Page MenuHomeMiraheze
Feed Advanced Search

Aug 26 2018

The_Pioneer added a comment to T3520: Personal and sensitive information being sent third party by a community.

Some comments.

  1. Script removal should be done by oversighters (so that local admins cannot restore).
  2. One of the problems is that the guy who made the script has been inactive for months (see this). I'm not sure whether anyone can make a contact.
  3. Also, at least one of the admins there hosts multiple wikis; those wikis should also be investigated (I'll send a list on CVT channel if necessary).
Aug 26 2018, 22:46 · MediaWiki, acl*security
John updated the task description for T3520: Personal and sensitive information being sent third party by a community.
Aug 26 2018, 22:28 · MediaWiki, acl*security
John triaged T3520: Personal and sensitive information being sent third party by a community as Unbreak Now! priority.
Aug 26 2018, 22:28 · MediaWiki, acl*security

Aug 12 2018

Reception123 lowered the priority of T3470: cant upload a dump file from Unbreak Now! to Normal.
Aug 12 2018, 10:04 · Import, MediaWiki
Reception123 closed T3064: Discuss whether to use PediaPress or not as Invalid.
Aug 12 2018, 10:01 · acl*security, Site Reliability Engineering, MacFan4000
Reception123 closed T2011: CentralAuth vulnerability as Resolved.
Aug 12 2018, 10:01 · revi, acl*security, MediaWiki
Rappy_4187 reopened T3064: Discuss whether to use PediaPress or not as "Open".
Aug 12 2018, 08:59 · acl*security, Site Reliability Engineering, MacFan4000
Rappy_4187 reopened T2011: CentralAuth vulnerability as "Open".
Aug 12 2018, 08:58 · revi, acl*security, MediaWiki
Rappy_4187 changed the status of T3470: cant upload a dump file from Stalled to Open.
Aug 12 2018, 08:51 · Import, MediaWiki
Rappy_4187 reopened T3477: Requesting custom domain for openhatch wiki as "Open".
Aug 12 2018, 08:50 · SSL

Aug 1 2018

John closed T3443: Linode email to OPS@ received by CVT member as Resolved.

https://github.com/miraheze/puppet/commit/61d1a21dc445ca977b3d04e8aa1a24e808e43da6

Aug 1 2018, 14:09 · Mail
Reception123 updated subscribers of T3443: Linode email to OPS@ received by CVT member.
Aug 1 2018, 13:59 · Mail
Reception123 updated the task description for T3443: Linode email to OPS@ received by CVT member.
Aug 1 2018, 13:59 · Mail
Reception123 triaged T3443: Linode email to OPS@ received by CVT member as Unbreak Now! priority.
Aug 1 2018, 13:58 · Mail

Jul 31 2018

John closed T3436: Lock down sql.php to only be able to access wiki's as Resolved.

Done a minor change but this was never a security issue.

Jul 31 2018, 18:31 · Site Reliability Engineering
John added a comment to T3436: Lock down sql.php to only be able to access wiki's.

Okay, can access - but can't use.

Jul 31 2018, 18:21 · Site Reliability Engineering
NDKilla changed the visibility for T3436: Lock down sql.php to only be able to access wiki's.
Jul 31 2018, 17:06 · Site Reliability Engineering
Paladox updated subscribers of T3436: Lock down sql.php to only be able to access wiki's.
Jul 31 2018, 15:54 · Site Reliability Engineering
Paladox added a comment to T3436: Lock down sql.php to only be able to access wiki's.

I have locked down sql.php on mw* by chown root:root sql.php and chmod 0400 sql.php.

Jul 31 2018, 15:52 · Site Reliability Engineering
Reception123 lowered the priority of T3436: Lock down sql.php to only be able to access wiki's from Unbreak Now! to High.

We have changed it to root only for now, but mw-admins should still be able to use sql.php so we should find another solution.

Jul 31 2018, 15:46 · Site Reliability Engineering
Paladox added a comment to T3436: Lock down sql.php to only be able to access wiki's.

tables can also be created.

Jul 31 2018, 15:41 · Site Reliability Engineering
Paladox changed the visibility for T3436: Lock down sql.php to only be able to access wiki's.
Jul 31 2018, 15:40 · Site Reliability Engineering
Reception123 added a comment to T3436: Lock down sql.php to only be able to access wiki's.

