Great Circle Associates Majordomo-Workers
(June 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: your mail
From: dwolfe @ risc . sps . mot . com (Dave Wolfe)
Date: Thu, 8 Jun 1995 09:02:43 -0500 (CDT)
To: uunet!mathcs.duq.edu!mothibi
Cc: majordomo-users @ greatcircle . com (Majordomo user's mailing list), majordomo-workers @ greatcircle . com (Majordomo developer's mailing list)
In-reply-to: <Pine.3.89.9506071424.A20941-0100000@agnesi> from "Elvidge Mothibi" at Jun 7, 95 06:44:37 pm
Reply-to: David Wolfe <david_wolfe @ risc . sps . mot . com>

[ copied to majordomo-workers for discussion of security issues raised ]

[ Elvidge Mothibi writes: ]
> 
> I am running a mailing list (using majordomo 1.93, perl 4.036) on system V, 
> and after making changes to archive files (that is, files retreivable by the 
> GET command), if I try to execute the CHOWN and CHGRP commands, I get error
> messages. 

Some systems comply with POSIX and don't allow anyone other than root
to change the owner uid of files. Similarly, a user must be a member of
the target group or root to change the owner gid of a file.

I ran into a similar problem on SVR4 and ended up changing wrapper.c to
renounce all but POSIX_GID and mail (instead of all but POSIX_GID) so
that things run under wrapper could chgrp() to mail so that sendmail
could read the files (owned by gid mail) without allowing world access
to the file. It's a potential system security issue, but probably better
than mj *running* as gid mail or allowing world access to my mail lists.

-- 
 Dave Wolfe    *Not a spokesman for Motorola*  (512) 891-3246
 Motorola MMTG  6501 Wm. Cannon Dr. W. OE112  Austin  TX  78735-8598

Indexed By Date Previous: More private lists.
From: Andy Whitcroft <andy@cs.city.ac.uk>
Next: HOSTILE ADDRESSes
From: John Relph <relph@presto.ig.com>
Indexed By Thread Previous: More private lists.
From: Andy Whitcroft <andy@cs.city.ac.uk>
Next: HOSTILE ADDRESSes
From: John Relph <relph@presto.ig.com>

Google
 
Search Internet Search www.greatcircle.com