[imp] BUG?

Steven Stern sds-email-list at mindspring.com
Sun Jan 11 11:23:50 PST 2004


On Sun, 11 Jan 2004 12:46:32 -0500, Chuck Hagenbuch <chuck at horde.org> wrote:

>Quoting Steven Stern <sds-email-list at mindspring.com>:
>
>> Wouldn't it make more sense to patch mailbox.php to prevent opening a mailbox
>> that's not on the folders list?
>
>No, no, no. First of all, there's a *ton* of history on this in the list
>archives from years back. Second, this would be an entirely artificial, false
>sense of security. If you don't want your IMAP server reading random files off
>of the filesystem, FIX YOUR IMAP SERVER. Period.
>
>-chuck
>
>--
>Charles Hagenbuch, <chuck at horde.org>
>"Here, I brought some cole slaw. It's made from peeeooople! Just kidding."

Well, never mind. I replaced imapd and qpopper with DoveCot (via up2date
dovecot) and it's now working as I like. There's no longer any access to the
/etc/passwd file.


More information about the imp mailing list