Re: Security incident on Fedora infrastructure on 23 Jan 2011

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, Jan 25, 2011 at 10:14:23AM +1000, Jared K. Smith wrote:

> The account in question was not a member of any sysadmin or Release Engineering
> groups. The following is a complete list of privileges on the account:
>  * SSH to fedorapeople.org (user permissions are very limited on this machine).
>  * Push access to packages in the Fedora SCM.
>  * Ability to perform builds and make updates to Fedora packages.

Did he really not have write access to the Fedora wiki or the different
trac instances (wiki, ticket system) on fedorahosted? I am not sure how
it is handled, but he also might have had push access to the comps repo
on fedorahosted.

Additionally it would be nice to investigate whether the account was
used to access the test machine resources for package maintainers:
https://fedoraproject.org/wiki/Test_Machine_Resources_For_Package_Maintainers

Regards
Till

Attachment: pgpFg5BBzDwyi.pgp
Description: PGP signature

-- 
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/devel

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux