Re: [SPAM] Password strength bug

Drew Wells <[email protected]> Tue, 15 Sep 2015 14:03:54 +0100
Newsgroups gmane.mail.vpopmail
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------090106040304070401000809
Content-Type: text/plain; charset=iso-8859-15; format=flowed
Content-Transfer-Encoding: 7bit

On 09/15/2015 11:00 AM, Tonix - Antonio Nati wrote:
> Il 15/09/2015 11:03, Drew Wells ha scritto:
>> In vpopmail-5.5.0 there seems to be a bug in vpopmail.c where the 
>> password strength is checked even if a password isn't used (such as 
>> when -e is used to add the encrypted password).  Patch attached.
>>
>>
>>
>
>
> I do not understand the problem.
>
> Of course password strenght is checked every time, and if it founds a 
> null/empty password it gives error back if password must have a 
> minimum lenght.
>
> Your patch instead permit to have null password even if strenght 
> policy would not allow it.
>
> Regards,
>
> Tonino
The problem is is that vadduser.c can call vadduser() (in vpopmail.c) 
without a password.  It does this in the situation where vadduser.c has 
had the options "-e" or "-n" passed to it, so if this is the case the 
password can't be checked againts the password strength rules.  The 
underlying function vadduser() needs to be able to add a user with no 
password.



!DSPAM:55f8173d41558919512318!

--------------090106040304070401000809
Content-Type: text/html; charset=iso-8859-15
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta content="text/html; charset=iso-8859-15"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix">On 09/15/2015 11:00 AM, Tonix - Antonio
      Nati wrote:<br>
    </div>
    <blockquote cite="mid:[email protected]" type="cite">
      <meta content="text/html; charset=iso-8859-15"
        http-equiv="Content-Type">
      <div class="moz-cite-prefix">Il 15/09/2015 11:03, Drew Wells ha
        scritto:<br>
      </div>
      <blockquote cite="mid:[email protected]" type="cite">In

        vpopmail-5.5.0 there seems to be a bug in vpopmail.c where the
        password strength is checked even if a password isn't used (such
        as when -e is used to add the encrypted password).  Patch
        attached. <br>
        <br>
        <br>
        <br>
      </blockquote>
      <br>
      <br>
      <font size="-1"><font face="Verdana">I do not understand the
          problem.<br>
          <br>
          Of course password strenght is checked every time, and if it
          founds a null/empty password it gives error back if password
          must have a minimum lenght.<br>
          <br>
          Your patch instead permit to have null password even if
          strenght policy would not allow it.<br>
          <br>
          Regards,<br>
          <br>
          Tonino</font></font><br>
    </blockquote>
    The problem is is that vadduser.c can call vadduser() (in
    vpopmail.c) without a password.  It does this in the situation where
    vadduser.c has had the options "-e" or "-n" passed to it, so if this
    is the case the password can't be checked againts the password
    strength rules.  The underlying function vadduser() needs to be able
    to add a user with no password.<br>
    <br>
  
!DSPAM:55f8173d41558919512318!

</body>
</html>



--------------090106040304070401000809--