Gentoo Archives: gentoo-hardened

From: Matt Poletiek <chill550@×××××.com>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Recomended paxctl flags for /var/qmail/bin/qmail-smtpd
Date: Tue, 23 Oct 2007 07:17:04
Message-Id: 1d624cdd0710230015t2a14c24anb73d2c986e8c3eb4@mail.gmail.com
1 Hey guys, I was attempting to write a plugin for my qmail-spp enabled
2 netqmail package when I ran into the following issue...
3
4 hackdmz control # nc localhost 25
5 220 hackdmz.net ESMTP
6 ehlo test
7 250-hackdmz.net
8 250-STARTTLS
9 250-PIPELINING
10 250-8BITMIME
11 250-SIZE 0
12 250 AUTH LOGIN PLAIN
13 mail from test@×××××××.net
14 250 ok
15 rcpt to test@×××××××.net
16 451 qmail-spp failure: plugins/validuser.pl: can't execute (#4.3.0)
17
18 This shows up in dmesg
19
20 grsec: From ***.***.***.***: denied untrusted exec of
21 /var/qmail/plugins/validuser.pl by
22 /var/qmail/bin/qmail-smtpd[qmail-smtpd:7451] uid/euid:201/201
23 gid/egid:200/200, parent /var/qmail/bin/qmail-smtpd[qmail-smtpd:7438]
24 uid/euid:201/201 gid/egid:200/200
25 grsec: From ***.***.***.***: denied untrusted exec of
26 /var/qmail/plugins/validuser.pl by
27 /var/qmail/bin/qmail-smtpd[qmail-smtpd:7861] uid/euid:201/201
28 gid/egid:200/200, parent /var/qmail/bin/qmail-smtpd[qmail-smtpd:7860]
29 uid/euid:201/201 gid/egid:200/200
30
31 I tried a few different pax flag settings for
32 /var/qmail/bin/qmail-smtpd to no avail so for now this binary is set
33 to default, which seem too lax to me. What do you guys think?
34
35 hackdmz control # cd /var/qmail/bin/
36 hackdmz bin # paxctl -v qmail-smtpd
37 PaX control v0.4
38 Copyright 2004,2005,2006 PaX Team <pageexec@××××××××.hu>
39
40 - PaX flags: -------x---- [qmail-smtpd]
41 RANDEXEC is disabled
42
43 --
44 Matthew Poletiek
45 www.chill-fu.net
46 --
47 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Recomended paxctl flags for /var/qmail/bin/qmail-smtpd Adam James <atj@××××××××××××××.uk>