LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-27-2006, 06:23 PM   #1
piforever
Member
 
Registered: Dec 2005
Distribution: CentOS 5 - Debian 5
Posts: 112

Rep: Reputation: 15
Using PINE to read root mail


I just installed pine in my FC4 system. When I was younger it was the main application to read the messages....and since I access my system through runlevel 3....are there any security concerns regarding pine??? I use it to check my system's daily logs....

ThnX

Last edited by piforever; 02-27-2006 at 06:27 PM.
 
Old 02-27-2006, 07:26 PM   #2
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
If you're using sendmail, you can add an entry to /etc/mail/aliases (and rebuild the aliases database with newaliases) to deliver mail for root to an ordinary user so you don't need to worry about this. For example:
Code:
root: steve
Pine is a good product, but you shouldn't have to be root just to read mail.
 
Old 02-27-2006, 08:02 PM   #3
cambie
Member
 
Registered: Jul 2004
Posts: 90

Rep: Reputation: 15
Quote:
Originally Posted by gilead
If you're using sendmail, you can add an entry to /etc/mail/aliases (and rebuild the aliases database with newaliases) to deliver mail for root to an ordinary user so you don't need to worry about this. For example:
Code:
root: steve
Pine is a good product, but you shouldn't have to be root just to read mail.
is there a way to set this up, and then flush all the mail spooled up for a user to that alias?
 
Old 02-27-2006, 08:10 PM   #4
piforever
Member
 
Registered: Dec 2005
Distribution: CentOS 5 - Debian 5
Posts: 112

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by gilead
Pine is a good product, but you shouldn't have to be root just to read mail.
Thnx...I disabled root SSH access...so I login to the system as an ordinary user and then becomes a root by means of su...I'm afraid if I delivered the mail to a different user and that user was hacked then they will even see the root mail....sorry if this does not add up...i'm a n00b who recently started to manage a Linux box for learning purposes....
 
Old 02-27-2006, 08:45 PM   #5
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
You could use the following (where username is the name of an account on the box), but make sure you use the 2 greater than symbols to append since using just one will overwrite the file:
Code:
cat /var/spool/mail/root >> /var/spool/mail/username
I'd check the file /var/spool/mail/username afterwards though. Sometimes you see something like the following in an otherwise empty mailbox:
Code:
From MAILER-DAEMON Tue Feb 14 10:33:32 2006
Date: 14 Feb 2006 10:33:32 +1000
From: Mail System Internal Data <MAILER-DAEMON@host.domain.au>
Subject: DON'T DELETE THIS MESSAGE -- FOLDER INTERNAL DATA
Message-ID: <1139877212@host.domain.au>
X-IMAP: 1139283039 0000000005
Status: RO

This text is part of the internal format of your mail folder, and is not
a real message.  It is created automatically by the mail system software.
If deleted, important folder data will be lost, and it will be re-created
with the data reset to initial values.
piforever, I take your point that there's a risk of a user account being compromised and it is common to SSH in and su to perform admin tasks. My assumption was that you were su'ing to root purely to read your mail which would be overkill.

The rule of thumb is that the root account should be used as little as possible. The exceptions that everyone makes to this rule depend on the risk involved in their own situation - and my lunch break isn't long enough to open that particular debate
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
read mail root from thunderbird axelmang Linux - Newbie 5 11-22-2005 06:25 AM
How to read /var/spool/mail/root? neo_in_matrix Linux - Newbie 1 04-04-2005 08:49 PM
Pine 4.58 can't send mail cseanburns Linux - Software 10 12-24-2004 01:34 PM
PINE can't send mail dushkinup Linux - Software 0 04-09-2004 04:34 PM
pine is read only asad_javid Linux - General 1 06-05-2001 06:17 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:04 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration