Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <3E86F44B.8040306@tagnet.ru>
Date: Sun, 30 Mar 2003 19:42:35 +0600
From: Boris Kovalenko <boris@...net.ru>
To:  popa3d-users@...ts.openwall.com
Subject: Re: virtual.c another question

Solar Designer wrote:

>On Sun, Mar 30, 2003 at 05:18:05PM +0600, Boris Kovalenko wrote:
>  
>
>>Solar Designer wrote:
>>    
>>
>>>On Sun, Mar 30, 2003 at 01:29:38PM +0600, Boris Kovalenko wrote:
>>>      
>>>
>>>>Why to run other code if we already know that user is invalid? Why lstat 
>>>>directory and try to open file for this "INVALID" user?
>>>>        
>>>>
>>>This is to reduce information leaks via timing.
>>>      
>>>
>>What type of information?
>>    
>>
>
>It's primarily whether a username corresponds to an existing mail
>account or not.
>
Hmm...You do not find it too difficult? And may be there is security 
hole? According to the code, we will check and read at least 
VIRTUAL_HOME_PATH/IP/VIRTUAL_AUTH_PATH/INVALID (with default settings it 
will be /vhome/ip/auth/INVALID). Someone may use this knowlege to 
compromise the whole system, or I'm paranoid?

>I'm afraid these discussions on programming topics are of no use to
>most popa3d-users subscribers.  If anyone is annoyed by them, please
>let me know and I'll be bringing them off-list in the future.
>  
>
I'm afraid too. But because I don't know your direct e-mail I need to 
write to the list.

P.S. Sorry if I'm not the first who asked about this. If so please point 
me to archive thread.

Boris



Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.