Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

disabling PMDF Messagestore accounts

2 views
Skip to first unread message

Richard Loken

unread,
Dec 15, 2008, 12:23:56 PM12/15/08
to
Good morning all,

One of our users graciously gave her Messagestore account password to a
spammer who spent the weekend using our system via Squirrelmail to send
out a few hundred thousand spams.

I found this out yesterday as I was leaving for an appointment and disusered
the guily account which appears to have had no effect at all since the
logs show that the spammer continued to log in unimpeded all night.

We authenticate to Messagestore with LDAP. Does the disuser flag have no
effect if authentication is done with LDAP????

I'm getting tired of squirrelmail...

--
Richard Loken VE6BSV, Unix System Administrator : "Anybody can be a father
Athabasca University : but you have to earn
Athabasca, Alberta Canada : the title of 'daddy'"
** rich...@admin.athabascau.ca ** : - Lynn Johnston

Valerie Miller

unread,
Dec 15, 2008, 12:46:15 PM12/15/08
to
>We authenticate to Messagestore with LDAP. Does the disuser flag have no
>effect if authentication is done with LDAP????

(I assume you mean you've configured security.cnf to authenticate usernames
and passwords using the LDAP authentication source.)

Yes, that is correct. Security.cnf does not know that the username and
password that it is authenticating refers to a msgstore account or some
other kind of account. All it knows is it has a username string and a
password string and a list of authentication sources to use to check them.

Valerie Miller
Process Software

Richard Loken

unread,
Dec 15, 2008, 1:38:42 PM12/15/08
to
On Mon, 15 Dec 2008, Valerie Miller wrote:

> Yes, that is correct. Security.cnf does not know that the username and
> password that it is authenticating refers to a msgstore account or some
> other kind of account. All it knows is it has a username string and a
> password string and a list of authentication sources to use to check them.

Alas, more is the pity. Anyway, I have gone to the gods of authentication
and received permission and access to change the password for recalcicrant
users so I can better attack these problems in the future.

0 new messages