analysis of Debian wiki security breach

2013-01-06 Thread Luca Filipozzi
Dear editors of the Debian wiki, Please recall our recent email regarding the moinmoin [1] vulnerability [2] and the penetration of Debian's wiki [3]. We have reset all password hashes and sent individual notification to all Debian wiki account holders with instructions on how to recover (and

analysis of Debian wiki security breach

2013-01-06 Thread Luca Filipozzi
Dear editors of the Debian wiki, Please recall our recent email regarding the moinmoin [1] vulnerability [2] and the penetration of Debian's wiki [3]. We have reset all password hashes and sent individual notification to all Debian wiki account holders with instructions on how to recover (and

Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Jeremy L. Gaddis
* Luca Filipozzi lfili...@debian.org wrote: Please recall our recent email regarding the moinmoin [1] vulnerability [2] and the penetration of Debian's wiki [3]. We have reset all password hashes and sent individual notification to all Debian wiki account holders with instructions on how to

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Luca Filipozzi
On Sun, Jan 06, 2013 at 07:08:08PM -0500, Jeremy L. Gaddis wrote: * Luca Filipozzi lfili...@debian.org wrote: Please recall our recent email regarding the moinmoin [1] vulnerability [2] and the penetration of Debian's wiki [3]. We have reset all password hashes and sent individual

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Charles Plessy
Le Mon, Jan 07, 2013 at 01:41:49AM +, Luca Filipozzi a écrit : OTOH, I'd argue that if one wishes to maintain content at wiki.debian.org, then one should understand the basics of PKI. What do you think? Hi Luca, how about Debian Single Sign On (https://sso.debian.org) ? Have a nice

Project Participants page: name errors.

2013-01-06 Thread Tae Wong
Joachim Breiter and Joachim Breitner have the same e-mail address. The correct one is Joachim Breitner. You might need to fix this error. -- To UNSUBSCRIBE, email to debian-www-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org Archive:

Re: wiki.debian.org password reset

2013-01-06 Thread Luca Filipozzi
On Mon, Jan 07, 2013 at 02:28:20AM +, Luca Filipozzi wrote: On Mon, Jan 07, 2013 at 12:57:38PM +1100, Andrew McGlashan wrote: What I want to know is the following Do you perform hardening practices such as described at this page: http://crackstation.net/hashing-security.htm

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Jeremy L. Gaddis
* Luca Filipozzi lfili...@debian.org wrote: On Sun, Jan 06, 2013 at 07:08:08PM -0500, Jeremy L. Gaddis wrote: Thanks, I just reset the password on my account only to realize that SSL is not being used by default on wiki.d.o. Yes. :/ Surely this will be fixed in the very near future?

Re: Project Participants page: name errors.

2013-01-06 Thread David Prévot
Le 06/01/2013 22:19, Tae Wong a écrit : You might need to fix this error. As already mentioned countless times to you via this list [0], and via private emails, THIS IS NOT THE PLACE TO MENTION SUCH ISSUE! PLEASE GO AWAY TIA David 0:

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Jeremy L. Gaddis
* Charles Plessy ple...@debian.org wrote: Le Mon, Jan 07, 2013 at 01:41:49AM +, Luca Filipozzi a écrit : OTOH, I'd argue that if one wishes to maintain content at wiki.debian.org, then one should understand the basics of PKI. What do you think? how about Debian Single Sign On

Re: Project Participants page: name errors.

2013-01-06 Thread victory
On Mon, 7 Jan 2013 11:19:48 +0900 Tae Wong wrote: Joachim Breiter and Joachim Breitner have the same e-mail address. The correct one is Joachim Breitner. You might need to fix this error. As already said repeatedly, www-team do NOT have permissions to fix those, you MUST talk such errors to

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Paul Wise
On Mon, Jan 7, 2013 at 8:08 AM, Jeremy L. Gaddis wrote: Thanks, I just reset the password on my account only to realize that SSL is not being used by default on wiki.d.o. As you found out, there is SSL available but not enforced. I strongly suggest installing xul-ext-https-everywhere and

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Paul Wise
On Mon, Jan 7, 2013 at 9:41 AM, Luca Filipozzi wrote: OTOH, I'd argue that if one wishes to maintain content at wiki.debian.org, then one should understand the basics of PKI. What do you think? Many of the Debian wiki editors are there to translate content to their own language. Some of

Re: Project Participants page: name errors.

