John Doe wrote:
> Hello all,
>
> I have big problem with qmail-scanner.
> I use vpopmail with qmail. I setup qmail-scanner to run with user qscand but
> i have problems with permission and i
> change permisions to use as user vpopmail group vchkpw.
umm... why.. that's a Bad Idea. qmail-scanner runs as an entirely separate
user for a few very good reasons:
if, while breaking the email apart, an exploit is performed that attempts to
modify files on your filesystem, the qscand user should not have any
permission to do so, therefore the attempt is thwarted.
if, while running a virus scanner, an exploit is performed, again, nothing
will be affected (other than perhaps the qmail-scanner directories, which,
isn't mission critical if some of those files get completely destroyed, as
they can be regenerated, and any incoming emails that get destroyed will get
deferred and tried again)
now say, someone ran that exploit when you had qmail-scanner running as the
vpopmail user, or as root as you said you had done. There can be a very huge
impact on your system, and one that may not be easily recoverable.
I will not go forth and tell you how to solve the problem you're having,
simply because you should not attempt to do what you're doing.
-Jeremy
--
Jeremy Kitchen ++ Systems Administrator ++ Inter7 Internet Technologies, Inc.
jeremy@inter7.com ++
www.inter7.com ++ 866.528.3530 ++ 847.492.0470 int'l
kitchen @ #qmail #gentoo on EFnet ++ scriptkitchen.com/qmail