On 08/10/10 07:48:42, Stevan Bajić wrote:
> Gary: And there I can see why it wouldn't be correct
> Gary: to allow me to query all users unless I'm a trusted user.
> Gary: But I can't even get at the stats for my own user id, when
> Gary: I was able to generate the spam signature database in the
> Gary: the first place?
>
> You know who created those tokens in the css database?
> It was the binary dspam. Can you check and tell me if
> the binary dspam is setuid or setgid? Probably it is while dspam_stats is not.

-r-x--s--x 1 dspam mail 104256 Jul 13 08:10 /usr/bin/dspam

Above, setgid on /usr/bin/dspam, group = mail.
Everything is mode 0755 and owner/group is root/root.


------------------------------------------------------------------------------
This SF.net email is sponsored by 

Make an app they can't live without
Enter the BlackBerry Developer Challenge
http://p.sf.net/sfu/RIM-dev2dev 
_______________________________________________
Dspam-user mailing list
Dspam-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/dspam-user

Reply via email to