Re: Re: Encrpted Passwords
droolin <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
It's a matter of the unrealircd conf Eric, if I rember back to when I origionally set it up. This was the only way that an oper status was able to see the connects. That is the only reason for the global oper status. Beleive this only occurs with the unreal ircd. I thought that the origional concept was that each shell should have its own bopm? On our network, due it being set up as shell accounts. This is the only means to run an individual bopm to each ircd. Its not a matter that I want to, just that I have to. Or run them all from one server accessing all the servers, and I think that defeats the best features of the bopm. droolin > > From: Erik Fears <[email protected]> > Date: 2003/11/07 Fri PM 12:18:53 EST > To: droolin <[email protected]> > CC: Philipp Kern <[email protected]>, > Wayne <[email protected]>, [email protected] > Subject: Re: Re: [bopm] Encrpted Passwords > > On Fri, Nov 07, 2003 at 12:08:47PM -0500, droolin wrote: > > You know, i've thought about this a couple times myself and have to agree with Philipp. I kind of came to the following security procedures to make life more difficult for security purposes: > > 1). Each shell has a unique passowrd for the bopm. > > 2). The bopm password found in the unreal conf for oper purposes is cyrpted. > > 3). The bopm only requires an global oline, they should not be able to cause much damage. > > Local, I hope. BOPM should not require global privledges. > > > > 4). A csop/netadmin has the ability to remove oline status online if a security break occurs.(svsmode I think) Worse case, jupe the server. Id do that anyway, just because it was a security leak/problem. At least till the security issue was resolved. > > This is false security. You should prevent the passwords from being compromised in the first place. > > > > > I look at it this way, if the bopm oper password is compromised. It is most likely due to a person has had access to the shell, and was able to acquire this information. If a person has access to a shell, they can create their own oline. So, crypting the bopm password really dont accomplish anything. Again, another reason to just jupe the server. > > Why if the person has access to the shell they can create their own? This would only happen if BOPM was running from the same shell as the ircd. > > -Erik >