[Fwd: Re: Open Rancid CVS Repository]
vast gemaakt door een stagiair ;-) Met vriendelijke groet, Jaap O. Mark IS Developer -------- I S - I N T E R N E D - S E R V I C E S - B V -------- domeinregistratie - webhosting - colocating - dedicated servers www.is.nl - helpdesk at is.nl - T: 0299-476185 Gorslaan 18 - 1441 RG - Purmerend ---------------------------------------------------------------
-----Original Message----- From: nlnog-bounces at nlnog.net [mailto:nlnog-bounces at nlnog.net] On Behalf Of Tycho Eggen Sent: dinsdag 3 augustus 2004 16:21 To: nlnog at nlnog.net Subject: [Nlnog] [Fwd: Re: Open Rancid CVS Repository]
Lees en huiver!
Grtz, Tycho
From: Darrell Newcomb <darrell at cenic.org> To: Tycho Eggen <tycho at capcave.com> Cc: dj at capcave.com Subject: Re: Open Rancid CVS Repository Date: Tue, 3 Aug 2004 07:17:24 -0700 Mailer: Apple Mail (2.613) Sadly it is an open repository. :-( Your email may help sway the opinions of others whom could not be persuaded on this issue previously.
CENIC is a consortium and as such expose a very large amount about our infrastructure to the public. The rancid repository is one of the items which goes too far IMO. With 10 Million end users on our network and a very small staff the added complexity of dealing with the security exposures of our configurations being online scares me to no end.
See also: http://cricket.cenic.org http://www.cenic.net/operations/documentation/BGPCommunities.shtml
Thanks again, Darrell
On Aug 3, 2004, at 3:29 AM, Tycho Eggen wrote:
Dear CENIC employee,
my co-worker, in the CC, was looking for rancid related configurations and happened to stumble onto your rancid cvs repository at http://rancid.engineering.cenic.org/cgi-bin/cvsweb.cgi
We wanted to bring this to your attention, since this is normally not something one would want to share with the world.
You will probably see some hits on that webserver for
-------- Forwarded Message -------- that site from
our ip space, since we wanted to verify that this was an open repository.
Kind regards, Tycho Eggen
-- Tycho Eggen, Capcave B.V. - Systems Specialist a: Papendorpseweg 83, 3528 BJ Utrecht t: +31(0)30 214 96 70, f: +31(0) 30 214 9679 m: +31(0)6 41 824 855, e: tycho at capcave.com po: TNE1-RIPE, pki: 0xC3DF0D35, as: 20786
-- Tycho Eggen, Capcave B.V. - Systems Specialist a: Papendorpseweg 83, 3528 BJ Utrecht t: +31(0)30 214 96 70, f: +31(0) 30 214 9679 m: +31(0)6 41 824 855, e: tycho at capcave.com po: TNE1-RIPE, pki: 0xC3DF0D35, as: 20786
participants (1)
-
jaap@is.nl