paths and permissions

David Relson relson at osagesoftware.com
Fri Feb 27 16:33:36 CET 2004


On Fri, 27 Feb 2004 09:56:07 -0600 (CST)
Jesse Trucks wrote:

> I believe this operation happens due to elevated privileges in the
> process that delivers mail. The reason is that mail comes in and is
> processed by the mail server and it has to have permissions to write
> to any user's mail file. Therefore, it has root privileges. Those
> expanded rights allow the process to write to the wordlist.db file.

Hi Jesse,

Sounds right.  Since that posting, I learned that procmail runs suid. 
It's been pointed out that that's potentially dangerous since users can
have their own .procmailrc files.

David




More information about the Bogofilter mailing list