On Wed, 12 Nov 2003, Philipp Ringli wrote:

> mandrake 9.2 has msec installed. something very similar to tripwire.
> 
> i am having an interesting discussion in Xchat on 
> kornbluth.freenode.net channel #Mandrake.
> 
> here's an excerpt:
> 
> cmyk: i think.. if a normal user can execute a app that only root can.. 
> thats bad..
>       <Roobarb-Work>  SUID means it runs with root privilages. if someonr 
> hacks your mail server, they have root.
>       <cmyk>  hrm...
>       <cmyk>  are you 100% sure about that?
>       <Redgore>       he is right
>       <cmyk>  poll?
>       <cmyk>  :)
>       <noaxess>       cmyk: they are right..
>       <cmyk>  shut up. you have no axess... :-b
>       <noaxess>       :)
>       <cmyk>  ok. i'll reformulate my qustion then...
>       <cmyk>  what could i do, that xmail wouldn't need to run that scritp as 
> root?
> 
> what do you say about all this?

Hmm ... don't they have a MILF chat-room? :)
Seriously, sendmail.xmail is *not* the server. Is a stupid program that 
drops stuff inside spool/local. XMail runs as root too, but you can run it 
as non root if you want (see XMail home page, there should be a link).



- Davide


-
To unsubscribe from this list: send the line "unsubscribe xmail" in
the body of a message to [EMAIL PROTECTED]
For general help: send the line "help" in the body of a message to
[EMAIL PROTECTED]

Reply via email to