[Geoserver-devel] geoserver.org rated "Red" security risk by McAfee

Just reporting from the field. McAfee "SiteAdvisor" is installed by
company policy. I'm not sure how to follow this up.

Rob Atkinson ha scritto:

Just reporting from the field. McAfee "SiteAdvisor" is installed by
company policy. I'm not sure how to follow this up.

Hmmm:
http://www.siteadvisor.nl/sites/geoserver.org/summary/

After providing the mail to the site they received spam?
Not sure what that means. Did they try to register into confluence?

Cheers
Andrea

--
Andrea Aime
OpenGeo - http://opengeo.org
Expert service straight from the developers.

Try this:

http://geoserver.org/browsepeople.action?startIndex=

-Miles

-----Original Message-----
From: Andrea Aime [mailto:aaime@…1501…]
Sent: Friday, 20 November 2009 9:13 AM
To: Rob Atkinson
Cc: Geoserver-devel
Subject: Re: [Geoserver-devel] geoserver.org rated "Red" security risk
by [SEC=Unclassified] McAfee [SEC=Unclassified]

Rob Atkinson ha scritto:
> Just reporting from the field. McAfee "SiteAdvisor" is installed by
> company policy. I'm not sure how to follow this up.

Hmmm:
http://www.siteadvisor.nl/sites/geoserver.org/summary/

After providing the mail to the site they received spam?
Not sure what that means. Did they try to register into confluence?

Cheers
Andrea

--
Andrea Aime
OpenGeo - http://opengeo.org
Expert service straight from the developers.

-----------------------------------------------------------------------
-------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008
30-Day
trial. Simplify your report design, integration and deployment - and
focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now. http://p.sf.net/sfu/bobj-july
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

___________________________________________________________________________

    Australian Antarctic Division - Commonwealth of Australia
IMPORTANT: This transmission is intended for the addressee only. If you are not the
intended recipient, you are notified that use or dissemination of this communication is
strictly prohibited by Commonwealth law. If you have received this transmission in error,
please notify the sender immediately by e-mail or by telephoning +61 3 6232 3209 and
DELETE the message.
        Visit our web site at http://www.antarctica.gov.au/
___________________________________________________________________________

yikes - time for some moderation! Or dump this completely - obvuiously
no-ones using it.

On Fri, Nov 20, 2009 at 10:53 AM, Miles Jordan <Miles.Jordan@anonymised.com> wrote:

Try this:

http://geoserver.org/browsepeople.action?startIndex=

-Miles

-----Original Message-----
From: Andrea Aime [mailto:aaime@anonymised.com]
Sent: Friday, 20 November 2009 9:13 AM
To: Rob Atkinson
Cc: Geoserver-devel
Subject: Re: [Geoserver-devel] geoserver.org rated "Red" security risk
by [SEC=Unclassified] McAfee [SEC=Unclassified]

Rob Atkinson ha scritto:
> Just reporting from the field. McAfee "SiteAdvisor" is installed by
> company policy. I'm not sure how to follow this up.

Hmmm:
http://www.siteadvisor.nl/sites/geoserver.org/summary/

After providing the mail to the site they received spam?
Not sure what that means. Did they try to register into confluence?

Cheers
Andrea

--
Andrea Aime
OpenGeo - http://opengeo.org
Expert service straight from the developers.

-----------------------------------------------------------------------
-------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008
30-Day
trial. Simplify your report design, integration and deployment - and
focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now. http://p.sf.net/sfu/bobj-july
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

___________________________________________________________________________

Australian Antarctic Division - Commonwealth of Australia
IMPORTANT: This transmission is intended for the addressee only. If you are not the
intended recipient, you are notified that use or dissemination of this communication is
strictly prohibited by Commonwealth law. If you have received this transmission in error,
please notify the sender immediately by e-mail or by telephoning +61 3 6232 3209 and
DELETE the message.
Visit our web site at http://www.antarctica.gov.au/
___________________________________________________________________________

On 20/11/09 06:07, Rob Atkinson wrote:

Just reporting from the field. McAfee "SiteAdvisor" is installed by
company policy. I'm not sure how to follow this up.

You can disable it in the Firefox Tools / Add Ons dialog.

--
Ben Caradoc-Davies <Ben.Caradoc-Davies@anonymised.com>
Software Engineer, CSIRO Earth Science and Resource Engineering
Australian Resources Research Centre
26 Dick Perry Ave, Kensington WA 6151, Australia

Confluence's Captcha was (/is) pretty crappy, and did not prevent robots from signing up, just from posting. So the database eventually filled up, and by the time we noticed it had become a pretty big task to clean it up. I'm pretty sure a bunch of lame profiles would not cause McAfee to react.

... but after googling for my own email address, what I now think is happening is this:

If you sign up with a new account, you have the option of using the email address as your username. In the latter case, your profile URL looks like this[1].

But either way, the default profile lists your email address for all to see [2]. It looks like the only alternative is to create a "personal space". The default homepage will again be ornamented with your email address, but you can then edit that page and remove it.

Confluence is Awesome.

-Arne

1: http://geoserver.org/display/~ak@anonymised.com
2: http://geoserver.org/display/~aaime

Rob Atkinson wrote:

yikes - time for some moderation! Or dump this completely - obvuiously
no-ones using it.

On Fri, Nov 20, 2009 at 10:53 AM, Miles Jordan <Miles.Jordan@anonymised.com> wrote:
  

Try this:

http://geoserver.org/browsepeople.action?startIndex=

-Miles

-----Original Message-----
From: Andrea Aime [mailto:aaime@anonymised.com]
Sent: Friday, 20 November 2009 9:13 AM
To: Rob Atkinson
Cc: Geoserver-devel
Subject: Re: [Geoserver-devel] geoserver.org rated "Red" security risk
by [SEC=Unclassified] McAfee [SEC=Unclassified]

Rob Atkinson ha scritto:
      

Just reporting from the field. McAfee "SiteAdvisor" is installed by
company policy. I'm not sure how to follow this up.
        

Hmmm:
http://www.siteadvisor.nl/sites/geoserver.org/summary/

After providing the mail to the site they received spam?
Not sure what that means. Did they try to register into confluence?

Cheers
Andrea

--
Andrea Aime
OpenGeo - http://opengeo.org
Expert service straight from the developers.

-----------------------------------------------------------------------
-------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008
30-Day
trial. Simplify your report design, integration and deployment - and
focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now. http://p.sf.net/sfu/bobj-july
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel
      

___________________________________________________________________________

   Australian Antarctic Division - Commonwealth of Australia
IMPORTANT: This transmission is intended for the addressee only. If you are not the
intended recipient, you are notified that use or dissemination of this communication is
strictly prohibited by Commonwealth law. If you have received this transmission in error,
please notify the sender immediately by e-mail or by telephoning +61 3 6232 3209 and
DELETE the message.
       Visit our web site at http://www.antarctica.gov.au/
___________________________________________________________________________

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day trial. Simplify your report design, integration and deployment - and focus on what you do best, core application coding. Discover what's new with
Crystal Reports now. http://p.sf.net/sfu/bobj-july
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel
  
--
Arne Kepp
OpenGeo - http://opengeo.org
Expert service straight from the developers