Serious Problem - db log file owner

Matthias Andree matthias.andree at gmx.de
Tue May 24 23:16:52 CEST 2005


David Relson <relson at osagesoftware.com> writes:

> On Tue, 24 May 2005 13:11:31 +0200
> Matthias Andree wrote:
>
>> David Relson <relson at osagesoftware.com> writes:
>> 
>> > What would happen if your system had a special group for running
>> > bogofilter, e.g. bogo, and used SGID for the bogofilter directory and
>> > bogofilter and bogoutil executables?
>> 
>> This should work, but provide no isolation whatsoever for users of this
>> group against each other - all users in the group must trust each other.
>
> It's more secure than using bogofilter as root, is it not?

One thing does not preclude the other, you need to make sure you're not
calling it as the root user.

-- 
Matthias Andree



More information about the Bogofilter mailing list