Dropping of course does not work, but accessing any db that is not meant for mw-admins (such as phabricator_*, icinga, etc.) can be done via the SQL.php prompt

Jul 31 2018, 15:40 · Site Reliability Engineering
Paladox changed the visibility for T3436: Lock down sql.php to only be able to access wiki's.
Jul 31 2018, 15:40 · Site Reliability Engineering
Paladox changed the edit policy for T3436: Lock down sql.php to only be able to access wiki's.
Jul 31 2018, 15:38 · Site Reliability Engineering
Paladox changed the edit policy for T3436: Lock down sql.php to only be able to access wiki's.
Jul 31 2018, 15:37 · Site Reliability Engineering
Paladox raised the priority of T3436: Lock down sql.php to only be able to access wiki's from High to Unbreak Now!.
Jul 31 2018, 15:37 · Site Reliability Engineering
Paladox created T3436: Lock down sql.php to only be able to access wiki's.
Jul 31 2018, 15:36 · Site Reliability Engineering

Jul 26 2018

Southparkfan removed a member for acl*security: revi.
Jul 26 2018, 14:49

Jun 3 2018

MacFan4000 added a watcher for acl*security: MacFan4000.
Jun 3 2018, 21:07

May 30 2018

John changed the edit policy for T3162: Upgrade git to 2.17.1.
May 30 2018, 14:21 · Site Reliability Engineering, acl*security
John closed T3162: Upgrade git to 2.17.1 as Resolved.
May 30 2018, 14:20 · Site Reliability Engineering, acl*security
Paladox added a comment to T3162: Upgrade git to 2.17.1.

All hosts updated now.

May 30 2018, 11:41 · Site Reliability Engineering, acl*security
Paladox added a comment to T3162: Upgrade git to 2.17.1.

2.17.1 is now able to be downloaded just upgraded misc1.

May 30 2018, 11:38 · Site Reliability Engineering, acl*security
Herald triaged T3165: Re: Research on Things to do in Italy as Unbreak Now! priority.
May 30 2018, 07:07 · Trash

May 29 2018

Paladox updated subscribers of T3162: Upgrade git to 2.17.1.
May 29 2018, 23:53 · Site Reliability Engineering, acl*security
Paladox added a project to T3162: Upgrade git to 2.17.1: Site Reliability Engineering.
May 29 2018, 23:35 · Site Reliability Engineering, acl*security
Paladox added a comment to T3162: Upgrade git to 2.17.1.

I updated my git's earlier today with homebrew without realising it was security update.

May 29 2018, 23:35 · Site Reliability Engineering, acl*security
Paladox added a comment to T3162: Upgrade git to 2.17.1.

I did salt -E ".*" cmd.run "apt-get -t stretch-backports install git -y" which installed git 2.17.0 but 2.17.1 is shown on https://packages.debian.org/stretch-backports/git but it's not installing with apt-get -t stretch-backports install git -y. I did do a apt-get update to make sure and still dosen't install 2.17.1

May 29 2018, 23:32 · Site Reliability Engineering, acl*security
labster created T3162: Upgrade git to 2.17.1.
May 29 2018, 22:58 · Site Reliability Engineering, acl*security

May 28 2018

Paladox changed the visibility for T3155: Update mariadb packages on db4..
May 28 2018, 20:44 · acl*security, Site Reliability Engineering
Paladox closed T3155: Update mariadb packages on db4. as Resolved.
May 28 2018, 20:43 · acl*security, Site Reliability Engineering
John claimed T3155: Update mariadb packages on db4..
May 28 2018, 18:33 · acl*security, Site Reliability Engineering
John closed T3156: Do a service check as Invalid.

I'm going to close this as invalid because;

May 28 2018, 18:20 · Site Reliability Engineering, acl*security
Paladox shifted T3156: Do a service check from the Restricted Space space to the S1 Public space.
May 28 2018, 16:05 · Site Reliability Engineering, acl*security
Southparkfan changed the visibility for T3155: Update mariadb packages on db4..
May 28 2018, 16:05 · acl*security, Site Reliability Engineering
John added a comment to T3156: Do a service check.

