Grex Coop Conference

Item 45: Disabling write access for unvalidated users

Entered by keesan on Thu Sep 20 18:12:47 2007:

I am frequently unable to log in to grex due to the write and
tel floods of a vandal.  I propose only allowing writes to validated
users. They are open to abuse same as outgoing ftp/telnet or email.
19 responses total.

#1 of 19 by nharmon on Thu Sep 20 18:44:30 2007:

I support this proposal. Meaning, I support bringing this proposal to a
vote.


#2 of 19 by keesan on Thu Sep 20 22:10:20 2007:

Mcnally suggested disabling write and having only tel.


#3 of 19 by mcnally on Thu Sep 20 23:21:54 2007:

 Since (as was pointed out elsewhere by user bertrand) they're the same
 program, just behaving differently based on what it's called, this will
 still require someone to patch and recompile the orville-write binary.
 I think bertrand's suggestion should work, however.


#4 of 19 by unicorn on Thu Sep 20 23:42:02 2007:

Is this something that needs to go through janc (the author of the
program)?  Otherwise, if he updates the program in any way without
copying our changes, those changes will be undone.


#5 of 19 by mcnally on Fri Sep 21 00:27:54 2007:

 It's something which should be acted on right away to solve the current
 annoyance, and then it should be brought up with Jan, with an explanation
 of the exploited behavior.  If he wants to fix it then it's up to him.


#6 of 19 by keesan on Fri Sep 21 04:47:33 2007:

Could we disable both write and tel until they are fixed or until we can vote
on whether to disallow them to unvalidated users?


#7 of 19 by unicorn on Fri Sep 21 04:50:10 2007:

I've already done that.  I'm one step ahead of you.  :)


#8 of 19 by keesan on Fri Sep 21 04:53:08 2007:

Thanks.  It is nice to access email again.


#9 of 19 by cmcgee on Fri Sep 21 13:41:59 2007:

unicorn, did you disable write and tel for everyone except members?

If you did, I think you need to discuss this with staff.  It is one
thing to limit new users, and an entirely different thing to shut down
*all* users access to a system resource.

For example, we have never shut down current IDs' access to email, even
if they are not validated.  


#10 of 19 by cmcgee on Fri Sep 21 14:06:32 2007:

Well, now that I've been to Agora, I can see why this is a problem.  



#11 of 19 by krj on Fri Sep 21 14:11:46 2007:

Essentially this is going to have to be delegated to staff; the 
situation is too fluid for solutions to be codified in member votes.


#12 of 19 by keesan on Fri Sep 21 14:29:15 2007:

Tel access is also disabled for members.  I can send email to get someone's
attention.


#13 of 19 by mcnally on Fri Sep 21 16:49:07 2007:

 re #11:  I second what Ken said re #9.


#14 of 19 by unicorn on Sat Sep 22 03:25:20 2007:

This was a temporary measure, cmcgee, as I'm sure you now know.  I'll
try to re-enable it after I've decided what the best way to do it is.
I'd like to enable it for everyone but the newpeople group.  Please
bear with me.


#15 of 19 by unicorn on Sat Sep 22 06:35:46 2007:

I think I have this working acceptably via the sudo command,
(transparently, so you don't need to enter a password), but you
may get a message from sudo the first time you use write or tel.
After that, you shouldn't notice any difference.  Let me know if
there are any problems.

New users will still get a message telling them that the command
they're trying to run is temporarily disabled.  This message will
have to be changed if we decide to make this change permanent.  I'd
like to do it without sudo, but I haven't yet thought of a way to do
that without recompiling the write binary.


#16 of 19 by mcnally on Sat Sep 22 08:25:05 2007:

 There's a trivially easy way to defeat your group check in #15,
 which I will mail to you, though I suspect it will be obvious.


#17 of 19 by unifuck on Sat Sep 22 15:09:07 2007:

Too late, I'm already one step ahead of mensa boy.


#18 of 19 by unicorn on Mon Sep 24 21:51:20 2007:

I've come up with a better way to disallow new users from using tel,
write, and wall that doesn't require sudo.  If anyone that isn't in
the newpeople group has a problem with these commands, let me know.


#19 of 19 by cmcgee on Tue Sep 25 02:41:05 2007:

Thanks for all your work unicorn.  



There are no more items selected.

You have several choices: