[13184] in bugtraq

home help back first fref pref prev next nref lref last post

Re: majordomo local exploit

daemon@ATHENA.MIT.EDU (John Archie)
Sun Jan 2 15:38:55 2000

Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Message-Id:  <006b01bf54dc$2d174020$0400a8c0@emeraldis.com>
Date:         Sat, 1 Jan 2000 23:45:20 -0500
Reply-To: John Archie <johnarchie@MAIL.EMERALDIS.COM>
From: John Archie <johnarchie@MAIL.EMERALDIS.COM>
To: BUGTRAQ@SECURITYFOCUS.COM

I chgrp'ed the wrapper to mail (the user that sendmail demotes itself to in
order to run the wrapper on my system) and do not allow normal users to
execute the wrapper.  Majordomo works fine after the change, but this breaks
anything that feeds input into the majordomo scripts directly that doesn't
have permission to execute the wrapper.

--John

home help back first fref pref prev next nref lref last post