Re: [SPAM] Password strength bug

Drew Wells <[email protected]> Thu, 17 Sep 2015 12:18:58 +0100
Newsgroups gmane.mail.vpopmail
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------060101000803050007040905
Content-Type: text/plain; charset=iso-8859-15; format=flowed
Content-Transfer-Encoding: 7bit

On 09/15/2015 03:27 PM, Tonix - Antonio Nati wrote:
> Il 15/09/2015 15:03, Drew Wells ha scritto:
>> On 09/15/2015 11:00 AM, Tonix - Antonio Nati wrote:
>>> Il 15/09/2015 11:03, Drew Wells ha scritto:
>>>> In vpopmail-5.5.0 there seems to be a bug in vpopmail.c where the 
>>>> password strength is checked even if a password isn't used (such as 
>>>> when -e is used to add the encrypted password).  Patch attached.
>>>>
>>>>
>>>>
>>>
>>>
>>> I do not understand the problem.
>>>
>>> Of course password strenght is checked every time, and if it founds 
>>> a null/empty password it gives error back if password must have a 
>>> minimum lenght.
>>>
>>> Your patch instead permit to have null password even if strenght 
>>> policy would not allow it.
>>>
>>> Regards,
>>>
>>> Tonino
>> The problem is is that vadduser.c can call vadduser() (in vpopmail.c) 
>> without a password.  It does this in the situation where vadduser.c 
>> has had the options "-e" or "-n" passed to it, so if this is the case 
>> the password can't be checked againts the password strength rules.  
>> The underlying function vadduser() needs to be able to add a user 
>> with no password.
>>
>
> I realize additional controls are done before calling vadduser(); but 
> I personally would prefer an explicit parameter added to vadduser for 
> avoiding password check (it may be a further parameter having default 
> = "check").
> It would make developers more protected against unwanted security bugs.
>
> Regards,
>
> Tonino
>
I agree that it would be better to explicitly indicate to vadduser() 
that no password is wanted.  I even looked quicky at setting the 
password to NULL to indicate no password, but both this and an explicit 
parameter would need changes to all the backends, so have left it as is 
for now.


!DSPAM:55faa1a741551399290072!

--------------060101000803050007040905
Content-Type: text/html; charset=iso-8859-15
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta content="text/html; charset=iso-8859-15"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix">On 09/15/2015 03:27 PM, Tonix - Antonio
      Nati wrote:<br>
    </div>
    <blockquote cite="mid:[email protected]" type="cite">
      <meta content="text/html; charset=iso-8859-15"
        http-equiv="Content-Type">
      <div class="moz-cite-prefix">Il 15/09/2015 15:03, Drew Wells ha
        scritto:<br>
      </div>
      <blockquote cite="mid:[email protected]" type="cite">
        <meta content="text/html; charset=iso-8859-15"
          http-equiv="Content-Type">
        <div class="moz-cite-prefix">On 09/15/2015 11:00 AM, Tonix -
          Antonio Nati wrote:<br>
        </div>
        <blockquote cite="mid:[email protected]"
          type="cite">
          <meta content="text/html; charset=iso-8859-15"
            http-equiv="Content-Type">
          <div class="moz-cite-prefix">Il 15/09/2015 11:03, Drew Wells
            ha scritto:<br>
          </div>
          <blockquote cite="mid:[email protected]"
            type="cite">In vpopmail-5.5.0 there seems to be a bug in
            vpopmail.c where the password strength is checked even if a
            password isn't used (such as when -e is used to add the
            encrypted password).  Patch attached. <br>
            <br>
            <br>
            <br>
          </blockquote>
          <br>
          <br>
          <font size="-1"><font face="Verdana">I do not understand the
              problem.<br>
              <br>
              Of course password strenght is checked every time, and if
              it founds a null/empty password it gives error back if
              password must have a minimum lenght.<br>
              <br>
              Your patch instead permit to have null password even if
              strenght policy would not allow it.<br>
              <br>
              Regards,<br>
              <br>
              Tonino</font></font><br>
        </blockquote>
        The problem is is that vadduser.c can call vadduser() (in
        vpopmail.c) without a password.  It does this in the situation
        where vadduser.c has had the options "-e" or "-n" passed to it,
        so if this is the case the password can't be checked againts the
        password strength rules.  The underlying function vadduser()
        needs to be able to add a user with no password.<br>
        <br>
      </blockquote>
      <br>
      I realize additional controls are done before calling vadduser();
      but I personally would prefer an explicit parameter added to
      vadduser for avoiding password check (it may be a further
      parameter having default = "check").<br>
      It would make developers more protected against unwanted security
      bugs.<br>
      <br>
      Regards,<br>
      <br>
      Tonino<br>
      <br>
    </blockquote>
    I agree that it would be better to explicitly indicate to vadduser()
    that no password is wanted.  I even looked quicky at setting the
    password to NULL to indicate no password, but both this and an
    explicit parameter would need changes to all the backends, so have
    left it as is for now.<br>
  
!DSPAM:55faa1a741551399290072!

</body>
</html>



--------------060101000803050007040905--