Path: utzoo!utgpu!news-server.csri.toronto.edu!cs.utexas.edu!wuarchive!usc!julius.cs.uiuc.edu!rpi!uupsi!ping.chi.il.us!gorpong From: gorpong@ping.chi.il.us (Gordon C. Galligher) Newsgroups: comp.mail.mh Subject: post(8) setuid and MH 6.7 and -fcc +obox not working Keywords: post(8), MH 6.7 Message-ID: <1991Jan6.002942.5409@ping.chi.il.us> Date: 6 Jan 91 00:29:42 GMT Organization: The 23rd. Century Lines: 54 Below is the output from post -help, but now I want to give a little history lesson. I tried to get MH 6.7 up on an SCO UNIX 3.2 box (3.2.0, NOT 3.2.2) and had to use sendmail and not mmdf2 because SCO does not distribute the header files and the library file which MH seems to require (at least in the mh-gen listing it requires it). OK, so I use sendmail without the /smtp option. I make MH, and install it. Everything is fine. I go to post the message (via comp and What now? send) and it gives me an error [510]: only root, daemon, and mmdf may set host information OK. No major deal. It looks like post is attempting to tell sendmail that it is a specific user. So I make post setuid (maybe not a Real Good Idea, but now I can use MH), and things work, almost. If I use the Fcc: +obox in my components file, or the -fcc +obox on the command line to comp, repl, or forw, when post gets it, it correctly saves the file, BUT it keeps it owned by root! I cannot scan my +obox folder, I cannot do anything until I chown the files back to myself. Now, here are my questions: o Is making post setuid a Real Bad Idea? o It appears that either I have something set up incorrectly (which is VERY possible!), or I cannot use MH on SCO o If post can be setuid, then all of you get your ESP working and tell me what I did wrong! Any, and all information, helpful hints, snickering, etc., would be greatly appreciated! Thank you. -- Gordon. POST -HELP: =========== syntax: post [switches] file switches are: -alias aliasfile -filter filterfile -nofilter -[no]format -[no]msgid -[no]verbose -[no]watch -width columns -(help) version: MH 6.7 #13[UCI] (ping) of Thu Jan 3 21:28:46 CST 1991 options: [SYS5] [SYS5DIR] [DBM] [TYPESIG=void] [DUMB] [OVERHEAD] [ATZ] [RPATHS] [MHE] [MHRC] [DBM] [MORE='"/usr/bin/more"'] [SBACKUP='"#"'] [MSGPROT='"0600"'] [FOLDPROT='"0700"'] [SENDMTS] [SPRINTFTYPE=int] -- Gordon C. Galligher 9127 Potter Rd. #2E Des Plaines, IL 60016-4881 gorpong@ping.chi.il.us gorpong%ping@uu.psi.com ...!uu.psi.com!ping!gorpong "I know how it works....That's why I don't like it" -- Chip Salzenberg on SCO "UNIX" C2 Security Package