Boston Linux & Unix (BLU) Home | Calendar | Mail Lists | List Archives | Desktop SIG | Hardware Hacking SIG
Wiki | Flickr | PicasaWeb | Video | Maps & Directions | Installfests | Keysignings
Linux Cafe | Meeting Notes | Blog | Linux Links | Bling | About BLU

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

cvs + xinetd setgid problem



Why are you even trying to use 'pserver' for write operations?  That's
a security hole waiting to bit you in the rear.  You should only really
use pserver for read operations (i.e. anonymous cvs).  IMHO it should not
be used for anything else.

You should use cvs over ssh for write access.

I'd also recommend you look into cvsd to limit your anon-cvs to a
chroot'ed environment.

-derek

Dan Barrett <nullpointer at pobox.com> writes:

> Folks,
> I'm trying to run a cvs respository on my Gentoo box.  I've got xinetd 
> running, with the cvspserver config (/etc/xinetd.d/cvspserver) looking like 
> so:
[snip]

-- 
       Derek Atkins                 617-623-3745
       derek at ihtfp.com             www.ihtfp.com
       Computer and Internet Security Consultant




BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org