Re: [SPAM] Password strength bug
Drew Wells <[email protected]> Tue, 15 Sep 2015 14:03:54 +0100
| Newsgroups | gmane.mail.vpopmail |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--------------090106040304070401000809
Content-Type: text/plain; charset=iso-8859-15; format=flowed
Content-Transfer-Encoding: 7bit
On 09/15/2015 11:00 AM, Tonix - Antonio Nati wrote:
> Il 15/09/2015 11:03, Drew Wells ha scritto:
>> In vpopmail-5.5.0 there seems to be a bug in vpopmail.c where the
>> password strength is checked even if a password isn't used (such as
>> when -e is used to add the encrypted password). Patch attached.
>>
>>
>>
>
>
> I do not understand the problem.
>
> Of course password strenght is checked every time, and if it founds a
> null/empty password it gives error back if password must have a
> minimum lenght.
>
> Your patch instead permit to have null password even if strenght
> policy would not allow it.
>
> Regards,
>
> Tonino
The problem is is that vadduser.c can call vadduser() (in vpopmail.c)
without a password. It does this in the situation where vadduser.c has
had the options "-e" or "-n" passed to it, so if this is the case the
password can't be checked againts the password strength rules. The
underlying function vadduser() needs to be able to add a user with no
password.
!DSPAM:55f8173d41558919512318!
--------------090106040304070401000809
Content-Type: text/html; charset=iso-8859-15
Content-Transfer-Encoding: 8bit
<html>
<head>
<meta content="text/html; charset=iso-8859-15"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix">On 09/15/2015 11:00 AM, Tonix - Antonio
Nati wrote:<br>
</div>
<blockquote cite="mid:[email protected]" type="cite">
<meta content="text/html; charset=iso-8859-15"
http-equiv="Content-Type">
<div class="moz-cite-prefix">Il 15/09/2015 11:03, Drew Wells ha
scritto:<br>
</div>
<blockquote cite="mid:[email protected]" type="cite">In
vpopmail-5.5.0 there seems to be a bug in vpopmail.c where the
password strength is checked even if a password isn't used (such
as when -e is used to add the encrypted password). Patch
attached. <br>
<br>
<br>
<br>
</blockquote>
<br>
<br>
<font size="-1"><font face="Verdana">I do not understand the
problem.<br>
<br>
Of course password strenght is checked every time, and if it
founds a null/empty password it gives error back if password
must have a minimum lenght.<br>
<br>
Your patch instead permit to have null password even if
strenght policy would not allow it.<br>
<br>
Regards,<br>
<br>
Tonino</font></font><br>
</blockquote>
The problem is is that vadduser.c can call vadduser() (in
vpopmail.c) without a password. It does this in the situation where
vadduser.c has had the options "-e" or "-n" passed to it, so if this
is the case the password can't be checked againts the password
strength rules. The underlying function vadduser() needs to be able
to add a user with no password.<br>
<br>
!DSPAM:55f8173d41558919512318!
</body>
</html>
--------------090106040304070401000809--