LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-30-2008, 05:19 PM   #1
dombrowsky
Member
 
Registered: Dec 2005
Location: New York
Distribution: Debian/GNU
Posts: 235

Rep: Reputation: 31
root-owned files in Maildir, possible hack?


I run exim4, courrier-imap, and sqwebmail on my home server. For quite some time now, I've noticed a reoccurring file named "from" in my ${HOME}/Maildir/cur folder, owned and read/write only by root. I also notice, from time to time, root-owned files named "whatever" and "todd" in the same folder, which makes me think my machine might me compromised. They also have out-of-whack modification times.

I've disabled these three services, and the files have not re-appeared. I'm no security guru, but I don't even know where to start. Anyone have a clue as to where I should look first?

details:
Exim version 4.63 #1 built 20-Jan-2007 10:40:39
courier-imap 4.1.1.20060828-5
sqwebmail 0.53.3-5

thanks,

-dave
 
Old 10-31-2008, 08:23 PM   #2
dombrowsky
Member
 
Registered: Dec 2005
Location: New York
Distribution: Debian/GNU
Posts: 235

Original Poster
Rep: Reputation: 31
problem is in default procmail install for debian

I found the problem.

Debian-etch version of procmail installs a default /etc/procmailrc that is very confusing. It contains code that will write a Maildir/from, Maildir/todd (?!) and Maildir/whatever file if you do not comment it out. I have my own ~/.procmailrc, and wasn't aware that it was automatically processing /etc/procmailrc.

I love Debian, but -10 points for this obvious oversight.

-d
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to erase files owned by root? maiden2 Linux - Newbie 6 12-22-2007 07:44 PM
how to edit files owned by root? maiden2 Linux - Newbie 3 12-12-2007 12:32 PM
Editing files owned by root SiW Programming 5 07-31-2007 01:36 PM
all users have access to root owned files sakatola Linux - Security 2 07-22-2005 12:45 AM
vfat mount - all files are 'root' owned, but even root can't -WX d33pdream Linux - General 5 02-28-2003 02:38 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration