On Tue, 10 Aug 2010 15:17:33 -0700
Gary Funck <g...@intrepid.com> wrote:

> On 08/10/10 07:48:42, Stevan Bajić wrote:
> > Gary: And there I can see why it wouldn't be correct
> > Gary: to allow me to query all users unless I'm a trusted user.
> > Gary: But I can't even get at the stats for my own user id, when
> > Gary: I was able to generate the spam signature database in the
> > Gary: the first place?
> >
> > You know who created those tokens in the css database?
> > It was the binary dspam. Can you check and tell me if
> > the binary dspam is setuid or setgid? Probably it is while dspam_stats is 
> > not.
> 
> -r-x--s--x 1 dspam mail 104256 Jul 13 08:10 /usr/bin/dspam
> 
> Above, setgid on /usr/bin/dspam, group = mail.
>
See? It is setgid.


> Everything is mode 0755 and owner/group is root/root.
> 
What do you mean with everything? What everything?

btw: Is the lock now removed or is it still there?

------------------------------------------------------------------------------
This SF.net email is sponsored by 

Make an app they can't live without
Enter the BlackBerry Developer Challenge
http://p.sf.net/sfu/RIM-dev2dev 
_______________________________________________
Dspam-user mailing list
Dspam-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/dspam-user

Reply via email to