Two questions...

1. Have you tried running checkvpw from the command line to see what it says? Maybe you'll get a bit more information.

2. Is checkvpw suid root? Note that DJB's checkpassword needs to be suid root for Binc, which is fine because it takes great care to ensure the user has authenticated before executing a command. I haven't looked at checkvpw to see what it does to ensure that it can not be used to gain arbitrary access to your system.

Regards,
Henry


On Fri, 30 Apr 2004 13:11:23 -0700, Joe Zacky <[EMAIL PROTECTED]> wrote:


I also tried hardcoding the timestamp so the parameters were exactly the same as with pop3:

[pid 28659] read(3, "zackynet-jztest\0testpass\0<[EMAIL PROTECTED]>\0", 513) = 63

Still get the same error:

[EMAIL PROTECTED] bobsdb]$ telnet qmail.zackynet.com 143
Trying 10.200.1.2...
Connected to qmail.zackynet.com.
Escape character is '^]'.
* OK Welcome to Binc IMAP Copyright (C) 2002-2004 Andreas Aardal Hanssen at 2004-04-30 12:53:20 PDT
1 LOGIN zackynet-jztest testpass
1 NO LOGIN failed: Login failed. Either your user name or your password was wrong. Please try again, and if the problem persists, please contact your system administrator.


And this doesn't even address the 111 error code (shown in the binciimap log and in my first post) when I login using the [EMAIL PROTECTED] form:

[EMAIL PROTECTED] bobsdb]$ telnet qmail.zackynet.com 143
Trying 10.200.1.2...
Connected to qmail.zackynet.com.
Escape character is '^]'.
* OK Welcome to Binc IMAP Copyright (C) 2002-2004 Andreas Aardal Hanssen at 2004-04-30 13:08:04 PDT
1 LOGIN [EMAIL PROTECTED] testpass
* BYE The server died unexpectedly. Please contact your system administrator for more information.
Connection closed by foreign host.


So what does that leave: environment, pipes, files, permissions...? Maybe if I could debug checkvpw in a controlled environment using the environment values from the pop3d and bincimap strace. That sounds like a task for a Monday morning (sigh). Or maybe someone will find the answer over the weekend? Too hopeful?

Cheers,
Joe




-- Henry Baragar Principal, Technical Architecture 416-453-5626 Instantiated Software Inc. http://www.instantiated.ca

Reply via email to