spamassassin a possible security risk?

Thomas Zehetbauer thomasz at hostmaster.org
Tue Oct 19 12:50:40 UTC 2004


On Mon, 2004-10-18 at 21:36 -0500, John Thompson wrote:
> Not on my FreeBSD machine:
> 
> Oct 18 21:27:30 amayatra spamd[51657]: info: setuid to root succeeded
> Oct 18 21:27:30 amayatra spamd[51657]: Still running as root: user not
> specified with -u, not found, or set to root.  Fall back to nobody.

Looks like you are ignoring two important security recommendations:
1.) never work as root
2.) root get's no mail

Tom

-- 
  T h o m a s   Z e h e t b a u e r   ( TZ251 )
  PGP encrypted mail preferred - KeyID 96FFCB89
      finger thomasz at hostmaster.org for key

Those, who are willing to give up essential liberty
for the sake of short-term security
deserve neither liberty nor security.
                                - Benjamin Franklin



-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 481 bytes
Desc: This is a digitally signed message part
URL: <http://listman.redhat.com/archives/fedora-list/attachments/20041019/b2786b7a/attachment-0001.sig>


More information about the fedora-list mailing list