Date: Thu, 15 Jul 1999 17:54:21 +0100 From: Stuart Henderson <stuart@eclipse.net.uk> To: Khetan Gajjar <khetan@os.org.za> Cc: Stephane.Lentz@ansf.alcatel.fr, freebsd-isp@FreeBSD.ORG Subject: Re: sendmail virtusertable Message-ID: <378E123D.35210708@eclipse.net.uk> References: <Pine.BSF.4.02A.9907151744490.4870-100000@pleb.cs.uct.ac.za>
next in thread | previous in thread | raw e-mail | index | archive | help
> As it stands right now, because I partially trust the users > (there are only 4), they all have read/write access to the > master virtusertable, but it would be trivial to create > multiple input virtusertables, cat them together to create the > master inputfile and rebuild the database periodically. If you dig through the archives of this list, you'll find a discussion on this, basically, if you can't trust your users you need to do a little sanity checking. "cat | grep '@allowed-domain.com '" should show what I mean, although you would really want something more robust than this (far too easy to break :-) I would also recommend building your db files to a new file, and check they have built OK before using them for real (at very least make sure they're not zero bytes). To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-isp" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?378E123D.35210708>