Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 8 Jun 1996 21:13:33 +0200 (MET DST)
From:      Mattias Pantzare <pantzer@ludd.luth.se>
To:        =?KOI8-R?Q?=E1=CE=C4=D2=C5=CA_=FE=C5=D2=CE=CF=D7?= <ache@astral.msk.su>
Cc:        pst@shockwave.com, security@FreeBSD.org
Subject:   Re: FreeBSD's /var/mail permissions
Message-ID:  <Pine.SUN.3.91.960608210807.3126A-100000@max.ludd.luth.se>
In-Reply-To: <199606080732.LAA00950@astral.msk.su>

next in thread | previous in thread | raw e-mail | index | archive | help
> > Why should adduser send any mail to anybody? Rather silly if you ask me.
> 
> Because bad guy can pre-create upcoming user mailbox with 666 permissions.

Not if the adduser script creates it. To remove the option on sending a mail
to the new user fills no function.







Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.SUN.3.91.960608210807.3126A-100000>