[Trac] Re: Nessus able to create user in Trac

2014-11-02 Thread RjOllos
On Saturday, November 1, 2014 5:06:29 AM UTC-7, ams wrote:
>
> I administer a system running a private installation of Trac 1.0.1.   Last 
> night I opened firewalls to allow a company Nessus scan.   Nessus was able 
> to create a new Trac user.
>
> 2014-11-01 02:40:43,407 Trac[main] DEBUG: Dispatching  "POST '/register'">
> 2014-11-01 02:40:43,408 Trac[session] DEBUG: Retrieving session for ID 
> 'd1e15c57faf4f33fabad61c9'
> 2014-11-01 02:40:43,409 Trac[main] DEBUG: Negotiated locale: None -> None
> 2014-11-01 02:40:43,410 Trac[api] WARNING: Unable to find repository 
> '(default)' for synchronization
> 2014-11-01 02:40:43,439 Trac[perm] DEBUG: *No policy allowed anonymous 
> performing ACCTMGR_USER_ADMIN on None*
> 2014-11-01 02:40:43,441 Trac[api] INFO: *Created new user: 12345*
>
> Is this a configuration issue, or native vulnerability?
>

For reference, solutions have been provided in:
http://trac.edgewall.org/ticket/11803
http://trac-hacks.org/ticket/12047 

-- 
You received this message because you are subscribed to the Google Groups "Trac 
Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to trac-users+unsubscr...@googlegroups.com.
To post to this group, send email to trac-users@googlegroups.com.
Visit this group at http://groups.google.com/group/trac-users.
For more options, visit https://groups.google.com/d/optout.


Re: [Trac] TypeError: 'NoneType' object is unsubscriptable during trac-admin resync after trac upgrade from 0.11 to 1.0.2

2014-11-02 Thread Steffen Hoffmann
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

On 02.11.2014 01:12, ytp...@gmail.com wrote:
> I just upgraded trac from 0.11 to 1.0.2. I followed the steps 1 ~ 6
> described in http://trac.edgewall.org/wiki/TracUpgrade. When I try to
> resync the project repository, I got the following error:
> 
> 
> [root@dm-git conf]# trac-admin /usr/share/trac/projects/partiqle
> repository resync '*'
> 19:55:45 Trac[env] INFO:  environment
> startup [Trac 1.0.2] 
...
> 19:55:45 Trac[loader] DEBUG: Loading git from
> /usr/lib/python2.6/site-packages/TracGit-0.11.0.2-py2.6.egg
...
> "/usr/lib/python2.6/site-packages/TracGit-0.11.0.2-py2.6.egg/tracext/git/git_fs.py",
> line 180, in __init__
> Repository.__init__(self, "git:"+path, None, log)
>   File
> "/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg/trac/versioncontrol/api.py",
> line 788, in __init__
> self.reponame = params['name']
> TypeError: 'NoneType' object is unsubscriptable
> 19:55:45 Trac[PyGIT] DEBUG: PyGIT.Storage instance 42904824 destructed
> [root@dm-git conf]# 
> 
> Any advise on how to fix this is most appreciated!

I don't use Trac with repositories at all, but I agree to Ryan, that you
should rather enable and use new bulit-in Git support than the external
plugin (TracGit-0.11.0.2), because Git support officially moved into
Trac's optional modules.

Steffen Hoffmann
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlRWj+MACgkQ31DJeiZFuHdxfwCg1FpffaZ4dOaSDTiDtdmxTSVL
EuUAoNWtoknT3T+R+goLwvVoq835Dthn
=NU9e
-END PGP SIGNATURE-

-- 
You received this message because you are subscribed to the Google Groups "Trac 
Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to trac-users+unsubscr...@googlegroups.com.
To post to this group, send email to trac-users@googlegroups.com.
Visit this group at http://groups.google.com/group/trac-users.
For more options, visit https://groups.google.com/d/optout.