2013-01-06 Thread Tae Wong
As you look, the messages you delete have to be re-created. Chrissie Caulfield is the correct one and Christie Caulfield is the incorrect one. These both have the same e-mail, chris...@debian.org. -- To UNSUBSCRIBE, email to debian-www-requ...@lists.debian.org with a subject of unsubscribe.

Re: Project Participants page: name errors.

2013-01-06 Thread victory
On Mon, 7 Jan 2013 12:14:16 +0900 Tae Wong wrote: As you look, the messages you delete have to be re-created. Chrissie Caulfield is the correct one and Christie Caulfield is the incorrect one. These both have the same e-mail, chris...@debian.org. As already said repeatedly, www-team do NOT

Re: wiki.debian.org password reset

2013-01-06 Thread Andrew McGlashan
Hi, On 7/01/2013 1:42 PM, Luca Filipozzi wrote: On Mon, Jan 07, 2013 at 02:28:20AM +, Luca Filipozzi wrote: On Mon, Jan 07, 2013 at 12:57:38PM +1100, Andrew McGlashan wrote: What I want to know is the following Do you perform hardening practices such as described at this page:

Debian WWW CVS commit by victory-guest: webwml/english/security/2013 dsa-2599.data dsa ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: victory-guest 13/01/06 15:03:04 Added files: english/security/2013: dsa-2599.data dsa-2599.wml Log message: dsa-2599 -- To UNSUBSCRIBE, email to debian-www-cvs-requ...@lists.debian.org with a subject of

Debian WWW CVS commit by victory-guest: webwml english/security/2011/dsa-2176.data eng ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: victory-guest 13/01/06 15:07:31 Added files: english/security/2011: dsa-2176.data dsa-2176.wml french/security/2011: dsa-2176.wml Log message: [SECURITY] [DSA 2176-1] cups security update Modified

Debian WWW CVS commit by taffit: webwml/english/security/2013 dsa-2599.data

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:10:39 Modified files: english/security/2013: dsa-2599.data Log message: document CVE-2013-0743 for DSA-2599-1 (r20833) -- To UNSUBSCRIBE, email to debian-www-cvs-requ...@lists.debian.org

Debian WWW CVS commit by taffit: webwml/french/security/2013 dsa-2599.wml

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:23:01 Added files: french/security/2013: dsa-2599.wml Log message: (fr) Initial translation -- To UNSUBSCRIBE, email to debian-www-cvs-requ...@lists.debian.org with a subject of

Debian WWW CVS commit by victory-guest: webwml/japanese/security/2013 dsa-2599.wml

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: victory-guest 13/01/06 15:23:31 Added files: japanese/security/2013: dsa-2599.wml Log message: dsa-2599 translated by victory -- To UNSUBSCRIBE, email to debian-www-cvs-requ...@lists.debian.org with a

Debian WWW CVS commit by victory-guest: webwml/japanese/security/2007 dsa-1273.wml dsa ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: victory-guest 13/01/06 15:25:21 Added files: japanese/security/2007: dsa-1273.wml dsa-1274.wml dsa-1275.wml dsa-1276.wml Log message: dsa-1273-1276 translated by victory --

Debian WWW CVS commit by victory-guest: webwml german/MailingLists/desc/user/translati ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: victory-guest 13/01/06 15:26:05 Modified files: german/MailingLists/desc/user: translation-check Added files: german/MailingLists/desc/user: debian-stable-announce Log message: Initial German

Debian WWW CVS commit by taffit: webwml/galician

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:46:52 webwml/galician Update of /cvs/webwml/webwml/galician In directory vasks:/tmp/cvs-serv13218/galician Log Message: Directory /cvs/webwml/webwml/galician added to the repository -- To UNSUBSCRIBE,

Debian WWW CVS commit by taffit: webwml/galician/international

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:47:26 webwml/galician/international Update of /cvs/webwml/webwml/galician/international In directory vasks:/tmp/cvs-serv13279/international Log Message: Directory /cvs/webwml/webwml/galician/international

Debian WWW CVS commit by taffit: webwml/galician/po

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:47:27 webwml/galician/po Update of /cvs/webwml/webwml/galician/po In directory vasks:/tmp/cvs-serv13279/po Log Message: Directory /cvs/webwml/webwml/galician/po added to the repository -- To UNSUBSCRIBE,

