View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0001527 | unreal | ircd | public | 2004-02-09 18:21 | 2004-02-11 18:37 |
| Reporter | fez | Assigned To | |||
| Priority | normal | Severity | feature | Reproducibility | always |
| Status | closed | Resolution | open | ||
| Product Version | 3.2-beta19 | ||||
| Summary | 0001527: bugs site | ||||
| Description | ok 2 things first of all, a lot of users have been complaining because when you try to make a new account at http://bugs.unrealircd.org they get some php or sql or whatever error. and also, a lot lot lot of users have been requesting in #unreal-support that there be an option to restrict /links and /map to ircops only (like in IRCu)... and maybe have it tell the user who requested it to visit somesite.com/serverlist.html or whatever Thoughts? -- fez | ||||
| 3rd party modules | |||||
|
|
The reason I don't like the 2nd thing is because it's misleading... and having a false sense of security is a lot worse than ""no security"". Let me explain some ways how you can discover servernames: - /who - /whois - /whowas - netsplits - netjoins - usually, like you said, the list is somewhere online (see later) - "server unmask"-tricks, /version a*, /version b*, it's fun! - and more... server names were never ment to be 'private information' So back to "why is this useful"? Hiding the names of your client servers makes no sense, since.. because they are client servers.. people have to connect to them so they are either listed on the webpage or have some kind of dns round robin... Now some reasons which DO make sense: A. You want a "flat map" so the routing information isn't shown (what is linked to what, hopcount, etc) B. You want to hide your hubs (non-public servers). Both are usually ment to prevent (or rather.. limit the impact of) [D]DoS attacks... [A] is something which I'll consider in the future and is quite easy, for [B] a solution is also simple: simply make the name of your hub something that does not resolve (like no A record), and use some other name that does resolve in link::hostname (or use an IP). |
|
|
about the first issue.. I've heard about that too, but every time I try it myself I don't get such an error.. weird eh? ;). |
|
|
About the first. I too can not reproduce this. However, just yesterday I upgraded Mantis to 0.18.1, perhaps that will solve it? As for the second part. I agree with Syzop. There is no real way to hide all server names so why provide people with a false sense of security? For example, if I want to know what server user A is on, all I have to do is type: /who A That will then return the erver that user A is on. Now I know what server he/she is on. By knowing: a.) what server a user is on b.) how many hops away that server is I can construct a network map. So adding this feature only provides a false sense of network security. Plus if you really want this, AngryWolf already has a module available to do it. |
|
|
Not 100% related, but:- Added a section "Security tips/checklist" to unreal32docs.html, this is something I worked on a few months ago... It tries to explain how to get a server/network secured, what the potential risks are, etc... Of course security is a complex topic so I cannot talk about everything in it, but I tried to mention the main risks and what you can do about it in a (hopefully) simple and understandable language ;). Also added a FAQ entry on this (with almost identical words as my bugnote). |
|
|
BUGS.UNREALIRCD.ORG IS SOOOOOOOOOO SLOW : ( -- fez |
|
|
Yes, hiding /map and /links isn't usefull at all. Only the reasons, syzop mentioned, do make sense. But if you like to hide it, use the module from AngryWolf, codemastr already said that. Just my opinion :) [OFFTOPIC] Uhm and yes, bugs.unrealircd.org is really slow, is it, because the server is so slow, or because the database is so big? ;) [/OFFTOPIC] bearbeitet am: 02-10-04 11:42 |
|
|
If you want bugs.* to be faster, than feel free to donate us a colocated machine. We were donated a machine on a T1 for free, so we're really not going to complain that the machine doesn't exactly have the best hardware... Like I said, feel free to donate us a colocation somewhere else :) |
