such to any
> user.
> >=20
> > I hope neomail catches up with the times and
> patches the easy exploits.
> >=20
> > Richard
>=20
> Richard,
>=20
>   A couple of things...
>=20
>   It's customary when replying to a message that's
> part of a digest to=20
> change the subject, so we know what you're replying
> to.
>=20
>   The SUID perl exploit you're referring to has been
> known about (and=20
> corrected) for 5 years now (unless you're referring
> to something much=20
> newer, but I can't be sure, since you failed to cite
> any reference=20
> materials). I'm _assuming_ you're talking about this
> one:
>
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=3D15630
> (sperl=20
> 5.00503) or this one (=20
>
http://msgs.securepoint.com/cgi-bin/get/bugtraq0008/102.html
> ) or=20
> perhaps this one (
>
http://www.linuxsecurity.com/content/view/102504/111/
>=20
> )... All of those are from 2000.
>=20
>   There is _always_ a risk when you run SUID
> software. That's the nature=20
> of 'set UID', you're trusting that the code you're
> running is bug free,=20
> and allowing it to run as someone else.
>=20
>   I was unable to find _any_ exploit for neomail via
> google (and I'm=20
> usually pretty good at research), nor have I ever
> heard of an exploit=20
> for neomail. Can you dig up any documentation to
> back up your claim that=20
> neomail is insecure? (Yes, passwords are transmitted
> cleartext, if you=20
> use http instead of https. That's your fault, not
> neomail's).
>=20
>   Neomail does not need SUID perl unless your setup
> is such that it=20
> requires it, that's why the install asks if you want
> it SUID or not.=20
> Don't like or trust SUID perl? Don't run neomail
> SUID! Yes, you might=20
> have to massage your server some to make everything
> play nice, but=20
> that's almost always the case when adding
> non-vendor-supplied software=20
> to a server (at least, in my experience, YMMV).
>=20
> The other nice thing about open source is, you don't
> have to wait - if=20
> you feel that neomail could be made better, make the
> changes yourself,=20
> and you can even send them back upstream to be
> included in the next version.
>=20
>   But please, please PLEASE... don't go making
> (damaging or otherwise)=20
> claims that you don't (or can't) back up with real
> data. Please.
>=20
> Tod.
>=20
> ps.
>   Oh, hi everyone. I've crawled back out of my
> shell. :)
>=20
>=20
>
-------------------------------------------------------
> This SF.Net email is sponsored by: IntelliVIEW --
> Interactive Reporting
> Tool for open source databases. Create drag-&-drop
> reports. Save time
> by over 75%! Publish reports on the web. Export to
> DOC, XLS, RTF, etc.
> Download a FREE copy at
> http://www.intelliview.com/go/osdn_nl
> _______________________________________________
> NeoMail-users mailing list
> [email protected]
>
https://lists.sourceforge.net/lists/listinfo/neomail-users
> =20

_________________________________________________________
Do You Yahoo!?
Informaci=F3n de Estados Unidos y Am=E9rica Latina, en Yahoo! Noticias.
Vis=EDtanos en http://noticias.espanol.yahoo.com


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl