View Full Version : Stats default security -- Feedback wanted
Terra
11-04-1998, 04:13 AM
As new domains are setup -- I would like to propose a poll to find out if the "/stats" directory should be 1) Locked or 2) Unlocked by default on a new domain setup...
Locked == requiring a password to view the stats...
Currently they are setup as "Unlocked"
Any feedback on this is greatly appreciated -- I leave it to the FQuest community for their voice to be heard...
Terra
SysAdmin
FutureQuest.net
[This message has been edited by ccTech (edited 11-04-98).]
Just going from past host experiences, how bout a link or button on the CNC to a script that generates the .htaccess and .htpasswd files inside /stats?
The link/button could just say "Password Protect your Stats directory" (or similar). Then, for those that wanted, a simple mouse click would take care of it for you.
I know that /stats isn't world writable, and I don't claim to understand fully how to make a script create files in a non-writeable dir, but I know it can be done somehow... hehehe (I've got a vague idea, but since it is vague, I won't try it til I know more. Somewhere in the setuid() thing it seems, or something.)
Del
Terra
11-05-1998, 07:19 AM
A button for that is not worth the real estate on the CNC... There will be a FileManager in a couple months that will provide that capability to you...
But I will ponder it though...
/stats will be going through another conversion from 'root' control to the 'xdomain' control... That removes any necessity for a setuid to root *not wise* to accomplish this...
The script to do this would/should not take long to cook up... That's not the problem, I first approached with the 'default setup' notion, to avoid figuring out how to deliver the capability to the client... Right now, that is only by CNC, and direct .htaccess creation by the Telnet/SSH power users...
Easy enough in concept -- difficult in delivery... *sigh*
Indeed, delivery is always the tough part hehehe. It is working fine as-is tho (in my opinion), so there's really no rush to change it. Only other members of the FQuest server know for sure that the stats dir is there. A robots.txt file that disallows /stats/ would be easy for each member to set up, which would keep the general nosy population of the 'net outta there.
You're already bustin your hump working on a thousand other things tho, no need to add another thing to the list, specially when it's not an area of problem right now (again, IMO)
Del
Terra
11-05-1998, 08:30 PM
hehehe -- I am only warming up... http://www.aota.net/ubb//wink.gif
A robots.txt file is an excellent interim solution...
It will be implemented tonight...
And "hint-hint" -- I've got the "EmailSiphon" bots already taken care of... I do not like spiders/bots that ignore the robots.txt file... They require my tender loving care... (evil grin) http://www.aota.net/ubb//smile.gif
So Del, how *do* you like playing with Lego's
*g*
Terra
11-05-1998, 08:33 PM
*Kidding around*
Wow, that response was 7 minutes -- I'm getting better at this support thingie...
My goal is to be able to email you an answer, 30 minutes before you send the question to me...
FQuest has high goals in this arena...
*Kidding Around*
hehehe 30 min in advance, now _that's_ what I call tech support!
I love legos, why? :-)
Del
Terra
11-12-1998, 03:09 AM
This is now a "Server Announcement"... Please view the following post...
http://www.aota.net/ubb//Forum4/HTML/000026.html
Andrew Gillespie
Systems Administrator
vBulletin® v3.6.8, Copyright ©2000-2009, Jelsoft Enterprises Ltd.