Subject: Re: Bug#854286: cyrus-imapd: cyrus user has a working shell. Date:
Tue, Feb 07, 2017 at 04:47:21PM +0100 Quoting Ondřej Surý (ond...@sury.org):
> Let's see:
> https://lists.andrew.cmu.edu/pipermail/cyrus-devel/2017-February/004000.html
Excellent!
> (Also p
er.cz/) – secure, privacy-aware,
fast DNS(SEC) resolver
Vše pro chleba (https://vseprochleba.cz) – Mouky ze mlýna a potřeby pro
pečení chleba všeho druhu
On Tue, Feb 7, 2017, at 16:04, Måns Nilsson wrote:
> Subject: Re: Bug#854286: cyrus-imapd: cyrus user has a working shell.
> Date: Tue, Feb 07,
Control: tags -1 +moreinfo
Hi Mans,
the cyrus user is created with disabled credentials:
adduser --quiet --system --ingroup mail --home /var/spool/cyrus
\
--shell /bin/sh --no-create-home --disabled-password \
--gecos "Cyrus Mailsystem User" cyrus >/dev/nul
Package: cyrus-imapd
Version: cyrus-imapd
Severity: important
Tags: patch
Dear Maintainer,
* What led up to the situation?
I was owned by a cracker that explited the fact that cyrus has /bin/sh
as shell
* What exactly did you do (or not do) that was effective (or
ineffective)?
I'd s
4 matches
Mail list logo