[Nlnog] [Fwd: Re: Open Rancid CVS Repository]

Jaap O Mark jaap at is.nl
Tue Aug 3 14:43:37 UTC 2004


vast gemaakt door een stagiair ;-)



Met vriendelijke groet,

Jaap O. Mark
IS Developer


-------- I S - I N T E R N E D - S E R V I C E S - B V --------
domeinregistratie - webhosting - colocating - dedicated servers
www.is.nl         -      helpdesk at is.nl     -    T: 0299-476185
Gorslaan 18       -         1441 RG         -         Purmerend
---------------------------------------------------------------
  

> -----Original Message-----
> From: nlnog-bounces at nlnog.net 
> [mailto:nlnog-bounces at nlnog.net] On Behalf Of Tycho Eggen
> Sent: dinsdag 3 augustus 2004 16:21
> To: nlnog at nlnog.net
> Subject: [Nlnog] [Fwd: Re: Open Rancid CVS Repository]
> 
> Lees en huiver!
> 
> Grtz,
> 	Tycho
> 
> -------- Forwarded Message --------
> > From: Darrell Newcomb <darrell at cenic.org>
> > To: Tycho Eggen <tycho at capcave.com>
> > Cc: dj at capcave.com
> > Subject: Re: Open Rancid CVS Repository
> > Date: Tue, 3 Aug 2004 07:17:24 -0700
> > Mailer: Apple Mail (2.613)
> > Sadly it is an open repository.  :-(  Your email may help sway the 
> > opinions of others whom could not be persuaded on this issue 
> > previously.
> > 
> > CENIC is a consortium and as such expose a very large 
> amount about our 
> > infrastructure to the public.  The rancid repository is one of the 
> > items which goes too far IMO.  With 10 Million end users on 
> our network 
> > and a very small staff the added complexity of dealing with the 
> > security exposures of our configurations being online 
> scares me to no 
> > end.
> > 
> > See also:
> > http://cricket.cenic.org
> > http://www.cenic.net/operations/documentation/BGPCommunities.shtml
> > 
> > Thanks again,
> > Darrell
> > 
> > 
> > On Aug 3, 2004, at 3:29 AM, Tycho Eggen wrote:
> > 
> > > Dear CENIC employee,
> > >
> > > my co-worker, in the CC, was looking for rancid related 
> configurations
> > > and happened to stumble onto your rancid cvs repository at
> > > http://rancid.engineering.cenic.org/cgi-bin/cvsweb.cgi
> > >
> > > We wanted to bring this to your attention,
> > > since this is normally not something one would want to 
> share with the
> > > world.
> > >
> > > You will probably see some hits on that webserver for 
> that site from 
> > > our
> > > ip space, since we wanted to verify that this was an open 
> repository.
> > >
> > > Kind regards,
> > > 	Tycho Eggen
> > >
> > > -- 
> > > Tycho Eggen, Capcave B.V. - Systems Specialist
> > > a: Papendorpseweg 83, 3528 BJ Utrecht
> > > t: +31(0)30 214 96 70, f: +31(0) 30 214 9679
> > > m: +31(0)6 41 824 855, e: tycho at capcave.com
> > > po: TNE1-RIPE, pki: 0xC3DF0D35, as: 20786
> > 
> -- 
> Tycho Eggen, Capcave B.V. - Systems Specialist
> a: Papendorpseweg 83, 3528 BJ Utrecht
> t: +31(0)30 214 96 70, f: +31(0) 30 214 9679
> m: +31(0)6 41 824 855, e: tycho at capcave.com
> po: TNE1-RIPE, pki: 0xC3DF0D35, as: 20786
> 




More information about the NLNOG mailing list