Xref: utzoo comp.mail.misc:1998 comp.mail.elm:1685 Path: utzoo!attcan!uunet!mcvax!dik From: dik@cwi.nl (Dik T. Winter) Newsgroups: comp.mail.misc,comp.mail.elm Subject: Re: Re^2: Can I use the "filter" program? Probably. Keywords: elm filter smail sendmail Message-ID: <8206@boring.cwi.nl> Date: 19 Jun 89 23:30:05 GMT References: <778@cjsa.WA.COM> <1989Jun1.193715.908@ateng.ateng.com> <259@ethz-inf.UUCP> <867@cjsa.WA.COM> <596@Aragorn.dde.dk> Organization: CWI, Amsterdam Lines: 16 In article <596@Aragorn.dde.dk> tpo@dde.dk (Thomas Peter Sonne Olesen) writes: > Many mailers support a pipe feature in the aliases file - > lines with a syntax like : > > tpo |some-kind-of-program > > unfortunately this means that the filter program will be executed by > the user that sends the mail, which means that filter cannot determine > the HOME directory of the reciever. > If this command is executed by the user that sends the mail: disable the feature! This is a gigantic security hole. -- dik t. winter, cwi, amsterdam, nederland INTERNET : dik@cwi.nl BITNET/EARN: dik@mcvax