Debian WWW CVS commit by taffit: webwml/galician/international/galician

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:48:58 webwml/galician/international/galician Update of /cvs/webwml/webwml/galician/international/galician In directory vasks:/tmp/cvs-serv13486/international/galician Log Message: Directory

Debian WWW CVS commit by taffit: webwml danish/security/2012/dsa-2506.wml galic ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:54:42 Modified files: danish/security/2012: dsa-2506.wml Log message: Sync Added files: galician : contact.wml donations.wml index.wml

Debian WWW CVS commit by taffit: webwml danish/security/2012/dsa-2506.wml galic ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:54:45 Modified files: danish/security/2012: dsa-2506.wml Log message: Sync Added files: galician : contact.wml donations.wml index.wml

Debian WWW CVS commit by taffit: webwml danish/security/2012/dsa-2506.wml galic ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:54:46 Modified files: danish/security/2012: dsa-2506.wml Log message: Sync Added files: galician : contact.wml donations.wml index.wml

Debian WWW CVS commit by taffit: webwml danish/security/2012/dsa-2506.wml galic ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:54:47 Modified files: danish/security/2012: dsa-2506.wml Log message: Sync Added files: galician : contact.wml donations.wml index.wml

Debian WWW CVS commit by taffit: webwml english/template/debian/languages.wml e ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:56:55 Modified files: english/template/debian: languages.wml language_names.wml . : Makefile Log message: Activate Galician translation -- To UNSUBSCRIBE, email to

Debian WWW CVS commit by taffit: webwml english/template/debian/languages.wml e ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:56:56 Modified files: english/template/debian: languages.wml language_names.wml . : Makefile english/devel/website: tc.data validation.data Log message: Activate

Debian WWW CVS commit by taffit: webwml/english/template/debian languages.wml l ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 15:56:54 Modified files: english/template/debian: languages.wml language_names.wml Log message: Activate Galician translation -- To UNSUBSCRIBE, email to

Debian WWW CVS commit by taffit: webwml english/security/2013/dsa-2600.data eng ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 19:07:33 Added files: english/security/2013: dsa-2600.data dsa-2600.wml french/security/2013: dsa-2600.wml Log message: [DSA 2600-1] cups security update -- To UNSUBSCRIBE, email to

Debian WWW CVS commit by taffit: webwml/english/security/2013 dsa-2600.data dsa ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 19:07:31 Added files: english/security/2013: dsa-2600.data dsa-2600.wml Log message: [DSA 2600-1] cups security update -- To UNSUBSCRIBE, email to debian-www-cvs-requ...@lists.debian.org with

Debian WWW CVS commit by taffit: webwml/english/security/2013 dsa-2601.data dsa ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 19:17:55 Added files: english/security/2013: dsa-2601.data dsa-2601.wml Log message: [DSA 2601-1] cups security update -- To UNSUBSCRIBE, email to debian-www-cvs-requ...@lists.debian.org with

Debian WWW CVS commit by taffit: webwml english/security/2013/dsa-2601.data eng ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 19:17:56 Added files: english/security/2013: dsa-2601.data dsa-2601.wml french/security/2013: dsa-2601.wml Log message: [DSA 2601-1] cups security update -- To UNSUBSCRIBE, email to

Debian WWW CVS commit by geissert: webwml japanese/security/2010/dsa-2133.wml jap ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: geissert13/01/06 21:47:46 Added files: japanese/security/2010: dsa-2133.wml Log message: Subject: [PATCH 5/6] Update japanese translation DSA 2133 (d-u@jp:54718) Added files:

Debian WWW CVS commit by taffit: webwml/english/News/weekly Makefile

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: taffit 13/01/06 22:00:31 Modified files: english/News/weekly: Makefile Log message: The current stuff are in projectnews now -- To UNSUBSCRIBE, email to debian-www-cvs-requ...@lists.debian.org with a subject

Debian WWW CVS commit by victory-guest: webwml english/security/2012/dsa-2574.data eng ...

2013-01-06 Thread Debian WWW CVS
CVSROOT:/cvs/webwml Module name:webwml Changes by: victory-guest 13/01/07 03:06:55 Added files: english/security/2012: dsa-2574.data dsa-2574.wml Log message: dsa-2574 Added files: japanese/security/2013: dsa-2600.wml dsa-2601.wml Log message: