info-cvs archive search

Search String: Display: Description: Sort:

Results:

References: [ pserver: 4404 ] [ security: 1340 ]

Total 529 documents matching your query.

221. Re: Problem with user group on linux cvs server (score: 9)
Author: HIDDEN
Date: Mon, 03 Feb 2003 11:05:42 -0500
Oops. You shouldn't do this to every file; only on directories. Check the archives of this list for a more complete discussion. The following link gives a good description: <http://www.mail-archive.c
/archive/html/info-cvs/2003-02/msg00008.html (5,564 bytes)

222. Re: Problem with user group on linux cvs server (score: 9)
Author: HIDDEN
Date: Mon, 03 Feb 2003 10:56:42 -0500
CVS 1.11.5 adds a major server-side security fix; you should upgrade. On the server, run 'chmod -R g+s YOUR_DIR'. This will "turn on" the set-group-ID bit so new files will be created with the same g
/archive/html/info-cvs/2003-02/msg00007.html (5,027 bytes)

223. Re: CVSROOT write permission vulnerability (score: 25)
Author: HIDDEN
Date: Wed, 22 Jan 2003 08:37:52 -0600 (CST)
It's simpler than that: don't use NFS and the :local: access method. Just say no. I've been on CVS lists for years now, and I don't remember a single case of repository corruption that didn't involv
/archive/html/info-cvs/2003-01/msg00203.html (7,785 bytes)

224. Re: CVS 1.11.5 Released <strong>(Security Update)</strong> (score: 169)
Author: HIDDEN
Date: Tue, 21 Jan 2003 13:14:14 -0500
because that is what I read off of the website in ~Dec 21 2000 and had worked since. With a root of :pserver:address@hidden:/home2/cvsroot and its module name was also ccvs. I think we discussed this
/archive/html/info-cvs/2003-01/msg00190.html (7,193 bytes)

225. Re: CVS 1.11.5 Released <strong>(Security Update)</strong> (score: 166)
Author: HIDDEN
Date: Tue, 21 Jan 2003 12:20:04 -0500 (EST)
I don't think so -- why are you looking for /home2/cvsroot? The correct CVSROOT for access to the current development version of cvs is (and the module name is ccvs). -Larry Jones I thought my life w
/archive/html/info-cvs/2003-01/msg00189.html (5,969 bytes)

226. CVS internal permissions patch updated to 1.11.5 (score: 9)
Author: HIDDEN
Date: Tue, 21 Jan 2003 09:28:39 -0600
I have updated the permissions patch to version 1.11.5. Because the security problems in 1.11.4, you should update immediately. In case you don't know, this patch adds the following: * directory/file
/archive/html/info-cvs/2003-01/msg00187.html (4,912 bytes)

227. Re: connection using pserver (score: 110)
Author: HIDDEN
Date: Mon, 20 Jan 2003 07:59:09 -0500
Yes. The PuTTY documentation <http://www.chiark.greenend.org.uk/~sgtatham/putty/docs.html> includes everything you should need for the authentication and connection end of things. I'm using WinCVS 1.
/archive/html/info-cvs/2003-01/msg00153.html (6,273 bytes)

228. Re: connection using pserver (score: 120)
Author: HIDDEN
Date: Sun, 19 Jan 2003 14:40:08 +1100
Hi Kenneth, We're using pserver with Windows 2000 and CVSNT, connecting to multiple repositories using a little tool which sets the CVS environment variables for the command prompt. We go through an
/archive/html/info-cvs/2003-01/msg00147.html (7,017 bytes)

229. Re: connection using pserver (score: 110)
Author: HIDDEN
Date: Fri, 17 Jan 2003 14:00:01 -0800
We started down this path but couldn't get it working on Windows with cygwin ssh. (Server is a Red Hat box, though.) Is there a cookbook somewhere that explains how to make that scenario work? For ot
/archive/html/info-cvs/2003-01/msg00142.html (5,490 bytes)

