Bugtraq mailing list archives

Re: majordomo local exploit


From: johnarchie () MAIL EMERALDIS COM (John Archie)
Date: Sat, 1 Jan 2000 23:45:20 -0500


I chgrp'ed the wrapper to mail (the user that sendmail demotes itself to in
order to run the wrapper on my system) and do not allow normal users to
execute the wrapper.  Majordomo works fine after the change, but this breaks
anything that feeds input into the majordomo scripts directly that doesn't
have permission to execute the wrapper.

--John


Current thread: