Tuesday, 2010-12-14

*** Joins: dhx1 (~anonymous@c122-107-170-247.eburwd5.vic.optusnet.com.au)00:00
*** Joins: scribe9343423 (~scribe934@static.96.23.63.178.clients.your-server.de)00:00
*** Joins: iip2 (~iip2@2a01:e35:2ef3:b360::f4:9e)00:00
*** Joins: dagb (~dagb@91.84-48-174.nextgentel.com)00:00
*** Joins: killefiz (~sven@fedora/pdpc.base.killefiz)00:00
*** Joins: Ragnor (~Ragnor@dslb-188-100-045-138.pools.arcor-ip.net)00:00
*** Joins: mellen (~thansen@x1-6-00-22-02-00-0c-40.k1109.webspeed.dk)00:00
*** Joins: CIA-28 (~CIA@208.69.182.149)00:00
*** Joins: tavasti (~tavasti@ov1.tavasti.fi)00:00
*** Joins: webnom (~Adium@ip68-6-124-216.sb.sd.cox.net)01:02
*** Quits: micahg (~micah@ubuntu/member/micahg) (Ping timeout: 255 seconds)01:03
webnomI have a MantisBT question. Am I in the right spot?01:04
*** Joins: micahg (~micah@ubuntu/member/micahg)01:06
*** Quits: Ragnor (~Ragnor@dslb-188-100-045-138.pools.arcor-ip.net) (Disconnected by services)01:07
*** Joins: Ragnor (~Ragnor@dslb-188-100-045-138.pools.arcor-ip.net)01:07
*** Quits: killefiz (~sven@fedora/pdpc.base.killefiz) (*.net *.split)01:10
*** Joins: killefiz (~sven@fedora/pdpc.base.killefiz)01:10
*** Quits: mellen (~thansen@x1-6-00-22-02-00-0c-40.k1109.webspeed.dk) (Ping timeout: 240 seconds)01:13
*** Joins: mellen (~thansen@x1-6-00-22-02-00-0c-40.k1109.webspeed.dk)01:14
*** Quits: micahg (~micah@ubuntu/member/micahg) (Quit: Leaving.)01:40
*** Joins: micahg (~micah@ubuntu/member/micahg)01:42
*** Quits: giallu (~giallu@fedora/giallu) (Ping timeout: 245 seconds)01:51
*** Joins: siebrand (~beis@535392CA.cm-6-4c.dynamic.ziggo.nl)02:23
*** Joins: Cupertino (~Cupez@unaffiliated/cupertino)02:24
*** Quits: siebrand (~beis@535392CA.cm-6-4c.dynamic.ziggo.nl) (Ping timeout: 250 seconds)02:32
*** Joins: djSupport (~djsupport@188-221-240-190.zone12.bethere.co.uk)02:37
*** Joins: giallu (~giallu@fedora/giallu)02:38
*** Joins: kirillka (~Miranda@195.242.142.17)02:43
*** Quits: webnom (~Adium@ip68-6-124-216.sb.sd.cox.net) (Quit: Leaving.)02:45
CIA-28Mantisbt: vboctor master-1.2.x * rc6295994a062 /admin/upgrade_unattended.php: Fix #12607: LFI/FD and XSS in the upgrade_unattended.php03:01
CIA-28Mantisbt: vboctor * r2af6e8ddc46e /admin/upgrade_unattended.php: Fix #12607: LFI/FD and XSS in the upgrade_unattended.php03:01
*** Quits: kirillka (~Miranda@195.242.142.17) (Read error: Connection reset by peer)03:14
*** Joins: kirillka (~Miranda@195.242.142.17)03:15
CIA-28Mantisbt: vboctor master-1.2.x * r1efe5be6c7a5 /admin/upgrade_unattended.php: Fix #12607: LFI/FD and XSS in the upgrade_unattended.php - part 203:25
CIA-28Mantisbt: vboctor * r184a0f4a06e9 /admin/upgrade_unattended.php: Fix #12607: LFI/FD and XSS in the upgrade_unattended.php - part 203:25
dhx1nuclear_eclipse: ping03:41
dhx1giallu: ping03:43
giallupong03:43
gialluuhm. upgrade_unattended...03:43
gialluI thought it was not functional since a good time03:44
dhx1giallu: you don't happen to know anyone on the RH/Fedora security teams that could assign a CVE?03:44
dhx1yeah I have no idea what that file does03:44
dhx1it's low impact anyway because we throw up warnings if a user leaves the /admin/ directory in place03:45
