From mboxrd@z Thu Jan 1 00:00:00 1970 X-Msuck: nntp://news.gmane.io/gmane.emacs.gnus.general/9830 Path: main.gmane.org!not-for-mail From: Rich Pieri Newsgroups: gmane.emacs.gnus.general Subject: Re: Starnge bug. Date: 06 Feb 1997 15:52:29 -0500 Message-ID: References: NNTP-Posting-Host: coloc-standby.netfonds.no X-Trace: main.gmane.org 1035149796 20811 80.91.224.250 (20 Oct 2002 21:36:36 GMT) X-Complaints-To: usenet@main.gmane.org NNTP-Posting-Date: Sun, 20 Oct 2002 21:36:36 +0000 (UTC) Return-Path: Original-Received: from ifi.uio.no (0@ifi.uio.no [129.240.64.2]) by deanna.miranova.com (8.8.5/8.8.5) with SMTP id NAA18265 for ; Thu, 6 Feb 1997 13:10:10 -0800 Original-Received: from londo.asds.com ([199.103.216.62]) by ifi.uio.no with ESMTP (8.6.11/ifi2.4) id for ; Thu, 6 Feb 1997 21:53:16 +0100 Original-Received: from gkar.asds.com (gkar.asds.com [111.17.19.1]) by londo.asds.com (8.8.4/8.8.4) with ESMTP id PAA28135 for ; Thu, 6 Feb 1997 15:52:33 -0500 Original-Received: (from ratinox@localhost) by gkar.asds.com (8.8.4/8.8.4) id PAA20078; Thu, 6 Feb 1997 15:52:33 -0500 Original-To: ding@ifi.uio.no In-Reply-To: Carsten Leonhardt's message of 06 Feb 1997 17:54:09 +0100 Original-Lines: 32 X-Mailer: Gnus v5.4.11/Emacs 19.34 Xref: main.gmane.org gmane.emacs.gnus.general:9830 X-Report-Spam: http://spam.gmane.org/gmane.emacs.gnus.general:9830 -----BEGIN PGP SIGNED MESSAGE----- >>>>> "Leo" == Carsten Leonhardt writes: Leo> I solved with by making movemail setgid mail. You'll have to decide Leo> for yourself if movemail is secure enough for that. It would be easy to argue that it is not, since there is no security or authentication involved in movemail. It would be trivial for someone to use this to overwrite other files writable by group mail. What I prefer to do is to make the mail spool directory mode 777 and +t, which allows anyone to write there but not delete any files they do not own, similar to /tmp. The sysmonster needs to keep an eye on it, though, to prevent people from using it as /tmp... or a script that deletes any file with a name that is not equal to the file's owner. -----BEGIN PGP SIGNATURE----- Version: 2.6.3a Charset: noconv iQCVAwUBMvpEj56VRH7BJMxHAQGAxgP/YMIdfLDjIagBUh2C9rR0let2jJgd+CEl D16JxwqCQy8mZyiyGXVU+VfIW06aF7H8mSwyK3MDJE+rSD9B0e6Y8PAhP4sRY2UR t7Dk0Iix7EfnDAz1NQRTCRHbbNxe8BnK7KhsjPU89QAymNirRGKooKRPC0H4Wj8s wqZw2Yv3iAo= =Hqb5 -----END PGP SIGNATURE----- -- Rich Pieri | Happy Fun Ball may stick to certain Prescient Technologies, Inc. | types of skin. A Stone & Webster Company | I speak for myself, not PTI or SWEC |