Print

Print


I pointed this out some time ago, but nobody appeared
to be listening...

        Barry.




On Sat, 19 Feb 2005, Kostas Georgiou wrote:

> Date: Sat, 19 Feb 2005 20:48:17 +0000
> From: Kostas Georgiou <[log in to unmask]>
> Reply-To: Testbed Support for GridPP member institutes
>     <[log in to unmask]>
> To: [log in to unmask]
> Subject: Accounting database...
>
> Hi,
>
> $ edg-gridftp-ls --verbose gsiftp://randomce/......./apel.conf
> -rw-r--r--    1 root     root      apel.conf
>
> $ head apel.conf
>    <DBURL>jdbc:mysql://thedbhost/accounting</DBURL>
>    <DBUsername>*******</DBUsername>
>    <DBPassword>*******</DBPassword>
>
> I had a look at a few uk sites and every single one has
> apel.conf world readable. I imagine everyone followed
> blindly the same recipe so all other sites have the same
> permissions :(
>
> Cheers,
> Kostas
>

---------------------------------------------------------
    Dr Barry MacEvoy
    High Energy Physics Group
    Imperial College London
    Blackett Laboratory
    Prince Consort Road         Tel:    020 7594 7802
    LONDON SW7 2BZ              Mobile: 07767 323871
    England                     Fax:    020 7823 8830
---------------------------------------------------------