users can see each other

Hi and congratulations for this software and for the contribution to open source.

Last 2 weeks I’ve been installing and uninstalling several different control panels available on the internet, after some headecks and 'cause i know webmin for a long time I decided to try the free version of this software.

I use outside DNS management and use this software to have our almost 30 domains on our own server. It seems that we’ll be using this CP and give up on all others.

Anyway I found 3 errors one of it very urgent to be solved by you guys, at least I don’t find anything on the foruns.

Please note that I’ve installed this today by the install script on a Debian machine and only created 2 domains when I found the errors.

1st detected problem…

When connecting trough FTP it will start showing your folders and nothing more, however, if you fly to awstats folder it will redirect you to /usr/xxxx… and from there you can see the whole server, in fact this is a serious error. I checked and in fact if you’re on a folder outside your allowed path you can’t upload files, but if we can download files from other users and even from the system it is enough to be considered a very dangerous issue. This was tested with Filezilla.

Is this a know problem?

2nd detected problem…

After creating a domain where can the user, domain owner, create databases? As I see there is no such option on the panel for the domain owner, only for admin…

3rd detected problem…

This one is strange… very strange…

After creating a new mail box I created the profile to access by imap trought outlook express. Everything was working fine. Next I used usermin to access this account, like before it all was working fine too. Then I went to outlook express and deleted the account and created the same account again but pop3. In outlook express worked fine but when I try to go to the usermin I found this message: "An error occurred listing mail in this folder : Failed to login to POP3 server : Internal error occurred. Refer to server log for more information. [2009-04-13 21:12:20]" however I can still send and receive messages in outlook express but I try to create new accounts and no longer can access by imap on none account even new ones and on usermin always get the message before explained…

On the mail.err I have this:

Apr 13 21:12:20 server02 dovecot: IMAP(info.ghp): mkdir(/var/lib/dovecot/index/info.ghp/.INBOX) failed: Permission denied

Apr 13 21:12:20 server02 dovecot: IMAP(info.ghp): mkdir(/var/lib/dovecot/control/info.ghp/.INBOX) failed: Permission denied"

Thanks and sorry for my gramar, I’m not english language native.

I hope I explain my self good.

Cheers and thanks for any possible help.

When connecting trough FTP it will start showing your folders and nothing more, however, if you fly to awstats folder it will redirect you to /usr/xxxx..... and from there you can see the whole server, in fact this is a serious error. I checked and in fact if you're on a folder outside your allowed path you can't upload files, but if we can download files from other users and even from the system it is enough to be considered a very dangerous issue. This was tested with Filezilla.

I’m not sure why this is a problem. But, if you actually do want to restrict FTP users to only their homes, you just need to turn it on. You can do that in Webmin->ProFTPd->Files and Directories->Limit users to directories. Set it to “Home directory” and save it.

After creating a domain where can the user, domain owner, create databases? As I see there is no such option on the panel for the domain owner, only for admin...

You have to grant them permission to create databases. Limits are found in Account Plans, and more complex details are configured in Server Templates.

Apr 13 21:12:20 server02 dovecot: IMAP(info.ghp): mkdir(/var/lib/dovecot/index/info.ghp/.INBOX) failed: Permission denied

Hmmm…Doe you have a /var/lib/dovecot/index/ directory? And does it have 777 permission? Also a /var/lib/dovecot/control directory.

If so, also make sure /var/lib/dovecot has 755 permissions, as users need to be able to read through to get to the index/control directories.

Thanks :slight_smile:

All solved, keep the good work and thanks for the assistance even to those on open source that really don’t help you guys pay the bills.

You should add an section for donations so people that don’t need to buy the PRO also be able to contribute somehow.

Cheers