> The password should be in plain text in the file
> /usr/share/toaster/include/admin.pass

I just noticed that this file has 644 permissions. Shouldn't it be 600?
Probably admin.htpasswd as well. EE?

It doesn't really matter as '/usr/share/toaster/include' is 770, with
the user/group of apache.

In other words, nobody but apache and root can even get into the
directory to read stuff.

Erik

---------------------------------------------------------------------
    QmailToaster hosted by: VR Hosted <http://www.vr.org>
---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to