Jürgen Hoffmann wrote: > > hi > > how about sqwebmail running as vpopmail ? It doesn't do that because it knows nothing about vpopmail (as Mr. Sam would say). SqWebmail setuid to the owner of the mailbox which you're trying to read. If the mailbox is owned by 'qmails' user, it'll setuid to that. If it is owned by 'jh' it'll setuid to 'jh'. > > just my 2 cents > > Juergen Hoffmann > > Dan Phoenix writes: > > > > > yes it needs suid root...how else is it going to create files in vpopmail > > dir. Another thought is running webserver with uid of vpopmail. > > > > > > On Mon, 8 Jan 2001, Murat Ilker Balaban wrote: > > > > > Date: Mon, 8 Jan 2001 16:15:38 +0200 > > > From: Murat Ilker Balaban <[EMAIL PROTECTED]> > > > To: [EMAIL PROTECTED] > > > Subject: sqwebmail installed suid-root > > > > > > > > > Hi, I am planning to move my production mailserver from sendmail to > > > qmail+vchkpw, and thus installed sqwebmail today. > > > However, I was thrilled to see the suid-root sqwebmail binary in my > > > cgi-bin. > > > > > > Is this the default installation, or did I do smth wrong? > > > - or - > > > is there any incidences of break-in to a mailserver with the help > > > of this-suid-root binary. > > > > > > I wanted to know your opinions about this issue, > > > Thanx... > > > > > > > > > [root@mailhub templates]# ls -l /usr/local/apache/cgi-bin/ > > > total 608 > > > -rwsr-xr-x 1 root root 299912 Jan 8 15:35 sqwebmail > > > [root@mailhub templates]# > > > > > > > > > -- Murat Balaban > > > > > -- -------------------------------------------------------------------- Daniel Augusto Fernandes (DAF tm) [EMAIL PROTECTED] GCSNet http://www.gcsnet.com.br/ -------------------------------------------------------------------- Se você não encontra o sentido das coisas é porque este não se encontra, se cria. Antoine Saint-Exupéry