|
|
Hm, doesn't make it many traffic? How much traffic is that per month, do you know that? |
|
|
*jump in* as long as it's something secure, so not some shared box with XX users on it... from time to time there's sensitive info going on here ;). [but we were talking about colo already, so... :p] |
|
|
http://devel.unrealircd.com/mrtg/localhost_1.html Well that's the traffic for the whole machine, I don't know how much bugs.* generates specifically. This server does run more than just that (Unreal's email, DNS, codemastr.com, solarstats.net, vulnscan.org, etc.) so I don't know exactly how much is generated by just the bugs site. |
|
|
I don't know either.. I moved vulnscan.org away from it a few months ago (got a shell on a colocated server from a friend now.. hmm that could be used for bugs.* too perhaps...).. anyway.. I didn't see any visibile decrease in traffic in the stats :). The total traffic for that box seems something like 9Gb/month (3.5kb/s x 3600 x 24 x 30 : 1000 = 9027Mb)... but cvs runs from it and I'm pretty sure that generates quite some traffic... dunnow about codemastr.com/solarstats/otherstuff, I'm unable to give a good educated guess here ;). |
|
|
ok, I just stole[1] some stats: Analysed requests from Tue-02-Sep-2003 01:29 to Tue-10-Feb-2004 23:01 (161.90 days). (Figures in parentheses refer to the 7-day period ending 11-Feb-2004 00:04). [..] Average data transferred per day: 30.45 megabytes (36.86 megabytes) so, taking the highest values.. 36.. 36*31 = 1.1Gb/month [1]: codemastr: I stole them from /usr/home/stskeeps/www/bugs/access_log and ran analog at it ;p |
|
|
1,1 gb/month for bugs.* ? That's not much. What are you understanding under "colocation server"? An own dedicated Server with root access? And can I ask, how much MHz/RAM your current server have? So I can think about, how much would be needed, that bugs.* would be faster ;) |
|
|
@colo, I'll leave that to codemastr;p. But as for specs... I presume a GHz machine with like 512mb or more would be sufficient, so that's pretty much any modern server... net stability is also an important point. Currently the box is a 400MHz thing with 64 or 128Mb memory... |
|
|
Ok, I just talked with the guy that hosts my site (should have done that earlier ;p).. he said he'll be happy to host bugs.* too... hosting/network at that place has always been pretty much ok [at least as good as devel*], it's a dual Pentium 4 3GHz box w/1Gb ram and I got root on it... so it should be quite an improvement. Rocko: thanks for the (possible) offer however, appreciated. |
|
|
Okay :) |
|
|
dumdeedum, this is a test bugnote. |
|
|
and this is a testbugnote too |
|
|
good.. we switched over to the new site.. dns update may take up to 3 hours to complete... signing up: ok (mail within 5s), bugnotes: ok, closing bugs: we'll see ;p. Only problem is the timezone is -5 hours, which causes any new bugnotes which are added in the next 5 hours to be wrongly sorted. Anyway, this is really a lot faster *happy*. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2004-02-09 18:21 | fez | New Issue | |
| 2004-02-09 21:16 | syzop | Note Added: 0004922 | |
| 2004-02-09 21:20 | syzop | Note Added: 0004923 | |
| 2004-02-09 21:42 |
|
Note Added: 0004925 | |
| 2004-02-10 01:37 | syzop | Note Added: 0004934 | |
| 2004-02-10 11:04 | fez | Note Added: 0004942 | |
| 2004-02-10 11:38 | Rocko | Note Added: 0004943 | |
| 2004-02-10 11:42 | Rocko | Note Edited: 0004943 | |
| 2004-02-10 16:51 |
|
Note Added: 0004948 | |
| 2004-02-10 17:26 | Rocko | Note Added: 0004950 | |
| 2004-02-10 17:37 | syzop | Note Added: 0004951 | |
| 2004-02-10 22:13 |
|
Note Added: 0004957 | |
| 2004-02-10 22:41 | syzop | Note Added: 0004959 | |
| 2004-02-10 23:12 | syzop | Note Added: 0004960 | |
| 2004-02-10 23:28 | Rocko | Note Added: 0004961 | |
| 2004-02-10 23:39 | syzop | Note Added: 0004962 | |
| 2004-02-11 05:25 | syzop | Note Added: 0004970 | |
| 2004-02-11 10:35 | Rocko | Note Added: 0004972 | |
| 2004-02-11 18:34 | test997 | Note Added: 0004979 | |
| 2004-02-11 18:34 | syzop | Note Added: 0004980 | |
| 2004-02-11 18:37 | syzop | Status | new => closed |
| 2004-02-11 18:37 | syzop | Note Added: 0004981 |