OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: administrator permissions mail server

From: Klaas Schaafsma (klaasxs4all.nl)
Date: Tue Feb 06 2007 - 10:44:33 CST


Step0ut wrote:

> I am working in a network with 40/50 PC's managed by 3 people with
> administrator passwords.
> The OS used is GNU/Linux.
> There is also a webmail service provided by the same server, which is also
> maintained
> by the same people.
> My question is the following:
> Since the administrator has of course access to all user files, does this
> mean that
> one with administrator privileges can read everybody's emails?

Yes it does. Since the mail is stored in whatever way (/var/spool/mail,
maildir, SQl etc.) The root user can read these files and thus read the
mail of all the users.