gialludhx1, it was an attempt at a shell script to perform the upgrade without user intervention03:45
gialluto be used in distro packages upgrades, eventually03:45
gialluanyway, I think you make a report in bugzilla, mark it "security" and let them handle it03:46
*** Quits: tavasti (~tavasti@ov1.tavasti.fi) (Ping timeout: 272 seconds)03:46
dhx1giallu: it looks like it is far from accomplishing those goals... it uses gpc_ functions that aren't going to work in PHP CLI mode03:46
gialluuhm03:47
gialluthen my memory fails03:47
dhx1as $_POST and $_GET are undefined in that situation :)03:47
dhx1I think you're close... it is outputting plain text instead of HTML03:47
*** Joins: tavasti (~tavasti@ov1.tavasti.fi)03:53
*** Quits: tavasti (~tavasti@ov1.tavasti.fi) (Max SendQ exceeded)03:53
*** Joins: tavasti (~tavasti@ov1.tavasti.fi)03:54
*** Quits: tavasti (~tavasti@ov1.tavasti.fi) (Max SendQ exceeded)03:54
*** Quits: CIA-28 (~CIA@208.69.182.149) (Ping timeout: 272 seconds)03:56
*** Joins: tavasti (~tavasti@ov1.tavasti.fi)03:57
*** Joins: CIA-15 (~CIA@208.69.182.149)03:57
*** Joins: siebrand (~beis@535392CA.cm-6-4c.dynamic.ziggo.nl)03:57
dhx1giallu: I don't think those bugs actually exist from my inspections so far04:25
dhx1giallu: it could be someone running an old version of ADOdb that has security flaws within the Connect function that takes the db_type parameter04:25
*** Quits: djSupport (~djsupport@188-221-240-190.zone12.bethere.co.uk) (Read error: Connection reset by peer)04:36
*** Quits: siebrand (~beis@535392CA.cm-6-4c.dynamic.ziggo.nl) ()04:49
*** Joins: Al_Chapone (~chatzilla@ATuileries-153-1-77-170.w83-202.abo.wanadoo.fr)04:58
*** Joins: paulr (~a@212.85.5.19)06:00
*** Joins: Github (~Github@sh1-ext.rs.github.com)06:30
Githubmantisbt: master Victor Boctor * 2af6e8d (1 files in 1 dirs): Fix #12607: LFI/FD and XSS in the upgrade_unattended.php06:30
Githubmantisbt: master Victor Boctor * 184a0f4 (1 files in 1 dirs): Fix #12607: LFI/FD and XSS in the upgrade_unattended.php - part 206:30
Githubmantisbt: master commits 2a7fe6d...184a0f4 - http://bit.ly/f6WDTe06:30
*** Parts: Github (~Github@sh1-ext.rs.github.com)06:30
*** Joins: Github (~Github@sh1-ext.rs.github.com)06:30
Githubmantisbt: master-1.2.x Victor Boctor * c629599 (1 files in 1 dirs): Fix #12607: LFI/FD and XSS in the upgrade_unattended.php06:30
Githubmantisbt: master-1.2.x Victor Boctor * 1efe5be (1 files in 1 dirs): Fix #12607: LFI/FD and XSS in the upgrade_unattended.php - part 206:30
Githubmantisbt: master-1.2.x commits 93b32ea...1efe5be - http://bit.ly/eoJMds06:30
*** Parts: Github (~Github@sh1-ext.rs.github.com)06:30
*** Quits: Al_Chapone (~chatzilla@ATuileries-153-1-77-170.w83-202.abo.wanadoo.fr) (Ping timeout: 272 seconds)06:56
*** Joins: Al_Chapone (~chatzilla@ATuileries-153-1-77-170.w83-202.abo.wanadoo.fr)08:01
*** Joins: feathersanddown (~feathersa@200.111.27.196)09:25
feathersanddownHi people, i want to know what means 'categories' in a project09:26
feathersanddownhttp://www.mantisbt.org/wiki/doku.php/mantisbt:global_categories_requirements <-- still can't understand that09:26