230. Re: connection using pserver (score: 121)
Author: HIDDEN
Date: Fri, 17 Jan 2003 16:46:24 -0500 (EST)
It also eliminates the ability to use the system's access controls to control access to your repository, not to mention any ability to track any particular action back to a specific user based on the
/archive/html/info-cvs/2003-01/msg00141.html (5,596 bytes)

231. Re: connection using pserver (score: 123)
Author: HIDDEN
Date: Fri, 17 Jan 2003 13:31:07 -0800
I just read the relevant section. Basically, CVS has its own password file, but will use the system password file as a backup. (This can be disabled.) The CVS password file uses a triplet of informat
/archive/html/info-cvs/2003-01/msg00138.html (5,815 bytes)

232. Re: How is a patch applied to CVS? (score: 19)
Author: HIDDEN
Date: Thu, 9 Jan 2003 11:14:59 +1100
Hi, But can patch be run in such a way that it generates conflict markers instead of .rej files? This would be very useful at times. Or is diff3 the go here instead? cheers, matt --Original Message--
/archive/html/info-cvs/2003-01/msg00064.html (28,055 bytes)

233. Re: CVS and multiple platforms - version conflicts, featuresavailable etc. (score: 19)
Author: HIDDEN
Date: Tue, 7 Jan 2003 17:02:26 -0600 (CST)
Look on the bright side. There are very few bad choices here. CVS does nicely with JSP, Java, and HTML files. The one thing you might want to watch out for is that, if you like messing with the pack
/archive/html/info-cvs/2003-01/msg00043.html (11,025 bytes)

234. CVS and multiple platforms - version conflicts, features available etc. (score: 9)
Author: HIDDEN
Date: Tue, 7 Jan 2003 17:30:06 +1100
I've been placed in charge of getting version control/management going at an organisation where I work. Right now, an almost anarchic situation exists where there is no real version control, several
/archive/html/info-cvs/2003-01/msg00052.html (7,377 bytes)

235. Re: Security setup (score: 170)
Author: HIDDEN
Date: Tue, 17 Dec 2002 22:10:06 -0800
Once you're connected to a pserver, it's a fairly simple process to get it to execute arbitrary commands for you; giving someone pserver access is equivalent to giving them shell access. s/pserver/s
/archive/html/info-cvs/2002-12/msg00278.html (7,482 bytes)

236. Security options :-( (score: 164)
Author: HIDDEN
Date: Tue, 17 Dec 2002 19:31:39 +0000
I recently set up a remote access repository using a third method, which may help: Method 3: description: - users SSH into a single existing account. - Account is set up using a restricted shell (act
/archive/html/info-cvs/2002-12/msg00265.html (8,568 bytes)

237. Re: Security setup (score: 177)
Author: HIDDEN
Date: Tue, 17 Dec 2002 11:56:57 -0500 (EST)
s/pserver/server/g The above applies to *any* kind of client/server mode, not just pserver. -Larry Jones We seem to be out of gun powder. -- Calvin
/archive/html/info-cvs/2002-12/msg00252.html (6,949 bytes)

238. Re: Security setup (score: 170)
Author: HIDDEN
Date: Tue, 17 Dec 2002 11:38:46 -0500
Perhaps I'm naive, but the recent posts describing local accounts (e.g. cvsphil) with no shell and ssh access to only the cvs command sound promising. Do you see anything specifically flawed with thi
/archive/html/info-cvs/2002-12/msg00250.html (7,414 bytes)

239. Re: Security setup (score: 164)
Author: HIDDEN
Date: Tue, 17 Dec 2002 11:29:42 -0500 (EST)
Once you're connected to a pserver, it's a fairly simple process to get it to execute arbitrary commands for you; giving someone pserver access is equivalent to giving them shell access. -Larry Jones
/archive/html/info-cvs/2002-12/msg00248.html (6,563 bytes)

240. RE: Security setup (score: 189)
Author: HIDDEN
Date: Tue, 17 Dec 2002 17:33:09 +0100
I think we need to differentiate between "really bullet-proof security" and "reasonable security" - after all, security is also there to protect users from themselves, with no malicious intent requir
/archive/html/info-cvs/2002-12/msg00247.html (8,125 bytes)


This search system is powered by Namazu