[Nlnog] [Fwd: Re: Open Rancid CVS Repository]
Tycho Eggen
tycho at capcave.com
Tue Aug 3 14:21:25 UTC 2004
Lees en huiver!
Grtz,
Tycho
-------- Forwarded Message --------
> From: Darrell Newcomb <darrell at cenic.org>
> To: Tycho Eggen <tycho at capcave.com>
> Cc: dj at capcave.com
> Subject: Re: Open Rancid CVS Repository
> Date: Tue, 3 Aug 2004 07:17:24 -0700
> Mailer: Apple Mail (2.613)
> Sadly it is an open repository. :-( Your email may help sway the
> opinions of others whom could not be persuaded on this issue
> previously.
>
> CENIC is a consortium and as such expose a very large amount about our
> infrastructure to the public. The rancid repository is one of the
> items which goes too far IMO. With 10 Million end users on our network
> and a very small staff the added complexity of dealing with the
> security exposures of our configurations being online scares me to no
> end.
>
> See also:
> http://cricket.cenic.org
> http://www.cenic.net/operations/documentation/BGPCommunities.shtml
>
> Thanks again,
> Darrell
>
>
> On Aug 3, 2004, at 3:29 AM, Tycho Eggen wrote:
>
> > Dear CENIC employee,
> >
> > my co-worker, in the CC, was looking for rancid related configurations
> > and happened to stumble onto your rancid cvs repository at
> > http://rancid.engineering.cenic.org/cgi-bin/cvsweb.cgi
> >
> > We wanted to bring this to your attention,
> > since this is normally not something one would want to share with the
> > world.
> >
> > You will probably see some hits on that webserver for that site from
> > our
> > ip space, since we wanted to verify that this was an open repository.
> >
> > Kind regards,
> > Tycho Eggen
> >
> > --
> > Tycho Eggen, Capcave B.V. - Systems Specialist
> > a: Papendorpseweg 83, 3528 BJ Utrecht
> > t: +31(0)30 214 96 70, f: +31(0) 30 214 9679
> > m: +31(0)6 41 824 855, e: tycho at capcave.com
> > po: TNE1-RIPE, pki: 0xC3DF0D35, as: 20786
>
--
Tycho Eggen, Capcave B.V. - Systems Specialist
a: Papendorpseweg 83, 3528 BJ Utrecht
t: +31(0)30 214 96 70, f: +31(0) 30 214 9679
m: +31(0)6 41 824 855, e: tycho at capcave.com
po: TNE1-RIPE, pki: 0xC3DF0D35, as: 20786
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
URL: <http://mailman.nlnog.net/pipermail/nlnog/attachments/20040803/067c65d4/attachment.pgp>
More information about the NLNOG
mailing list