*** Quits: tsnfoo (~tsnfoo@ws-intelimac3.test.denison.edu) (Quit: tsnfoo)09:31
*** Quits: kirillka (~Miranda@195.242.142.17) (Quit: kirillka)10:13
*** Quits: Cupertino (~Cupez@unaffiliated/cupertino) (Quit: I give up...)11:00
*** Joins: Al_Chapone_ (~chatzilla@ATuileries-153-1-77-170.w83-202.abo.wanadoo.fr)11:01
*** Quits: Al_Chapone (~chatzilla@ATuileries-153-1-77-170.w83-202.abo.wanadoo.fr) (Ping timeout: 240 seconds)11:03
*** Al_Chapone_ is now known as Al_Chapone11:03
*** Joins: killefiz_ (~sven@fedora/pdpc.base.killefiz)11:18
*** Quits: killefiz (~sven@fedora/pdpc.base.killefiz) (*.net *.split)11:23
*** killefiz_ is now known as killefiz11:31
*** Joins: MrGlass (~mrglass@cpe-66-108-105-205.nyc.res.rr.com)11:34
MrGlasshi. i am trying to migrate all my companies stuff to a VPS. we are using mantis for bug tracking. I copied over the install directory, migrated my database, and edited config_inc.php to reflect my new DB name, user, and pw.11:36
MrGlassi keep getting db fail errors, saying access denied11:37
*** Parts: MrGlass (~mrglass@cpe-66-108-105-205.nyc.res.rr.com)11:42
*** Quits: paulr (~a@212.85.5.19) ()11:53
*** Joins: siebrand (~beis@535392CA.cm-6-4c.dynamic.ziggo.nl)12:10
*** Quits: Al_Chapone (~chatzilla@ATuileries-153-1-77-170.w83-202.abo.wanadoo.fr) (Quit: ChatZilla 0.9.86 [Firefox 3.6.13/20101203075014])12:15
*** Quits: giallu (~giallu@fedora/giallu) (Ping timeout: 272 seconds)12:16
*** Joins: tsnfoo (~tsnfoo@ws-intelimac3.test.denison.edu)12:16
*** Joins: moto-moi (~hylke@2001:888:13e4:0:21f:e2ff:fe0c:ce28)12:38
*** Quits: feathersanddown (~feathersa@200.111.27.196) (Remote host closed the connection)12:44
*** Joins: giallu (~giallu@fedora/giallu)13:21
*** Joins: djSupport (~djsupport@188-221-240-190.zone12.bethere.co.uk)13:27
*** Quits: micahg (~micah@ubuntu/member/micahg) (Ping timeout: 265 seconds)13:43
*** Quits: djSupport (~djsupport@188-221-240-190.zone12.bethere.co.uk) (Remote host closed the connection)16:01
*** Joins: micahg (~micah@ubuntu/member/micahg)16:54
*** Joins: LiquidWorm (~jox@92.53.11.102)17:02
dhx1nuclear_eclipse: ping17:34
nuclear_eclipsehi dhx1 17:34
dhx1nuclear_eclipse: can we roll out a 1.2.4 tarball ASAP? :)17:35
nuclear_eclipsezounds, I probably meant to do that a few weeks ago, eh?17:35
dhx1nuclear_eclipse: well the reason for me asking is due to a fairly major security problem (which you probably know about from the emails I've sent)17:36
nuclear_eclipseoh, the one Victor came back from the dead to commit fixes for?17:36
dhx1yep hehe :)17:36
nuclear_eclipseyeah, if you can put together a summary of the security problem/fix for the release notes, I'll try to get that together tonight or tomorrow17:37
nuclear_eclipseI haven't actually read any of the emails yet17:37
nuclear_eclipseand it's dinner time now...17:37
dhx1nuclear_eclipse: ok I'll send you change notes ASAP17:37
dhx1nuclear_eclipse: thanks :)17:37
nuclear_eclipsecheers17:37
dhx1nuclear_eclipse: do you use nginx by any chance?17:39