Re: [Trac] TypeError: 'NoneType' object is unsubscriptable during trac-admin resync after trac upgrade from 0.11 to 1.0.2

2014-11-02 Thread Ryan Ollos
On Sat, Nov 1, 2014 at 5:12 PM,  wrote:


I just upgraded trac from 0.11 to 1.0.2. I followed the steps 1 ~ 6
> described in http://trac.edgewall.org/wiki/TracUpgrade. When I try to
> resync the project repository, I got the following error:
>
>
> [root@dm-git conf]# trac-admin /usr/share/trac/projects/partiqle
> repository resync '*'
> 19:55:45 Trac[env] INFO:  environment
> startup [Trac 1.0.2] 
> 19:55:45 Trac[loader] DEBUG: Loading acct_mgr.admin from
> /usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading acct_mgr.api from
> /usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading acct_mgr.db from
> /usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading acct_mgr.htfile from
> /usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading acct_mgr.http from
> /usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading acct_mgr.macros from
> /usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading acct_mgr.notification from
> /usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading acct_mgr.pwhash from
> /usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading acct_mgr.svnserve from
> /usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading acct_mgr.web_ui from
> /usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading git from
> /usr/lib/python2.6/site-packages/TracGit-0.11.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.about from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.admin.console from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.admin.web_ui from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.attachment from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.db.mysql from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.db.postgres from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.db.sqlite from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.mimeview.patch from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.mimeview.pygments from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Skipping "trac.mimeview.pygments =
> trac.mimeview.pygments [pygments]": ("DistributionNotFound: Pygments>=0.6"
> not found)
> 19:55:45 Trac[loader] DEBUG: Loading trac.mimeview.rst from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Skipping "trac.mimeview.rst =
> trac.mimeview.rst [rest]": ("DistributionNotFound: docutils>=0.3.9" not
> found)
> 19:55:45 Trac[loader] DEBUG: Loading trac.mimeview.txtl from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Skipping "trac.mimeview.txtl =
> trac.mimeview.txtl [textile]": ("DistributionNotFound: textile>=2.0" not
> found)
> 19:55:45 Trac[loader] DEBUG: Loading trac.prefs from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.search from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.ticket.admin from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.ticket.batch from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.ticket.query from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.ticket.report from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.ticket.roadmap from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.ticket.web_ui from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.timeline from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.versioncontrol.admin from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.versioncontrol.svn_authz from
> /usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
> 19:55:45 Trac[loader] DEBUG: Loading trac.versioncontrol.web_ui from
> /usr/lib/pyt

[Trac] TypeError: 'NoneType' object is unsubscriptable during trac-admin resync after trac upgrade from 0.11 to 1.0.2

2014-11-02 Thread ytpo88
I just upgraded trac from 0.11 to 1.0.2. I followed the steps 1 ~ 6 
described in http://trac.edgewall.org/wiki/TracUpgrade. When I try to 
resync the project repository, I got the following error:


[root@dm-git conf]# trac-admin /usr/share/trac/projects/partiqle repository 
resync '*'
19:55:45 Trac[env] INFO:  environment 
startup [Trac 1.0.2] 
19:55:45 Trac[loader] DEBUG: Loading acct_mgr.admin from 
/usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading acct_mgr.api from 
/usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading acct_mgr.db from 
/usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading acct_mgr.htfile from 
/usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading acct_mgr.http from 
/usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading acct_mgr.macros from 
/usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading acct_mgr.notification from 
/usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading acct_mgr.pwhash from 
/usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading acct_mgr.svnserve from 
/usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading acct_mgr.web_ui from 
/usr/lib/python2.6/site-packages/TracAccountManager-0.4.3-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading git from 
/usr/lib/python2.6/site-packages/TracGit-0.11.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.about from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.admin.console from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.admin.web_ui from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.attachment from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.db.mysql from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.db.postgres from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.db.sqlite from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.mimeview.patch from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.mimeview.pygments from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Skipping "trac.mimeview.pygments = 
trac.mimeview.pygments [pygments]": ("DistributionNotFound: Pygments>=0.6" 
not found)
19:55:45 Trac[loader] DEBUG: Loading trac.mimeview.rst from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Skipping "trac.mimeview.rst = 
trac.mimeview.rst [rest]": ("DistributionNotFound: docutils>=0.3.9" not 
found)
19:55:45 Trac[loader] DEBUG: Loading trac.mimeview.txtl from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Skipping "trac.mimeview.txtl = 
trac.mimeview.txtl [textile]": ("DistributionNotFound: textile>=2.0" not 
found)
19:55:45 Trac[loader] DEBUG: Loading trac.prefs from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.search from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.ticket.admin from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.ticket.batch from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.ticket.query from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.ticket.report from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.ticket.roadmap from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.ticket.web_ui from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.timeline from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.versioncontrol.admin from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.versioncontrol.svn_authz from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.versioncontrol.web_ui from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac[loader] DEBUG: Loading trac.web.auth from 
/usr/lib/python2.6/site-packages/Trac-1.0.2-py2.6.egg
19:55:45 Trac