[Dxspider-support] Security problem

Ian J Maude ian at gb7mbc.net
Thu Mar 31 19:21:11 BST 2005


On Thu, 2005-03-31 at 11:26 -0500, Mike McCarthy, W1NR wrote:
> Yesterday someone, either deliberately or accidentally, succeeded in
> disconnecting my console login and my main node feeds by logging in as those
> call signs.  I just discovered that the build I am running, 59.34, bumps
> existing users AND NODES off of the cluster should a duplicate login be
> performed with that call sign.  This should be prevented somehow as it opens
> the entire community to abuse.  It never allowed this before.
Dirk made this change under a LOT of pressure to do so from sysops on
this list.  The opposite was that if a user lost connection, he/she
could not login again for up to 15 minutes.  Did you capture the IP
address of the culprit?  If you can, ban his address.

Ian

-- 
Ian Maude G0VGS Morecambe Lancs UK | ian at gb7mbc.net
Sysop of GB7MBC, the Morecambe Bay Cluster
Running Linux and DXSpider | K2 #4044

DX and Cluster forums at http://www.gb7mbc.net/forum/




More information about the Dxspider-support mailing list