|
Message-ID: <3E86F44B.8040306@tagnet.ru> Date: Sun, 30 Mar 2003 19:42:35 +0600 From: Boris Kovalenko <boris@...net.ru> To: popa3d-users@...ts.openwall.com Subject: Re: virtual.c another question Solar Designer wrote: >On Sun, Mar 30, 2003 at 05:18:05PM +0600, Boris Kovalenko wrote: > > >>Solar Designer wrote: >> >> >>>On Sun, Mar 30, 2003 at 01:29:38PM +0600, Boris Kovalenko wrote: >>> >>> >>>>Why to run other code if we already know that user is invalid? Why lstat >>>>directory and try to open file for this "INVALID" user? >>>> >>>> >>>This is to reduce information leaks via timing. >>> >>> >>What type of information? >> >> > >It's primarily whether a username corresponds to an existing mail >account or not. > Hmm...You do not find it too difficult? And may be there is security hole? According to the code, we will check and read at least VIRTUAL_HOME_PATH/IP/VIRTUAL_AUTH_PATH/INVALID (with default settings it will be /vhome/ip/auth/INVALID). Someone may use this knowlege to compromise the whole system, or I'm paranoid? >I'm afraid these discussions on programming topics are of no use to >most popa3d-users subscribers. If anyone is annoyed by them, please >let me know and I'll be bringing them off-list in the future. > > I'm afraid too. But because I don't know your direct e-mail I need to write to the list. P.S. Sorry if I'm not the first who asked about this. If so please point me to archive thread. Boris
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.