Sim Zacks wrote:
Are there any server-side security possibilities involved in dbmail?
For example, is it at all possible that a received email attachment
will actually execute on the server? Or could a mail with specific
headers cause the dbmail to execute shell commands or run an application?
I'm trying to decide if it makes sense to put the dbmail on my
production server or if I should lock it down on its own server.
Thank you
Sim
Its the same as with any server type software. A buffer overflow or some
other kind of weakness may exist that will potentially allow somebody to
pw0nz j00r b0x. But thats no different to apache or mysql.
Nothing in dbmail needs root access or even file system access (write)
as i understand it though. It should run chrooted pretty easily,
alternately stick it in a virtual machine somewhere if your really worried.
_______________________________________________
DBmail mailing list
[email protected]
https://mailman.fastxs.nl/mailman/listinfo/dbmail