Re: [SPAM] Password strength bug
Tonix - Antonio Nati <[email protected]> Tue, 15 Sep 2015 16:27:04 +0200
| Newsgroups | gmane.mail.vpopmail |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--------------030408010506080404020902
Content-Type: text/plain; charset=iso-8859-15; format=flowed
Content-Transfer-Encoding: 7bit
Il 15/09/2015 15:03, Drew Wells ha scritto:
> On 09/15/2015 11:00 AM, Tonix - Antonio Nati wrote:
>> Il 15/09/2015 11:03, Drew Wells ha scritto:
>>> In vpopmail-5.5.0 there seems to be a bug in vpopmail.c where the
>>> password strength is checked even if a password isn't used (such as
>>> when -e is used to add the encrypted password). Patch attached.
>>>
>>>
>>>
>>
>>
>> I do not understand the problem.
>>
>> Of course password strenght is checked every time, and if it founds a
>> null/empty password it gives error back if password must have a
>> minimum lenght.
>>
>> Your patch instead permit to have null password even if strenght
>> policy would not allow it.
>>
>> Regards,
>>
>> Tonino
> The problem is is that vadduser.c can call vadduser() (in vpopmail.c)
> without a password. It does this in the situation where vadduser.c
> has had the options "-e" or "-n" passed to it, so if this is the case
> the password can't be checked againts the password strength rules.
> The underlying function vadduser() needs to be able to add a user with
> no password.
>
I realize additional controls are done before calling vadduser(); but I
personally would prefer an explicit parameter added to vadduser for
avoiding password check (it may be a further parameter having default =
"check").
It would make developers more protected against unwanted security bugs.
Regards,
Tonino
>
--
------------------------------------------------------------
Inter@zioni Interazioni di Antonio Nati
http://www.interazioni.it [email protected]
------------------------------------------------------------
!DSPAM:55f82abc41552085678254!
--------------030408010506080404020902
Content-Type: text/html; charset=iso-8859-15
Content-Transfer-Encoding: 8bit
<html>
<head>
<meta content="text/html; charset=iso-8859-15"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-cite-prefix">Il 15/09/2015 15:03, Drew Wells ha
scritto:<br>
</div>
<blockquote cite="mid:[email protected]" type="cite">
<meta content="text/html; charset=iso-8859-15"
http-equiv="Content-Type">
<div class="moz-cite-prefix">On 09/15/2015 11:00 AM, Tonix -
Antonio Nati wrote:<br>
</div>
<blockquote cite="mid:[email protected]" type="cite">
<meta content="text/html; charset=iso-8859-15"
http-equiv="Content-Type">
<div class="moz-cite-prefix">Il 15/09/2015 11:03, Drew Wells ha
scritto:<br>
</div>
<blockquote cite="mid:[email protected]"
type="cite">In vpopmail-5.5.0 there seems to be a bug in
vpopmail.c where the password strength is checked even if a
password isn't used (such as when -e is used to add the
encrypted password). Patch attached. <br>
<br>
<br>
<br>
</blockquote>
<br>
<br>
<font size="-1"><font face="Verdana">I do not understand the
problem.<br>
<br>
Of course password strenght is checked every time, and if it
founds a null/empty password it gives error back if password
must have a minimum lenght.<br>
<br>
Your patch instead permit to have null password even if
strenght policy would not allow it.<br>
<br>
Regards,<br>
<br>
Tonino</font></font><br>
</blockquote>
The problem is is that vadduser.c can call vadduser() (in
vpopmail.c) without a password. It does this in the situation
where vadduser.c has had the options "-e" or "-n" passed to it, so
if this is the case the password can't be checked againts the
password strength rules. The underlying function vadduser() needs
to be able to add a user with no password.<br>
<br>
</blockquote>
<br>
I realize additional controls are done before calling vadduser();
but I personally would prefer an explicit parameter added to
vadduser for avoiding password check (it may be a further parameter
having default = "check").<br>
It would make developers more protected against unwanted security
bugs.<br>
<br>
Regards,<br>
<br>
Tonino<br>
<br>
<br>
<blockquote cite="mid:[email protected]" type="cite">
</blockquote>
<br>
<br>
<pre class="moz-signature" cols="72">--
------------------------------------------------------------
Inter@zioni Interazioni di Antonio Nati
<a class="moz-txt-link-freetext" href="http://www.interazioni.it">http://www.interazioni.it</a> <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
------------------------------------------------------------
</pre>
!DSPAM:55f82abc41552085678254!
</body>
</html>
--------------030408010506080404020902--