*** Quits: moto-moi (~hylke@2001:888:13e4:0:21f:e2ff:fe0c:ce28) (Read error: Operation timed out)18:21
CIA-15Mantisbt: hickseydr * r974e6da4a2f0 /admin/upgrade_unattended.php: Fix #12607: LFI/PD/XSS in upgrade_unattended.php18:51
CIA-15Mantisbt: hickseydr master-1.2.x * rd67c4debcacf /admin/upgrade_unattended.php: Fix #12607: LFI/PD/XSS in upgrade_unattended.php18:51
CIA-15Mantisbt: hickseydr master-1.1.x * r2641fdc60d20 /admin/upgrade_unattended.php: Fix #12607: LFI/PD/XSS in upgrade_unattended.php18:58
*** Quits: scribe9343423 (~scribe934@static.96.23.63.178.clients.your-server.de) (Remote host closed the connection)19:00
*** Joins: scribe9343423 (~scribe934@static.96.23.63.178.clients.your-server.de)19:00
*** Joins: LiquidWormio (~jox@92.53.11.102)19:00
*** Quits: LiquidWorm (~jox@92.53.11.102) (Ping timeout: 240 seconds)19:04
CIA-15Mantisbt: hickseydr * r065c99c30f69 /doc/INSTALL: Fix #12607: Update installation instructions regarding admin directory19:07
CIA-15Mantisbt: hickseydr master-1.2.x * r54aace939c16 /doc/INSTALL: Fix #12607: Update installation instructions regarding admin directory19:07
dhx1ugh I screwed that up19:17
dhx1schema.php in admin/ is checked by login_page.php :(19:17
dhx1wait, not quite... :)19:19
CIA-15Mantisbt: hickseydr master-1.2.x * r77de677023ab /login_page.php: Fix #12607: Improve admin directory check on login_page19:26
CIA-15Mantisbt: hickseydr * r970630aa8c04 /login_page.php: Fix #12607: Improve admin directory check on login_page19:26
dhx1nuclear_eclipse: ready for packaging :)19:42
CIA-15Mantisbt: hickseydr master-1.2.x * rd066f095ceab / (core/constant_inc.php doc/RELEASE): Prepare for MantisBT 1.2.4 release19:42
*** Quits: LiquidWormio (~jox@92.53.11.102) (Ping timeout: 276 seconds)20:20
*** Joins: LiquidWorm (~jox@92.53.11.102)20:23
*** Quits: micahg (~micah@ubuntu/member/micahg) (Ping timeout: 240 seconds)20:36
nuclear_eclipsedhx1: building the tarballs atm21:10
nuclear_eclipsegotta relearn how to upload them...21:10
LiquidWorm:)21:10
LiquidWormhi John21:11
nuclear_eclipsehello21:11
LiquidWormim Gjoko21:11
nuclear_eclipsegotta update the mantisbt.org tracker too21:11
LiquidWormyou just do ur thing, and say the word ;)21:11
nuclear_eclipseLiquidWorm: it'll probably be about 20 minutes or so before I get everything ready and can make the release announcements21:12
LiquidWormyeah not a problem21:13
nuclear_eclipsehmm, it seems that sf.net ha s a new file upload system21:16
dhx1nuclear_eclipse: I think it has a new file upload system every time we make a new release? :p21:20
dhx1nuclear_eclipse: we should remove /admin/ from the server21:21
nuclear_eclipsedhx1: I thought it was protected by .htaccess...21:21
dhx1nuclear_eclipse: nope... :(21:22
nuclear_eclipseoops, just realized that I built the tarballs without docbook...21:22
nuclear_eclipsesigh21:22
dhx1nuclear_eclipse: 1.2.4 will actually throw up a warning if the "admin" directory exists so htaccess/changing permissions on the folder is no longer good enough21:23
nuclear_eclipseapparently I didn't have the docbook packages installed on my home machine, and I've been using my server for building the last few sets of tarballs 21:23
dhx1aha21:23
