Re: majordomo local exploit

From: John Archie (johnarchieat_private)
Date: Sat Jan 01 2000 - 20:45:20 PST

  • Next message: Justin Tripp: "HPUX Aserver revisited."

    I chgrp'ed the wrapper to mail (the user that sendmail demotes itself to in
    order to run the wrapper on my system) and do not allow normal users to
    execute the wrapper.  Majordomo works fine after the change, but this breaks
    anything that feeds input into the majordomo scripts directly that doesn't
    have permission to execute the wrapper.
    
    --John
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:25:35 PDT