Hi Anthony,

Thanks for that, I noticed you were putting pressure on the hard drive and
got a little nervous. :)

You’re right, root is not necessary. It’s mainly to make it easier to break
and that I’d rather not have to deal with security both from a “can’t log
in as root” perspective, and from an infrastructure point of view. The
backend should be solid enough to encapsulate even root.

I’ve got one console instance where I’ve just chewed up a gig and a half,
which i’m seeing reflected in another instance

Well spotted, each machine is virtual and is running on the same host. Once
memory and disk space is all chewed up, it would break. So that’s something
to look out for.

More generally as well, what’s the backend setup you’re using for this?
Curiosity and all :D

Seeing as I’m looking for flaws from the perspective of users who won’t
know the backend, I’ll hold on revealing it until the experiment is done.

lol. I bombed your instances with tons of dd’s, to fill up the disk. Seems
to have gone down now? :-)

So it has. :) Good job. Investigating the cause.
​

On 18 August 2015 at 12:06, Anthony Tan <[email protected]> wrote:

> First thing I'd say as much as I appreciate getting root, do I really need
> to be getting it? I've *never* had root on any box I didn't install myself,
> so seeing it on this instance somewhat freaks me out.
>
> Next thing - I've got one console instance where I've just chewed up a
> gig and a half, which i'm seeing reflected in another instance, without
> having access to the files. What happens if I soak up all your disk space
> and then log out? (for good form, i just blew them away -
> instance 02d2aa6f6c32 if you can track it down)
>
> More generally as well, what's the backend setup you're using for this?
> Curiosity and all :D
>
>
> On Tue, Aug 18, 2015, at 08:40 PM, Marcus Ottosson wrote:
>
> As an experiment, I’ve set-up a terminal you can log into and communicate
> with over the browser, and I need someone to try and break it so as to find
> identify security flaws.
>
>    - http://f492dea4.ngrok.io/
>
> The link will most likely be up for a day or two so if you miss it, don’t
> fret it.
>
> It’s a got Maya 2016 installed along with a few standard terminal apps,
> like nano. The behaviour is that, whenever you enter the site, a new
> machine spins up. I’m looking for ways in which this behaviour stops
> working.
>
> Let me know what you find, and good luck!
>
> --
> *Marcus Ottosson*
> [email protected]
>
>
> --
> You received this message because you are subscribed to the Google Groups
> "Python Programming for Autodesk Maya" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/python_inside_maya/CAFRtmOBEPtcWO3c6s3%3Dq469MfAq9AS84gxQFVYgLETckrv3JsA%40mail.gmail.com
> <https://groups.google.com/d/msgid/python_inside_maya/CAFRtmOBEPtcWO3c6s3%3Dq469MfAq9AS84gxQFVYgLETckrv3JsA%40mail.gmail.com?utm_medium=email&utm_source=footer>
> .
> For more options, visit https://groups.google.com/d/optout.
>
>
>
> --
> You received this message because you are subscribed to the Google Groups
> "Python Programming for Autodesk Maya" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/python_inside_maya/1439895969.415928.359131297.68B21E69%40webmail.messagingengine.com
> <https://groups.google.com/d/msgid/python_inside_maya/1439895969.415928.359131297.68B21E69%40webmail.messagingengine.com?utm_medium=email&utm_source=footer>
> .
> For more options, visit https://groups.google.com/d/optout.
>



-- 
*Marcus Ottosson*
[email protected]

-- 
You received this message because you are subscribed to the Google Groups 
"Python Programming for Autodesk Maya" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/python_inside_maya/CAFRtmOCcpRmipz5nxic2qWBQntC4gR02ZqBvzii%2BBOoSwKqfXg%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to