Running as root

Ugo Bellavance ugob at camo-route.com
Thu Jan 26 18:17:37 GMT 2006


Matt Kettler wrote:
> Julian Field wrote:
>> On 26 Jan 2006, at 15:02, Darryl DeLao wrote:
>>
>>> Is there any dangers to running MailScanner as root?  What user should
>>> it run under?
>>>
>> It needs to run as the same user as your MTA. It does not interact with
>> the outside world at all (that's the job of your MTA) so root is pretty
>> safe.
> 
> Unless of course your AV has a security flaw which can be exploited by feeding
> it malformed data. Many AV products have recently had fixes for such holes in
> their handling of various compressed or "encrypted" executables.
> 

Here is a recent one:

http://www.f-secure.com/security/fsc-2006-1.shtml

-- 
Ugo

-> Please don't send a copy of your reply by e-mail.  I read the list.
-> Please avoid top-posting, long signatures and HTML, and cut the
irrelevant parts in your replies.



More information about the MailScanner mailing list