“checking all services that we have to make sure they are documented” this has been something we’ve been trying to do since July 2015 I swear

May 28 2018, 15:08 · Site Reliability Engineering, acl*security
MacFan4000 changed the edit policy for T3156: Do a service check.
May 28 2018, 11:24 · Site Reliability Engineering, acl*security
MacFan4000 added a project to T3155: Update mariadb packages on db4.: acl*security.
May 28 2018, 11:23 · acl*security, Site Reliability Engineering
Paladox created T3156: Do a service check.
May 28 2018, 10:17 · Site Reliability Engineering, acl*security

May 24 2018

Herald triaged T3135: Research on Things to do in Italy as Unbreak Now! priority.
May 24 2018, 03:56 · Trash

May 20 2018

Paladox shifted T2674: External Auth on all logins from the Restricted Space space to the S1 Public space.
May 20 2018, 23:24 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
Paladox closed T2674: External Auth on all logins as Resolved by committing Unknown Object (Diffusion Commit).
May 20 2018, 23:21 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering

May 17 2018

Paladox added a comment to T3108: Make sure we are in compliance with the GDPR.

Legal is different to security.

May 17 2018, 15:09 · Site Reliability Engineering, MacFan4000
MacFan4000 added a project to T3108: Make sure we are in compliance with the GDPR: acl*security.

I'm pretty sure security is valid since this is dealing with legal stuff in europe.

May 17 2018, 14:49 · Site Reliability Engineering, MacFan4000
Paladox added a comment to T3108: Make sure we are in compliance with the GDPR.

Cc @labster wondering do you have any opinion on this? :)

May 17 2018, 08:10 · Site Reliability Engineering, MacFan4000
MacFan4000 raised the priority of T3108: Make sure we are in compliance with the GDPR from High to Unbreak Now!.
May 17 2018, 01:11 · Site Reliability Engineering, MacFan4000

May 16 2018

Paladox changed the visibility for T3108: Make sure we are in compliance with the GDPR.
May 16 2018, 21:46 · Site Reliability Engineering, MacFan4000
Paladox changed the edit policy for T3108: Make sure we are in compliance with the GDPR.
May 16 2018, 21:46 · Site Reliability Engineering, MacFan4000
Paladox added a comment to T3108: Make sure we are in compliance with the GDPR.

Maybe UBN?

May 16 2018, 21:05 · Site Reliability Engineering, MacFan4000
Herald added a project to T3108: Make sure we are in compliance with the GDPR: MacFan4000.
May 16 2018, 21:05 · Site Reliability Engineering, MacFan4000

May 15 2018

Paladox added a comment to T2674: External Auth on all logins.

We need to get this to work by not auto logging into the wiki's, but we carn't seem to get it working.

May 15 2018, 15:00 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
revi added a comment to T2674: External Auth on all logins.

What's to be done here?

May 15 2018, 14:50 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering

May 9 2018

John added a comment to T2674: External Auth on all logins.

3 months for a security task is quite poor now as a FYI for people here.

May 9 2018, 13:29 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
John closed T3064: Discuss whether to use PediaPress or not as Invalid.
May 9 2018, 11:13 · acl*security, Site Reliability Engineering, MacFan4000

May 5 2018

John shifted T3064: Discuss whether to use PediaPress or not from the Restricted Space space to the S1 Public space.
May 5 2018, 00:18 · acl*security, Site Reliability Engineering, MacFan4000

May 4 2018

MacFan4000 shifted T3064: Discuss whether to use PediaPress or not from the S1 Public space to the Restricted Space space.
May 4 2018, 23:48 · acl*security, Site Reliability Engineering, MacFan4000
Paladox added a comment to T3064: Discuss whether to use PediaPress or not.

The Wikimedia Foundation have decided that they will outsource there pdf efforts (ie they will not be hosting it now). They have an agreement with pediapress to host the pdfs for them.

May 4 2018, 22:47 · acl*security, Site Reliability Engineering, MacFan4000
NDKilla added a project to T3064: Discuss whether to use PediaPress or not: acl*security.

@Reception123 @labster I'm pretty sure Security is valid because there were mentioned concerns about outsourcing anything related to the content of private wikis.

May 4 2018, 22:41 · acl*security, Site Reliability Engineering, MacFan4000
MacFan4000 shifted T3064: Discuss whether to use PediaPress or not from the Restricted Space space to the S1 Public space.
May 4 2018, 18:40 · acl*security, Site Reliability Engineering, MacFan4000
Reception123 added a comment to T3064: Discuss whether to use PediaPress or not.

