Caylan Van Larson | 1 Oct 2003 04:12
Favicon

Re: Safe Mode

> Always a dangerous combination.  Make sure you check everything for
> access restrictions, like where you save php session files, php 
> uploaded
> files, etc.  I don't allow logins to my Horde server just because of 
> such
> reasons.

Nor do I Eric.  This server processes ~/<username> requests from a 
mod_rewrite rule from our main non-student accessible server.  AFAIK, 
suexec, cgiwrap or sbox  that effectively chroots user processes 
protects the server from cgi scripts.  However, when php is thrown in 
(that is not protected with suexec/cgi-wrapper) how do you chmod the 
php.ini file so users can not read it using php (which runs as the www 
user)?  Isn't that why safe_mode was created?

> While your reason for putting safe_mode on was completely bogus

Am I missing something or did you just have a bad day?

Caylan

Caylan Van Larson
  Unix Administrator
   UND Aerospace

--

-- 
IMP mailing list
Frequently Asked Questions: http://horde.org/faq/
To unsubscribe, mail: imp-unsubscribe <at> lists.horde.org

(Continue reading)

Cory | 1 Oct 2003 06:30

Notice: Undefined index errors

Hi,
I've just installed imp and am getting numerous errors.  I have a feeling
they are all related somehow, but am too much of a notice at the moment to
figure it out..  Any help would be greatly appreciated.
At the login page I'm getting the following errors.

Notice: Undefined index: alternate_login in
/var/www/html/mail/horde/login.php on line 95
Warning: Cannot add header information - headers alread sent by (output
started at /var/www/html/mail/horde/imp/login.php:95) in
/var/www/html/horde/lib/Secret.php on line 144
Notice: Undefined index: server in /var/www/html/mail/horde/login.php on
line 142
Notice: Undefined index: server in
/var/www/html/mail/horde/imp/templates/login/login.inc on line 80
Notice: Undefined index: server in
/var/www/html/mail/horde/imp/templates/login/login.inc on line 83
Notice: Undefined index: server in
/var/www/html/mail/horde/imp/templates/login/login.inc on line 89
Notice: Undefined index: server in
/var/www/html/mail/horde/imp/templates/login/login.inc on line 127

After displaying all of the errors it prompts me to login, after
successfully logging in it allows me to get into my INBOX, however that
page has even more errors.

Once again, any help would be greatly appreciated..

Thanks in advance,

(Continue reading)

Eric Rostetter | 1 Oct 2003 06:40
Picon

Re: Safe Mode

Quoting Caylan Van Larson <caylan <at> aero.und.edu>:

> > Always a dangerous combination.  Make sure you check everything for
> > access restrictions, like where you save php session files, php
> > uploaded
> > files, etc.  I don't allow logins to my Horde server just because of
> > such
> > reasons.
>
> Nor do I Eric.  This server processes ~/<username> requests from a
> mod_rewrite rule from our main non-student accessible server.  AFAIK,

Yeah, I kind of mispoke there.  I meant to say, I don't allow user cgi,
user server side includes, or user scripting of any sort on the
server ;)  In other words, no users have access to put files on the
machine, and no user web pages exist on the server.

> suexec, cgiwrap or sbox  that effectively chroots user processes
> protects the server from cgi scripts.  However, when php is thrown in
> (that is not protected with suexec/cgi-wrapper) how do you chmod the
> php.ini file so users can not read it using php (which runs as the www
> user)?  Isn't that why safe_mode was created?

Like I said, in your situation (user pages on the same server) safe_mode
is a very good thing.  I avoid safe mode by not allowing users to any
kind of cgi/ssi/scripting on the machine.

> > While your reason for putting safe_mode on was completely bogus
>
> Am I missing something or did you just have a bad day?
(Continue reading)

Lord Apollyon | 1 Oct 2003 09:25

Re: Safe Mode


> how do you chmod the 
> php.ini file so users can not read it using php (which runs as the www 
> user)?  Isn't that why safe_mode was created?

Yes, precisely.  No, it's not a perfect "security solution", but like all
security OPTIONS, they exist within a layered model to make things
progressively more difficult for "Bad Things" to happen.

> > While your reason for putting safe_mode on was completely bogus
> 
> Am I missing something or did you just have a bad day?

Don't take it personally, as I suspect the US-based Horde team never have
"good days"... though Cranky Chuck(R) did wave hello across the Charles to
someone in Boston yesterday. 

Hey, I lived in the South End for eight years, does that count for
slightly-less-Crankiness?  

I didn't think so. :)  Ah well.

=Apollyon=

(R) Marca registrada not used with permission.

--

-- 
IMP mailing list
Frequently Asked Questions: http://horde.org/faq/
To unsubscribe, mail: imp-unsubscribe <at> lists.horde.org
(Continue reading)

Sam Bashton | 1 Oct 2003 09:29
Picon

Re: hardcoded admin account?

