Re: [SPAM] Password strength bug

Tonix - Antonio Nati <[email protected]> Tue, 15 Sep 2015 16:27:04 +0200
Newsgroups gmane.mail.vpopmail
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------030408010506080404020902
Content-Type: text/plain; charset=iso-8859-15; format=flowed
Content-Transfer-Encoding: 7bit

Il 15/09/2015 15:03, Drew Wells ha scritto:
> On 09/15/2015 11:00 AM, Tonix - Antonio Nati wrote:
>> Il 15/09/2015 11:03, Drew Wells ha scritto:
>>> In vpopmail-5.5.0 there seems to be a bug in vpopmail.c where the 
>>> password strength is checked even if a password isn't used (such as 
>>> when -e is used to add the encrypted password).  Patch attached.
>>>
>>>
>>>
>>
>>
>> I do not understand the problem.
>>
>> Of course password strenght is checked every time, and if it founds a 
>> null/empty password it gives error back if password must have a 
>> minimum lenght.
>>
>> Your patch instead permit to have null password even if strenght 
>> policy would not allow it.
>>
>> Regards,
>>
>> Tonino
> The problem is is that vadduser.c can call vadduser() (in vpopmail.c) 
> without a password.  It does this in the situation where vadduser.c 
> has had the options "-e" or "-n" passed to it, so if this is the case 
> the password can't be checked againts the password strength rules.  
> The underlying function vadduser() needs to be able to add a user with 
> no password.
>

I realize additional controls are done before calling vadduser(); but I 
personally would prefer an explicit parameter added to vadduser for 
avoiding password check (it may be a further parameter having default = 
"check").
It would make developers more protected against unwanted security bugs.

Regards,

Tonino


>  


-- 
------------------------------------------------------------
         Inter@zioni            Interazioni di Antonio Nati
    http://www.interazioni.it      [email protected]
------------------------------------------------------------



!DSPAM:55f82abc41552085678254!

--------------030408010506080404020902
Content-Type: text/html; charset=iso-8859-15
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta content="text/html; charset=iso-8859-15"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Il 15/09/2015 15:03, Drew Wells ha
      scritto:<br>
    </div>
    <blockquote cite="mid:[email protected]" type="cite">
      <meta content="text/html; charset=iso-8859-15"
        http-equiv="Content-Type">
      <div class="moz-cite-prefix">On 09/15/2015 11:00 AM, Tonix -
        Antonio Nati wrote:<br>
      </div>
      <blockquote cite="mid:[email protected]" type="cite">
        <meta content="text/html; charset=iso-8859-15"
          http-equiv="Content-Type">
        <div class="moz-cite-prefix">Il 15/09/2015 11:03, Drew Wells ha
          scritto:<br>
        </div>
        <blockquote cite="mid:[email protected]"
          type="cite">In vpopmail-5.5.0 there seems to be a bug in
          vpopmail.c where the password strength is checked even if a
          password isn't used (such as when -e is used to add the
          encrypted password).  Patch attached. <br>
          <br>
          <br>
          <br>
        </blockquote>
        <br>
        <br>
        <font size="-1"><font face="Verdana">I do not understand the
            problem.<br>
            <br>
            Of course password strenght is checked every time, and if it
            founds a null/empty password it gives error back if password
            must have a minimum lenght.<br>
            <br>
            Your patch instead permit to have null password even if
            strenght policy would not allow it.<br>
            <br>
            Regards,<br>
            <br>
            Tonino</font></font><br>
      </blockquote>
      The problem is is that vadduser.c can call vadduser() (in
      vpopmail.c) without a password.  It does this in the situation
      where vadduser.c has had the options "-e" or "-n" passed to it, so
      if this is the case the password can't be checked againts the
      password strength rules.  The underlying function vadduser() needs
      to be able to add a user with no password.<br>
      <br>
    </blockquote>
    <br>
    I realize additional controls are done before calling vadduser();
    but I personally would prefer an explicit parameter added to
    vadduser for avoiding password check (it may be a further parameter
    having default = "check").<br>
    It would make developers more protected against unwanted security
    bugs.<br>
    <br>
    Regards,<br>
    <br>
    Tonino<br>
    <br>
    <br>
    <blockquote cite="mid:[email protected]" type="cite">
      
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
------------------------------------------------------------
        Inter@zioni            Interazioni di Antonio Nati 
   <a class="moz-txt-link-freetext" href="http://www.interazioni.it">http://www.interazioni.it</a>      <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>           
------------------------------------------------------------
</pre>
  
!DSPAM:55f82abc41552085678254!

</body>
</html>



--------------030408010506080404020902--