@MacFan4000 Why "Security"?

May 4 2018, 18:20 · acl*security, Site Reliability Engineering, MacFan4000
Herald added a project to T3064: Discuss whether to use PediaPress or not: MacFan4000.
May 4 2018, 18:16 · acl*security, Site Reliability Engineering, MacFan4000

Apr 29 2018

John assigned T2674: External Auth on all logins to Paladox.
Apr 29 2018, 23:18 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering

Apr 26 2018

John added a member for acl*security: MacFan4000.
Apr 26 2018, 23:30
Reception123 removed a member for acl*security: labster.
Apr 26 2018, 17:16
Reception123 removed a member for acl*security: ImBoPhil.
Apr 26 2018, 17:16

Apr 21 2018

Vlad26t created T3017: Київстар.
Apr 21 2018, 07:58 · MediaWiki

Apr 17 2018

Paladox added a project to P49 (An Untitled Masterwork): acl*security.
Apr 17 2018, 20:20

Apr 11 2018

Reception123 added a member for acl*security: Paladox.
Apr 11 2018, 14:19

Apr 10 2018

John added a comment to T2674: External Auth on all logins.

@Southparkfan because it made logins on all custom domains impossible.

Apr 10 2018, 23:09 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
Southparkfan added a comment to T2674: External Auth on all logins.

Why was this change reverted? This auto-login vector is a security vulnerability (since the custom domains are not under our control) and DoS vector (one auto-login generates more than 250 web requests in just a few seconds. It's impossible to handle those with just 12 virtual cores!).

Apr 10 2018, 22:06 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering

Apr 1 2018

Reception123 updated subscribers of T2674: External Auth on all logins.

@John Ok

Apr 1 2018, 07:06 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering

Mar 30 2018

John added a comment to T2674: External Auth on all logins.

@Reception123 fyi you shouldn't have moved this to S2 but changed the policy to allow only Security+me (because I made this task and I could have looked into this way way earlier).

Mar 30 2018, 22:37 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
John added a member for acl*security: John.
Mar 30 2018, 21:08

Feb 23 2018

Southparkfan added a comment to T2674: External Auth on all logins.

FYI, this may also be the cause of >95% of the 503 errors.

Feb 23 2018, 09:25 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering

Feb 5 2018

revi placed T2674: External Auth on all logins up for grabs.
Feb 5 2018, 18:15 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
Reception123 reopened T2674: External Auth on all logins as "Open".

This is still a concern, as any malicious user could in theory still do this.

Feb 5 2018, 17:24 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
Reception123 updated subscribers of T2674: External Auth on all logins.
Feb 5 2018, 17:23 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
Reception123 shifted T2674: External Auth on all logins from the S1 Public space to the Restricted Space space.
Feb 5 2018, 17:22 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering

Feb 1 2018

John added a comment to T2674: External Auth on all logins.

For security reasons it may be better to disable this feature for all domains not in staff control.

Feb 1 2018, 17:26 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
Southparkfan added a comment to T2674: External Auth on all logins.

For security reasons it may be better to disable this feature for all domains not in staff control.

Feb 1 2018, 13:20 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
John closed T2674: External Auth on all logins as Resolved.
Feb 1 2018, 13:15 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
John added a comment to T2674: External Auth on all logins.

Seems to be good now.

Feb 1 2018, 13:15 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
revi moved T2674: External Auth on all logins from Incoming to Config on the revi board.
Feb 1 2018, 13:11 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
revi added a comment to T2674: External Auth on all logins.

Committed b0517d9a309290bbd00aad2bf5f470d663665923, please verify.

Feb 1 2018, 13:11 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
revi claimed T2674: External Auth on all logins.

ACK

Feb 1 2018, 13:06 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
Herald added a project to T2674: External Auth on all logins: MacFan4000.
Feb 1 2018, 12:03 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering
John triaged T2674: External Auth on all logins as Unbreak Now! priority.
Feb 1 2018, 11:36 · revi, MacFan4000, acl*security, Configuration, Site Reliability Engineering

Jan 26 2018

revi shifted T2659: "miraheze" from the Restricted Space space to the S1 Public space.
Jan 26 2018, 20:14 · Trash
revi closed T2659: "miraheze" as Invalid.

Fuck off spam

Jan 26 2018, 20:13 · Trash