Re: [HACKERS] [pgsql-www] Problems logging into CVS server

2004-07-13 Thread Justin Clift
Marc G. Fournier wrote:
Damn ... I'll have to look at it ... we had a hacker get in through the 
way anoncvs was setup, so I set a passwd on in /etc/passwd (but didn't 
touch the anoncvs setup itself) ... will play with it tonight and see if 
I can figure out how to do a more secure anon-cvs ;(  I have to be 
missing something in the config *sigh*
Um, that sounds worrying.  Was the activity of the hacker anything that 
would affect PG code, or access to anything sensitive (account 
passwords, etc)?

Regards and best wishes,
Justin Clift
---(end of broadcast)---
TIP 7: don't forget to increase your free space map settings


Re: [HACKERS] [pgsql-www] Problems logging into CVS server

2004-07-12 Thread Marc G. Fournier
On Tue, 13 Jul 2004, Justin Clift wrote:
Marc G. Fournier wrote:
Damn ... I'll have to look at it ... we had a hacker get in through the 
way anoncvs was setup, so I set a passwd on in /etc/passwd (but didn't 
touch the anoncvs setup itself) ... will play with it tonight and see if I 
can figure out how to do a more secure anon-cvs ;(  I have to be missing 
something in the config *sigh*
Um, that sounds worrying.  Was the activity of the hacker anything that would 
affect PG code, or access to anything sensitive (account passwords, etc)?
No ... anoncvs is not part of the same group as the primary cvsroot, so 
not able to commit to the source tree ... the anoncvs cvsroot is a 
different directory structure altogether (/projects/cvsroot vs /cvsroot), 
and the anoncvs user has no write permissions on /cvsroot ...


Marc G. Fournier   Hub.Org Networking Services (http://www.hub.org)
Email: [EMAIL PROTECTED]   Yahoo!: yscrappy  ICQ: 7615664
---(end of broadcast)---
TIP 2: you can get off all lists at once with the unregister command
   (send unregister YourEmailAddressHere to [EMAIL PROTECTED])