paths and permissions

Eric Wood eric at interplas.com
Mon Feb 23 17:16:32 CET 2004


David Relson wrote:
> -rwsr-sr-x    1 root     mail        72536 Jul 11  2003 /usr/bin/procmail*

On newer RH's boxes I get:
-rwxr-xr-x    1 root     root        95400 Dec 12 22:54
/usr/sbin/sendmail.postfix
-rwxr-sr-x    1 root     smmsp      734432 Dec 13 00:15
/usr/sbin/sendmail.sendmail
-rwxr-xr-x    1 root     mail        80064 Dec 12 23:01 /usr/bin/procmail

Users can't simply run them get setuid priveleges.   I'm really suspect of
your procmail attributes.  Wouldn't that mean any user can write a recipe
and blow away any file on the system using your procmail binary!?

MTA's (ie, postfix and sendmail) do have to run as root (called by root) in
order to read everyones .foward files.

-Eric Wood





More information about the Bogofilter mailing list