On Tue, Sep 30, 2003 at 10:30:22AM -0700, Steve McGhee wrote:
> 
> hi there,
> 
>   i have IMP installed on a server and noticed that i had a weak 
> password (admin/admin) and decided to change it.  after doing so, i 
> could still log in as (admin/admin) even though the IMAP server had been 
> updated.
>   i tried testing with another account (tester/password) which i 
> changed to (tester/newpass) which all worked fine (the old pass stopped 
> working immediately, as it should).
> 
>   is there any reason why this admin/admin account is still being 
> allowed to log in? some sort of cache in Horde?

Are you using ImapProxy?  This would produce exactly what you are describing,
in fact it's even in the FAQ:

http://www.kuleuven.net/projects/imapproxy/download/latest/docs/FAQ

-- 
Sam Bashton
Systems Administrator
IP Support 

--

-- 
IMP mailing list
Frequently Asked Questions: http://horde.org/faq/
To unsubscribe, mail: imp-unsubscribe <at> lists.horde.org

(Continue reading)

Jochen Roderburg | 1 Oct 2003 09:42
Picon
Favicon

Re: archiving mails

alois blasbichler wrote:
> 
>>>now i have seen this export function. a folder was saved like a file
>>>.mbox
>>>can i reimport this file with imp ?
>>
>>Yes.
> 
> 
> and how, i dont find any import-function 
> 

I would also be interested in an answer to this.

We are about to migrate out university mail system from a classic 
unix/uw-imap based system to a Cyrus system, and such an export/import 
capability would allow our IMP/Webmail users to transfer their mailboxes 
themselves with the system that they know.

Jochen Roderburg
ZAIK/RRZK
University of Cologne
Robert-Koch-Str. 10                 Tel.:   +49-221/478-7024
D-50931 Koeln                       E-Mail: Roderburg <at> rrz.Uni-Koeln.DE
Germany

--

-- 
IMP mailing list
Frequently Asked Questions: http://horde.org/faq/
To unsubscribe, mail: imp-unsubscribe <at> lists.horde.org
(Continue reading)

Favicon

Can i use option exchange serveur 5.5 ?

Hello,

I test horde+Imp in cvs mode, and i see in imp/config/server.php that an option for use an exchange server
5.5, and i know if i can use this option.
I have test, but that's not work, i don't now why my linux serveur can établish an authentification on a
microsoft exchange server.
 
Can you help me please ?

 <at> +

Accédez au courrier électronique de La Poste : www.laposte.net ; 
3615 LAPOSTENET (0,34€/mn) ; tél : 08 92 68 13 50 (0,34€/mn)

--

-- 
IMP mailing list
Frequently Asked Questions: http://horde.org/faq/
To unsubscribe, mail: imp-unsubscribe <at> lists.horde.org

Jan Schneider | 1 Oct 2003 11:35
Favicon
Gravatar

Re: archiving mails

Zitat von Jochen Roderburg <Roderburg <at> uni-koeln.de>:

> alois blasbichler wrote:
> >
> >>>now i have seen this export function. a folder was saved like a file
> >>>.mbox
> >>>can i reimport this file with imp ?
> >>
> >>Yes.
> >
> >
> > and how, i dont find any import-function
> >
>
> I would also be interested in an answer to this.
>
> We are about to migrate out university mail system from a classic
> unix/uw-imap based system to a Cyrus system, and such an export/import
> capability would allow our IMP/Webmail users to transfer their mailboxes
> themselves with the system that they know.

There is such a feature in the folder view, but probably only in the HEAD
version.

Jan.

--
http://www.horde.org - The Horde Project
http://www.ammma.de - discover your knowledge
http://www.tip4all.de - Deine private Tippgemeinschaft
(Continue reading)

Ahmed | 1 Oct 2003 11:50

Re: Attachments not saved in Drafts (IMP-CVS)

works, thanks.

also seems to have fixed the other 'odd problem' with the attachments not
sticking to outgoing mails.

Ahmed...

Quoting Chuck Hagenbuch sent on Tue 30 Sep 2003 22:22:55 BST

> > > when I try to save a draft of a message that has an attachment, the
> > > attachment seems to be missed in the saved message. The draft is
> > > saved to
> > > draft folder under cyrus 2.1.14 with the unseen flag.
>
> This should be fixed now.

--

-- 
IMP mailing list
Frequently Asked Questions: http://horde.org/faq/
To unsubscribe, mail: imp-unsubscribe <at> lists.horde.org

Ahmed | 1 Oct 2003 12:03

Intermittent message viewing problems (IMP-CVS)


I've been getting the following problem with increasing regularity:

when I click on a new unread message IMP will not display the message but
will display the notfication

"There was an error viewing the requested message"

and the view drops back to the last folder I was viewing before the current
one. For example, I move from inbox view to summary view then to lists.imp
folder click on a new message that has just arrived I get te above error
and the current folder view is the INBOX view not the lists.imp folder
view.

The behaviour is intermittant but consistent. It will disappear for a while
if I log out and log back in again.

Any ideas any one?

Setup:
 apache       : 1.3.27 (RH build)
 php          : 4.3.3 and 4.3.4RC1
 Horde+friends: CVS 30-09  <at>  23:00 GMT
 IMAP server  : cyrus 2.1.14

Ahmed...

--

-- 
IMP mailing list
Frequently Asked Questions: http://horde.org/faq/
(Continue reading)


Gmane