Re: Problems with Neomail
Miguel! <[email protected]> Fri, 21 Jan 2005 19:09:19 -0600 (CST)
| Newsgroups | gmane.mail.neomail.general |
|---|---|
| Message-ID | <[email protected]> |
Hi everyone again and thanks for your help ! I installed with success NeoMail version 1.24 But i have problems with this :(. When i send a mail to my account and i login in this An error is found :( The server encountered an internal error or misconfiguration and was unable to complete your request. Please contact the server administrator, [email protected] and inform them of the time the error occurred, and anything you might have done that may have caused the error. When i erase the message by outlook, my neomail login is success. But when i compose a new email or try to change from inbox to send-mail folder the next error appears: Software error: Insecure dependency in open while running setuid at /home/www/cgi-bin/neomail.pl line 2773. For Neomail worked i had to make a chmod 4755 on neomail.pl and neomail-prefs.pl, and a chmod 755 on checklogin.pl, and only with this changes NeoMail runs!!!! Any Idea for having success :( ?, thanks for your advices!!!, Miguel ! --- "Tod D. Ihde" <[email protected]> escribi=F3:=20 > support wrote: > > Hi, > >=20 > > Warning suidperl is a highly easy and simple > hackable exploit. > >=20 > > You are endangering your server or hosting > providers server by=20 > > installing this perl access. > >=20 > > We are waiting for neomail to release a secure non > hackable (easy hack)=20 > > version of neomail as we have many clients that > like the functions, but=20 > > since this neomail is on the top of the easy hack > to root on a server we=20 > > cannot use and will not recommend such to any > user. > >=20 > > I hope neomail catches up with the times and > patches the easy exploits. > >=20 > > Richard >=20 > Richard, >=20 > A couple of things... >=20 > It's customary when replying to a message that's > part of a digest to=20 > change the subject, so we know what you're replying > to. >=20 > The SUID perl exploit you're referring to has been > known about (and=20 > corrected) for 5 years now (unless you're referring > to something much=20 > newer, but I can't be sure, since you failed to cite > any reference=20 > materials). I'm _assuming_ you're talking about this > one: > https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=3D15630 > (sperl=20 > 5.00503) or this one (=20 > http://msgs.securepoint.com/cgi-bin/get/bugtraq0008/102.html > ) or=20 > perhaps this one ( > http://www.linuxsecurity.com/content/view/102504/111/ >=20 > )... All of those are from 2000. >=20 > There is _always_ a risk when you run SUID > software. That's the nature=20 > of 'set UID', you're trusting that the code you're > running is bug free,=20 > and allowing it to run as someone else. >=20 > I was unable to find _any_ exploit for neomail via > google (and I'm=20 > usually pretty good at research), nor have I ever > heard of an exploit=20 > for neomail. Can you dig up any documentation to > back up your claim that=20 > neomail is insecure? (Yes, passwords are transmitted > cleartext, if you=20 > use http instead of https. That's your fault, not > neomail's). >=20 > Neomail does not need SUID perl unless your setup > is such that it=20 > requires it, that's why the install asks if you want > it SUID or not.=20 > Don't like or trust SUID perl? Don't run neomail > SUID! Yes, you might=20 > have to massage your server some to make everything > play nice, but=20 > that's almost always the case when adding > non-vendor-supplied software=20 > to a server (at least, in my experience, YMMV). >=20 > The other nice thing about open source is, you don't > have to wait - if=20 > you feel that neomail could be made better, make the > changes yourself,=20 > and you can even send them back upstream to be > included in the next version. >=20 > But please, please PLEASE... don't go making > (damaging or otherwise)=20 > claims that you don't (or can't) back up with real > data. Please. >=20 > Tod. >=20 > ps. > Oh, hi everyone. I've crawled back out of my > shell. :) >=20 >=20 > ------------------------------------------------------- > This SF.Net email is sponsored by: IntelliVIEW -- > Interactive Reporting > Tool for open source databases. Create drag-&-drop > reports. Save time > by over 75%! Publish reports on the web. Export to > DOC, XLS, RTF, etc. > Download a FREE copy at > http://www.intelliview.com/go/osdn_nl > _______________________________________________ > NeoMail-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/neomail-users > =20 _________________________________________________________ Do You Yahoo!? Informaci=F3n de Estados Unidos y Am=E9rica Latina, en Yahoo! Noticias. Vis=EDtanos en http://noticias.espanol.yahoo.com ------------------------------------------------------- This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting Tool for open source databases. Create drag-&-drop reports. Save time by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc. Download a FREE copy at http://www.intelliview.com/go/osdn_nl