Next | qmail | 23 |
Suppose you could trick qmail-queue into running a command for you
So what?
You are now running a command as qmailq
qmailq has even less permission than you have
You can now write files into the qmail queue directory
You could do that anyway
Suppose you could trick qmail-remote into running a command for you
So what?
qmailr doesn't have any permissions anyway
Suppose you could trick qmail-send?
Maybe you could read or tamper with the queue
You might read some secret messages
That's bad, but it could be worse
If you trick sendmail into running a command, you have taken over the machine
Next | Copyright © 2004 M. J. Dominus |