nuclear_eclipsedhx1: umm, doesn't that break the ability to run mantis from a git repo?21:23
dhx1nuclear_eclipse: no, it only shows a warning (which can be ignored)21:24
nuclear_eclipseoh, ok21:24
nuclear_eclipsedhx1: that's the reason the admin folder is still there on the mantisbt.org server, because it's running from a repo clone21:25
nuclear_eclipsethat way I only have to do `git pull` to bring it up to date21:25
dhx1nuclear_eclipse: ah ok, I guess it just needs git pull && rm -R admin21:25
nuclear_eclipsedhx1: or just add a .htaccess rule to protect that folder :P21:26
dhx1nuclear_eclipse: that'll still show the warning in 1.2.421:26
nuclear_eclipsedhx1: you can turn off the warnings ;)21:27
nuclear_eclipsebecause that's exactly what I've been doing on my own server21:27
dhx1nuclear_eclipse: you can turn off CSRF too... :p21:27
nuclear_eclipsereuploading....21:28
dhx1and actually, you can turn off XSS protection too heh21:28
dhx1thanks21:28
nuclear_eclipseyeah, but turning off the admin folder warning is not actually a security risk if you're doing something to prevent it from being accessed21:28
dhx1at least most of our users won't know how to turn off the warning21:30
dhx1I don't see the point in keeping /admin/ anyhow21:31
dhx1git pull will replace it21:31
nuclear_eclipsedhx1: because it's an extra step that I don't want to rely on people remembering to do :P21:31
nuclear_eclipseyay, new tarballs are up21:32
dhx1nuclear_eclipse: true...21:32
nuclear_eclipseomg, srs?21:35
nuclear_eclipseok, phew21:36
nuclear_eclipseI downloaded the .zip from sf.net to test and it was corrupted...21:37
dhx1I can confirm the tar.gz is OK21:37
nuclear_eclipsehad to re-download to get a good copy21:37
dhx1but SF is taking a while to distribute it thus it is possible to download partial files at the moment21:37
dhx1yep21:37
nuclear_eclipseok, dropping the release announcements21:37
dhx1then *cough* ahem /admin/ on the server :)21:38
nuclear_eclipsethat's still my favorite command21:39
dhx1http://www.mantisbt.org/bugs/admin/test_langs.php throws errors before "access denied"... great script21:39
nuclear_eclipseroot@mantis:/var/www/html/bugs# rm -r admin/21:42
nuclear_eclipseroot@mantis:/var/www/html/bugs#21:42
nuclear_eclipsedhx1: happy now?21:42
dhx1:)21:42
dhx1I don't trust anything in admin/ and scripts/21:42
dhx1legacy cruft... :)21:42
nuclear_eclipseanywho, bedtime for me21:43
dhx1thanks for pushing the tarballs21:43
dhx1the announcement ML has a post too?21:43
nuclear_eclipseyeah, but that one always takes forever to propogate21:44
nuclear_eclipseI assume it's a giant list of subscribers21:44
nuclear_eclipseoh, just got it :)21:44
nuclear_eclipsew2g sf.net, everything actually went *smoothly* for a change21:44
dhx1haha21:45
nuclear_eclipseand their new file management interface is actually *simple* and *easy* to use21:45
dhx1thanks :)21:45
CIA-15Mantisbt: hickseydr * r99deb817006f /admin/test_langs.php: Move admin access check to top of test_langs script21:45
CIA-15Mantisbt: hickseydr master-1.2.x * r51d4164416fe /admin/test_langs.php: Move admin access check to top of test_langs script21:45
nuclear_eclipse /smack dhx121:45
