LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > *BSD
User Name
Password
*BSD This forum is for the discussion of all BSD variants.
FreeBSD, OpenBSD, NetBSD, etc.

Notices


Reply
  Search this Thread
Old 09-11-2004, 12:05 PM   #1
predrag
Member
 
Registered: Aug 2003
Location: Salzburg, Austria
Distribution: Ubuntu, CentOS, FreeBSD
Posts: 34

Rep: Reputation: 15
mount suid


Just how more insecure is it to mount /var on OpenBSD (3.5 patch) suid? It is mounted nosuid by default, but I could not manage to make vqadmin and qmailadmin work with /var mounted as nosuid.

Tnx.
 
Old 09-12-2004, 03:16 AM   #2
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
That means you're allowed to execute suid binaries and scripts on that partition, which can be particularly bad in the case of /var since that's where Apache and BIND live, and also the mail spool, cron spool, etc... All of those are potential vectors for attack. If an attacker manages to find an suid script on that partition, or an suid binary, and they can exploit it with a buffer overflow, or by forcing it to exectute commands of their choosing, you'll be rooted. Of all the partitions, /var is probably the one you least want to mount with suid allowed.

Is there a particular reason you want qmail? Postfix works great on OpenBSD and is well supported. It's easier to setup and use than Qmail and it has a native port (unlike Qmail). The OpenBSD Sendmail (installed by default) is also quite a bit more secure than the normal Sendmail, because the OpenBSD developers have hardened it a great deal (although it's still an exercize in frustration to try to edit the configuration).
 
Old 09-12-2004, 08:01 AM   #3
predrag
Member
 
Registered: Aug 2003
Location: Salzburg, Austria
Distribution: Ubuntu, CentOS, FreeBSD
Posts: 34

Original Poster
Rep: Reputation: 15
Yes, qmail comes with a set of useful apps for administration, namely vqadmin and qmailadmin. I need those, especially the possibility that users can setup autoreply messages from the web interface alone, that domain admins can add and modify users within their domains (from the web interface) etc.

I am also more than satisfied with postfix and have used it extensively. I now have a running system supporting virtual domains and all security/privacy related addons, but it seems unlikely to find a web interface that will enable the normal user to, say, mamange his own vacation message, the domain admin user to use the web interface to add/delete users, makes new forwards, delete the old ones etc. The postfix+courier imap+authuserdb works just perfectly for me and I need absolutely nothing more as far as the server itself is considered. But users here want comodity and I simply have to see to it that they get it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Suid only for one user? sti2envy Linux - Security 2 11-04-2004 09:43 PM
suid peculiarities navawatanasob Linux - Security 2 09-17-2004 06:42 PM
SUID C function untwisted Programming 10 03-22-2004 07:19 PM
SUID file drops suid bit on append? c_coder Programming 1 03-12-2004 07:59 AM
suid iptables john8675309 Linux - Software 5 01-26-2004 03:26 PM

LinuxQuestions.org > Forums > Other *NIX Forums > *BSD

All times are GMT -5. The time now is 03:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration