On Sun, Feb 15, 2004 at 10:40:53PM +0000, Mark Pratt wrote:
> When I run sophie (and ClamAV) as the user qscand, I receive the message as 
> shown below. If I run Sophie as root, the processing completes as normal 
> and the message is delivered. What appears to be happening is that the 
> message is dropped into a directory under /var/spool/qmailscan/tmp/ which 
> is chown-ed by root.qmail and chmod 700. Obviously, poor old qscand does 
> not have access to this directory and the scan fails.

You have a horribly broken install then.

Since when would Q-S *EVER* be doing anything as root!!!!

I bet your using that broken Qmail-Toaster install. It installs reformime as
setuid root - which means the message written into /var/spool/qmailscan/tmp/
is owned by root instead of qscand.

I can see why DJB has such issues with people creating distributions - total
loss of quality control...

EVERYTHING UNDER /var/spool/qmailscan SHOULD BE OWNED BY "qscand"


Anything that changes that is broken.

-- 
Cheers

Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1


-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click
_______________________________________________
Qmail-scanner-general mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general

Reply via email to