Question about the security

Discuss anything to do with Nexuiz here.

Moderators: Nexuiz Moderators, Moderators

Question about the security

Postby vinix » Fri Feb 08, 2008 5:56 pm

Hi. There are a known issues about the security of Nexuiz?

I can leave a dedicated server online 24/24. But the pc-server is my work server.....

Thank you for the replies.

VInix
vinix
Newbie
 
Posts: 3
Joined: Fri Feb 08, 2008 5:46 pm

Postby Psychcf » Fri Feb 08, 2008 9:24 pm

not that I know of.
Psychcf
Forum addon
 
Posts: 1554
Joined: Sun Dec 03, 2006 11:38 pm
Location: NY, USA

Postby divVerent » Fri Feb 08, 2008 9:46 pm

That there are no known issues does not mean you should take security lightly.

1. DO NOT RUN THE SERVER WITH ADMIN PRIVILEGES (i.e. ROOT)! Ideally, make a separate user account just for your server.

2. Depending on your OS, limit the rights of the server even more. On Linux, you could set up a chroot environment for it, for example.
1. Open Notepad
2. Paste: ÿþMSMSMS
3. Save
4. Open the file in Notepad again

You can vary the number of "MS", so you can clearly see it's MS which is causing it.
divVerent
Site admin and keyboard killer
 
Posts: 3809
Joined: Thu Mar 02, 2006 4:46 pm
Location: BRLOGENSHFEGLE

Postby oz » Fri Feb 08, 2008 11:24 pm

Since I have not found a bug tracking system for nexuiz other than this forum, I strongly recommend to seperate it from any work related environment!
Not that I am an authority... but I would never, ever, ever, run a public nexuiz server on some of my work boxes. Never. No, no, no.

... at least make lots of backups, all the time.

... and use a firewall and IDS!

... better more than one IDS.

... and change your passwords/keyhashes like every week!
oz
 

Postby divVerent » Sat Feb 09, 2008 7:17 am

Actually, there is one, but it isn't used much. Maybe this will change with version 2.4.

Also, you should know that there ARE some known crashes on the CLIENT - but as these happen inside the graphics driver (as the debugger shows), we can't do anything about them.

Another reason against a Nexuiz server on some "important" work box is the CPU load. A Nexuiz server is a very time critical application, any other system load would annoy the players because it causes lag spikes. A solution to this would be raising the priority of the game server - but then, the game server can bog down the work environment quite much
1. Open Notepad
2. Paste: ÿþMSMSMS
3. Save
4. Open the file in Notepad again

You can vary the number of "MS", so you can clearly see it's MS which is causing it.
divVerent
Site admin and keyboard killer
 
Posts: 3809
Joined: Thu Mar 02, 2006 4:46 pm
Location: BRLOGENSHFEGLE

Postby oz » Sat Feb 09, 2008 8:57 am

Thats the well known dilemma: Whats more imprtant, work or play? I dunno! It drives me crazzzy. Dammit.

All work and no play makes Jack a dull boy.
All play and no work makes Jack a mere toy.

http://en.wikipedia.org/wiki/All_work_a ... a_dull_boy
oz
 

Postby vinix » Sat Feb 09, 2008 8:59 am

Thank you very much for the advices! The server is Windows 2003 and it must be logged as administrator for work.
So I have chosed to run Nexuiz on a less important workstation.

Vinix
vinix
Newbie
 
Posts: 3
Joined: Fri Feb 08, 2008 5:46 pm


Return to Nexuiz - General Discussion

Who is online

Users browsing this forum: No registered users and 1 guest

cron