View Issue Details

IDProjectCategoryView StatusLast Update
0001527unrealircdpublic2004-02-11 18:37
Reporterfez Assigned To 
PrioritynormalSeverityfeatureReproducibilityalways
Status closedResolutionopen 
Product Version3.2-beta19 
Summary0001527: bugs site
Descriptionok 2 things

first of all, a lot of users have been complaining because when you try to make a new account at http://bugs.unrealircd.org they get some php or sql or whatever error.

and also, a lot lot lot of users have been requesting in #unreal-support that there be an option to restrict /links and /map to ircops only (like in IRCu)... and maybe have it tell the user who requested it to visit somesite.com/serverlist.html or whatever

Thoughts?

 -- fez
3rd party modules

Activities

syzop

2004-02-09 21:16

administrator   ~0004922

The reason I don't like the 2nd thing is because it's misleading... and having a false sense of security is a lot worse than ""no security"".

Let me explain some ways how you can discover servernames:
- /who
- /whois
- /whowas
- netsplits
- netjoins
- usually, like you said, the list is somewhere online (see later)
- "server unmask"-tricks, /version a*, /version b*, it's fun!
- and more... server names were never ment to be 'private information'

So back to "why is this useful"? Hiding the names of your client servers makes no sense, since.. because they are client servers.. people have to connect to them so they are either listed on the webpage or have some kind of dns round robin...

Now some reasons which DO make sense:
A. You want a "flat map" so the routing information isn't shown (what is linked to what, hopcount, etc)
B. You want to hide your hubs (non-public servers).
Both are usually ment to prevent (or rather.. limit the impact of) [D]DoS attacks...

[A] is something which I'll consider in the future and is quite easy, for [B] a solution is also simple: simply make the name of your hub something that does not resolve (like no A record), and use some other name that does resolve in link::hostname (or use an IP).

syzop

2004-02-09 21:20

administrator   ~0004923

about the first issue.. I've heard about that too, but every time I try it myself I don't get such an error.. weird eh? ;).

codemastr

2004-02-09 21:42

reporter   ~0004925

About the first. I too can not reproduce this. However, just yesterday I upgraded Mantis to 0.18.1, perhaps that will solve it?

As for the second part. I agree with Syzop. There is no real way to hide all server names so why provide people with a false sense of security?

For example, if I want to know what server user A is on, all I have to do is type:
/who A

That will then return the erver that user A is on. Now I know what server he/she is on. By knowing:
a.) what server a user is on
b.) how many hops away that server is

I can construct a network map.

So adding this feature only provides a false sense of network security. Plus if you really want this, AngryWolf already has a module available to do it.

syzop

2004-02-10 01:37

administrator   ~0004934

Not 100% related, but:
- Added a section "Security tips/checklist" to unreal32docs.html, this is something
  I worked on a few months ago... It tries to explain how to get a server/network
  secured, what the potential risks are, etc... Of course security is a complex topic
  so I cannot talk about everything in it, but I tried to mention the main risks and
  what you can do about it in a (hopefully) simple and understandable language ;).


Also added a FAQ entry on this (with almost identical words as my bugnote).

fez

2004-02-10 11:04

reporter   ~0004942

BUGS.UNREALIRCD.ORG IS SOOOOOOOOOO SLOW


: (

 -- fez

Rocko

2004-02-10 11:38

reporter   ~0004943

Last edited: 2004-02-10 11:42

Yes, hiding /map and /links isn't usefull at all.
Only the reasons, syzop mentioned, do make sense.
But if you like to hide it, use the module from AngryWolf, codemastr already said that.

Just my opinion :)

[OFFTOPIC] Uhm and yes, bugs.unrealircd.org is really slow, is it, because the server is so slow, or because the database is so big? ;) [/OFFTOPIC]

bearbeitet am: 02-10-04 11:42

codemastr

2004-02-10 16:51

reporter   ~0004948

If you want bugs.* to be faster, than feel free to donate us a colocated machine. We were donated a machine on a T1 for free, so we're really not going to complain that the machine doesn't exactly have the best hardware...

