On Wednesday, December 10, 2003, at 07:29 PM, John Johnson wrote:
It worked just fine before the code was changed. Now it's a problem it was
not in the older versions so
this tells me that there is no big chore to not break tmda in the .qmail
files

I can't recall if or how it worked in 1.0.6. I do know that when it worked in the development releases, it allowed users to put ANYTHING in their .qmail file which is a bit of a security problem. vdelivermail is running as vpopmail, so it would be possible for a malicious user to do things up to and including deleting ~vpopmail.


How do normal qmail installs handle this? I assume that qmail-local usually runs as root and does a setuid() to the user's account before processing their .qmail file.

--
Tom Collins  -  [EMAIL PROTECTED]
QmailAdmin: http://qmailadmin.sf.net/  Vpopmail: http://vpopmail.sf.net/
Info on the Sniffter hand-held Network Tester: http://sniffter.com/




Reply via email to