Re: BSDstats v3.0 - The Security Rewrite

2006-09-03 Thread Marc G. Fournier
On Thu, 17 Aug 2006, Oliver Fromme wrote: (1) When run for the first time, you get an error message: : not found That's because a few bogus spaces after the backslash in the line containing the chmod command. Those trailing spaces should be removed. I suppose I don't need to send a PR for

Re: BSDstats v3.0 - The Security Rewrite

2006-09-03 Thread Marc G. Fournier
On Mon, 14 Aug 2006, Paul Schmehl wrote: Marc, thanks for all your hard work on these issues. One small change needs to be made. The pkg-message file reads, at its end: o view current statistics, go to: http://bsdstats.hub.org That needs to be changed to http://www.bsdstst.org/ This

Re: BSDstats v3.0 - The Security Rewrite

2006-08-18 Thread Marc G. Fournier
Thanks for your comments and suggestions ... I am currently in the middle of a campground working on a laptop (missing my desktop dearly, since this laptop is my wife's Windows box) ... when I get back online properly beginning of Sept, I will work on the suggestions though ... thx ... On

Re: BSDstats v3.0 - The Security Rewrite

2006-08-17 Thread Oliver Fromme
Marc G. Fournier wrote: Over the past few days, I've been working with Paul Schmehl and Matthew Seaman to come up with a more security sensitive version of BSDstats ... one that reduces the amount of sensitive information stored in the database down to ... zero. No IPs, no hostnames

Re: BSDstats v3.0 - The Security Rewrite

2006-08-16 Thread Igor Robul
On Tue, Aug 15, 2006 at 10:37:10AM -0400, John Nielsen wrote: On Tuesday 15 August 2006 08:12, Igor Robul wrote: On Mon, Aug 14, 2006 at 10:19:05AM -0300, Marc G. Fournier wrote: None of the pre-v3.x clients can talk to the v3.x server, since the DB format has totally changed, so everyone

Re: BSDstats v3.0 - The Security Rewrite

2006-08-16 Thread Marc G. Fournier
On Mon, 14 Aug 2006, Jonathan Horne wrote: i noticed the percentages columns, they definatly make the information all that more fascinating. would it be possible to segregate the far right column by release, and show what percentages of the 6.1s are stable, p3, p2, release? etc etc? that

Re: BSDstats v3.0 - The Security Rewrite

2006-08-15 Thread Igor Robul
On Mon, Aug 14, 2006 at 10:19:05AM -0300, Marc G. Fournier wrote: None of the pre-v3.x clients can talk to the v3.x server, since the DB format has totally changed, so everyone needs to grab the latest version and run it so that we can re-sync the database properly ... It does not build with

Re: BSDstats v3.0 - The Security Rewrite

2006-08-15 Thread John Nielsen
On Tuesday 15 August 2006 08:12, Igor Robul wrote: On Mon, Aug 14, 2006 at 10:19:05AM -0300, Marc G. Fournier wrote: None of the pre-v3.x clients can talk to the v3.x server, since the DB format has totally changed, so everyone needs to grab the latest version and run it so that we can

BSDstats v3.0 - The Security Rewrite

2006-08-14 Thread Marc G. Fournier
Over the past few days, I've been working with Paul Schmehl and Matthew Seaman to come up with a more security sensitive version of BSDstats ... one that reduces the amount of sensitive information stored in the database down to ... zero. No IPs, no hostnames ... This new version also

Re: BSDstats v3.0 - The Security Rewrite

2006-08-14 Thread Paul Schmehl
Marc G. Fournier wrote: Over the past few days, I've been working with Paul Schmehl and Matthew Seaman to come up with a more security sensitive version of BSDstats ... one that reduces the amount of sensitive information stored in the database down to ... zero. No IPs, no hostnames ...

Re: BSDstats v3.0 - The Security Rewrite

2006-08-14 Thread John Nielsen
On Monday 14 August 2006 09:19, Marc G. Fournier wrote: Over the past few days, I've been working with Paul Schmehl and Matthew Seaman to come up with a more security sensitive version of BSDstats ... one that reduces the amount of sensitive information stored in the database down to ... zero.

Re: BSDstats v3.0 - The Security Rewrite

2006-08-14 Thread Marc G. Fournier
On Mon, 14 Aug 2006, John Nielsen wrote: This is great! Is the 15-minute first-time waiting period enforced on the server side? Obviously there's nothing to stop an administrator from editing the script locally.. It is enforced on the server side ... in fact, one person just reported to me

Re: BSDstats v3.0 - The Security Rewrite

2006-08-14 Thread Scott Sipe
On Aug 14, 2006, at 4:28 PM, Marc G. Fournier wrote: On Mon, 14 Aug 2006, John Nielsen wrote: This is great! Is the 15-minute first-time waiting period enforced on the server side? Obviously there's nothing to stop an administrator from editing the script locally.. It is enforced on

Re: BSDstats v3.0 - The Security Rewrite

2006-08-14 Thread Marc G. Fournier
On Mon, 14 Aug 2006, Scott Sipe wrote: On Aug 14, 2006, at 4:28 PM, Marc G. Fournier wrote: On Mon, 14 Aug 2006, John Nielsen wrote: This is great! Is the 15-minute first-time waiting period enforced on the server side? Obviously there's nothing to stop an administrator from editing the

Re: BSDstats v3.0 - The Security Rewrite

2006-08-14 Thread Jonathan Horne
On Monday 14 August 2006 08:19, Marc G. Fournier wrote: Over the past few days, I've been working with Paul Schmehl and Matthew Seaman to come up with a more security sensitive version of BSDstats ... one that reduces the amount of sensitive information stored in the database down to ... zero.