Like I said, feel free to donate us a colocation somewhere else :)

Rocko

2004-02-10 17:26

reporter   ~0004950

Hm, doesn't make it many traffic?
How much traffic is that per month, do you know that?

syzop

2004-02-10 17:37

administrator   ~0004951

*jump in* as long as it's something secure, so not some shared box with XX users on it... from time to time there's sensitive info going on here ;). [but we were talking about colo already, so... :p]

codemastr

2004-02-10 22:13

reporter   ~0004957

http://devel.unrealircd.com/mrtg/localhost_1.html

Well that's the traffic for the whole machine, I don't know how much bugs.* generates specifically. This server does run more than just that (Unreal's email, DNS, codemastr.com, solarstats.net, vulnscan.org, etc.) so I don't know exactly how much is generated by just the bugs site.

syzop

2004-02-10 22:41

administrator   ~0004959

I don't know either.. I moved vulnscan.org away from it a few months ago (got a shell on a colocated server from a friend now.. hmm that could be used for bugs.* too perhaps...).. anyway.. I didn't see any visibile decrease in traffic in the stats :).

The total traffic for that box seems something like 9Gb/month (3.5kb/s x 3600 x 24 x 30 : 1000 = 9027Mb)... but cvs runs from it and I'm pretty sure that generates quite some traffic... dunnow about codemastr.com/solarstats/otherstuff, I'm unable to give a good educated guess here ;).

syzop

2004-02-10 23:12

administrator   ~0004960

ok, I just stole[1] some stats:
Analysed requests from Tue-02-Sep-2003 01:29 to Tue-10-Feb-2004 23:01 (161.90 days).
(Figures in parentheses refer to the 7-day period ending 11-Feb-2004 00:04).
[..]
Average data transferred per day: 30.45 megabytes (36.86 megabytes)
so, taking the highest values.. 36.. 36*31 = 1.1Gb/month

[1]: codemastr: I stole them from /usr/home/stskeeps/www/bugs/access_log and ran analog at it ;p

Rocko

2004-02-10 23:28

reporter   ~0004961

1,1 gb/month for bugs.* ? That's not much.
What are you understanding under "colocation server"?
An own dedicated Server with root access?

And can I ask, how much MHz/RAM your current server have?
So I can think about, how much would be needed, that bugs.* would be faster ;)

syzop

2004-02-10 23:39

administrator   ~0004962

@colo, I'll leave that to codemastr;p.

But as for specs... I presume a GHz machine with like 512mb or more would be sufficient, so that's pretty much any modern server... net stability is also an important point. Currently the box is a 400MHz thing with 64 or 128Mb memory...

syzop

2004-02-11 05:25

administrator   ~0004970

Ok, I just talked with the guy that hosts my site (should have done that earlier ;p).. he said he'll be happy to host bugs.* too... hosting/network at that place has always been pretty much ok [at least as good as devel*], it's a dual Pentium 4 3GHz box w/1Gb ram and I got root on it... so it should be quite an improvement.

Rocko: thanks for the (possible) offer however, appreciated.

Rocko

2004-02-11 10:35

reporter   ~0004972

Okay :)

test997

2004-02-11 18:34

reporter   ~0004979

dumdeedum, this is a test bugnote.

syzop

2004-02-11 18:34

administrator   ~0004980

and this is a testbugnote too

syzop

2004-02-11 18:37

administrator   ~0004981

good.. we switched over to the new site.. dns update may take up to 3 hours to complete... signing up: ok (mail within 5s), bugnotes: ok, closing bugs: we'll see ;p.

Only problem is the timezone is -5 hours, which causes any new bugnotes which are added in the next 5 hours to be wrongly sorted.

Anyway, this is really a lot faster *happy*.

Issue History

Date Modified Username Field Change
2004-02-09 18:21 fez New Issue
2004-02-09 21:16 syzop Note Added: 0004922
2004-02-09 21:20 syzop Note Added: 0004923
2004-02-09 21:42 codemastr Note Added: 0004925
2004-02-10 01:37 syzop Note Added: 0004934
2004-02-10 11:04 fez Note Added: 0004942
2004-02-10 11:38 Rocko Note Added: 0004943
2004-02-10 11:42 Rocko Note Edited: 0004943
2004-02-10 16:51 codemastr Note Added: 0004948
2004-02-10 17:26 Rocko Note Added: 0004950
2004-02-10 17:37 syzop Note Added: 0004951
2004-02-10 22:13 codemastr Note Added: 0004957
2004-02-10 22:41 syzop Note Added: 0004959
2004-02-10 23:12 syzop Note Added: 0004960
2004-02-10 23:28 Rocko Note Added: 0004961
2004-02-10 23:39 syzop Note Added: 0004962
2004-02-11 05:25 syzop Note Added: 0004970
2004-02-11 10:35 Rocko Note Added: 0004972
2004-02-11 18:34 test997 Note Added: 0004979
2004-02-11 18:34 syzop Note Added: 0004980
2004-02-11 18:37 syzop Status new => closed
2004-02-11 18:37 syzop Note Added: 0004981