X-Original-To: pgsql-www-postgresql.org@localhost.postgresql.org Received: from localhost (unknown [200.46.204.144]) by svr1.postgresql.org (Postfix) with ESMTP id 33ED9D1B1A0; Mon, 12 Jul 2004 22:16:52 -0300 (ADT) Received: from svr1.postgresql.org ([200.46.204.71]) by localhost (av.hub.org [200.46.204.144]) (amavisd-new, port 10024) with ESMTP id 42402-02; Tue, 13 Jul 2004 01:16:46 +0000 (GMT) Received: from ganymede.hub.org (u46n208.hfx.eastlink.ca [24.222.46.208]) by svr1.postgresql.org (Postfix) with ESMTP id E9B83D1B19B; Mon, 12 Jul 2004 22:16:42 -0300 (ADT) Received: by ganymede.hub.org (Postfix, from userid 1000) id DB4EB37547; Mon, 12 Jul 2004 22:16:45 -0300 (ADT) Received: from localhost (localhost [127.0.0.1]) by ganymede.hub.org (Postfix) with ESMTP id DA3F737524; Mon, 12 Jul 2004 22:16:45 -0300 (ADT) Date: Mon, 12 Jul 2004 22:16:45 -0300 (ADT) From: "Marc G. Fournier" X-X-Sender: scrappy@ganymede.hub.org To: Justin Clift Cc: Devrim GUNDUZ , pgsql-hackers@postgresql.org, PostgreSQL WWW Mailing List Subject: Re: Problems logging into CVS server In-Reply-To: <40F3326C.507@postgresql.org> Message-ID: <20040712221420.L867@ganymede.hub.org> References: <20040712183014.O867@ganymede.hub.org> <40F3326C.507@postgresql.org> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed X-Virus-Scanned: by amavisd-new at hub.org X-Spam-Status: No, hits=0.0 tagged_above=0.0 required=5.0 tests= X-Spam-Level: X-Archive-Number: 200407/42 X-Sequence-Number: 4712 On Tue, 13 Jul 2004, Justin Clift wrote: > Marc G. Fournier wrote: > >> >> Damn ... I'll have to look at it ... we had a hacker get in through the >> way anoncvs was setup, so I set a passwd on in /etc/passwd (but didn't >> touch the anoncvs setup itself) ... will play with it tonight and see if I >> can figure out how to do a more secure anon-cvs ;( I have to be missing >> something in the config *sigh* > > Um, that sounds worrying. Was the activity of the hacker anything that would > affect PG code, or access to anything sensitive (account passwords, etc)? No ... anoncvs is not part of the same group as the primary cvsroot, so not able to commit to the source tree ... the anoncvs cvsroot is a different directory structure altogether (/projects/cvsroot vs /cvsroot), and the anoncvs user has no write permissions on /cvsroot ... ---- Marc G. Fournier Hub.Org Networking Services (http://www.hub.org) Email: scrappy@hub.org Yahoo!: yscrappy ICQ: 7615664