dhx1hehe, fast response or what? :)21:45
nuclear_eclipsegreat, now we need to release 1.2.5... :P21:45
dhx1it's not a problem because people shouldn't have admin/ on live sites :)21:46
dhx1+ the information that *could* be leaked isn't very sensitive21:46
nuclear_eclipse;)21:46
dhx1LiquidWorm: we're ready for the advisories now :)21:46
dhx1nuclear_eclipse: thanks for pushing this tarball through21:47
nuclear_eclipsenp21:47
LiquidWormthanks21:47
LiquidWorm:D21:47
dhx1one day I have to set myself up with SF access, etc21:47
LiquidWormgood job21:47
LiquidWormis http://www.mantisbt.org/bugs/view.php?id=12607 viewable now ?21:47
dhx1clickety, now it is21:48
*** Quits: siebrand (~beis@535392CA.cm-6-4c.dynamic.ziggo.nl) (Ping timeout: 276 seconds)21:48
LiquidWormoh my21:50
*** Joins: alcidae (~ferris@c-68-38-222-142.hsd1.nj.comcast.net)21:54
alcidaeHello, I have a couple of quick questions if someone would be so kind.  1) Can you set the minimum threshold for input of a builtin field like Priority to someone higher than Reporter.   I know you can do it for custom fields but don't see where to do it for builtins.21:57
alcidaeand 2) Can you set a default assignee per category for each project so it does not always need to be manually assigned?   Thanks in advance.21:58
nuclear_eclipsealcidae: you can't change thresholds for most of the builtin fields22:00
nuclear_eclipseyou can assign a user to each category though, and it will auto-assign the issue to that user if the reporter has not already assigned someone to the issue22:01
LiquidWormit is done :)22:01
LiquidWormthanks22:01
dhx1LiquidWorm: bugtraq?22:02
alcidaenuclear_eclipse: assign a user to a category?   OK.22:02
LiquidWormyes, bugtraq2@ :)22:03
dhx1LiquidWorm: cheers :)22:03
LiquidWormcheers!22:04
alcidaenuclear_eclipse: I was drawing the same conclusion about thresholds for builtins.  As far as assigning a category,  just to clarify : if a reporter does not assign then it will be automatically assigned to the user for that category ?22:08
nuclear_eclipseyes22:09
alcidaenuclear_eclipse: Great.  One last question, will the assignee always get an email or can the assignee turn this off through their own profile (I'd rather they be unable to disable this)?22:13
nuclear_eclipsetbh I'm not 100% sure22:14
nuclear_eclipseemail notification seems to be one of the iffy portions of mantisbt22:14
*** Quits: LiquidWorm (~jox@92.53.11.102) (Read error: Connection reset by peer)22:15
*** Joins: LiquidWorm (~jox@92.53.11.102)22:22
alcidaenuclear_eclipse: I think that I will have to go test with a (test) developer account to see what can be turned off when $g_default_email_on_assigned = ON;22:28
*** Joins: micahg (~micah@ubuntu/member/micahg)22:41
*** Quits: LiquidWorm (~jox@92.53.11.102) ()22:46
*** Parts: alcidae (~ferris@c-68-38-222-142.hsd1.nj.comcast.net)22:47
*** Quits: micahg (~micah@ubuntu/member/micahg) (Ping timeout: 255 seconds)22:59
dhx1nuclear_eclipse: channel title? :)23:01
*** Joins: micahg (~micah@ubuntu/member/micahg)23:36

Generated by irclog2html.py 2.9.2 by Marius Gedminas - find it at mg.pov.lt!