i am new to procmail, but not to sendmail.
a number of years ago i replaced the Mprog in our sendmail config to
restrict the programs that could be run via a .forward file to a few
that i prescribed (vacation, etc...)
this was done to plug a security hole that later eric allman plugged
with a similar method.
from what i cat gather, procmail will allow a person to filter their
mail through an arbitary program. this reopens things i'd rather let
stay shut.
i would like to stop procmail from allowing users to push their mail
through any program they desire.
could someone point me to the appropriate docs, or tell how do acheive
this?
--
email: zaphod(_at_)zoology(_dot_)ubc(_dot_)ca box: Lance R. Bailey,
System/Network Admin
fax: +1 604 822 2416 Department of Zoology, UBC
vox: +1 604 822 6527 6270 University Boulevard
http://www.zoology.ubc.ca/~zaphod Vancouver, B.C. V6T 1Z4