Post by Raoul BhatiaPost by Sven HartgePost by Marc AymerichOne thing that I'm not quite sure about is how to deal with user
provided procmails, since the process which executes them has
privileges for all vmailboxes, this sounds like a security problem.
Perhaps I'm mistaken or missing something here. Do you guys need to
provide this kind of service on your mail servers (user provider
procmail or sieve) ?
Solution is simple: don't provide procmail as filtering solution, use
Sieve to allow users to filter their mails.
AFAIRC there is a virtual uid mapping available which can query a database, LDAP etc..
Still: procmail is "evil" and full of security nightmares if you try to
use it inside a virtual user context.
It was initially built to be used from the .forward file of a user and
to be run as the specific user the mail was delivered to.
And then there is the problem of how to allow users to provide their own
procmailrc. Because procmail is so powerful and its configuration syntax
is so complex, it will be very difficult to write a parser to detect a)
malformed config files and b) harmful config files.
Of course you can write a very simple web interface, only allowing
filtering of mails by specific criteria into specific folders, thus
limiting the attack vectors by limiting the used features of procmail.
But then you may also use Sieve in the first place, which provides a
well-defined protocol to allow the users to securely update the filter
file themselves.
Sieve on the other hand was designed with virtual users in mind. If
implemented correctly, no user is able to write to a different mailbox
than his own. Also per default you cannot execute any commands on the
host and also limit the possibility to redirect mails to other
(external) mail-adresses.
All in all: procmail is dead (at least in a virtual user multi hosting
scenario), all hail Sieve!
Grüße,
Sven.
--
Sigmentation fault. Core dumped.
--
To UNSUBSCRIBE, email to debian-isp-***@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact ***@lists.debian.org
Archive: https://lists.debian.org/***@mids.svenhartge.de