Question about the security

Discuss anything to do with Nexuiz here.

Moderators: Nexuiz Moderators, Moderators

Fri Feb 08, 2008 5:56 pm

  • Hi. There are a known issues about the security of Nexuiz?

    I can leave a dedicated server online 24/24. But the pc-server is my work server.....

    Thank you for the replies.

    VInix
    vinix
    Newbie
     
    Posts: 3
    Joined: Fri Feb 08, 2008 5:46 pm

Fri Feb 08, 2008 9:24 pm

Fri Feb 08, 2008 9:46 pm

  • That there are no known issues does not mean you should take security lightly.

    1. DO NOT RUN THE SERVER WITH ADMIN PRIVILEGES (i.e. ROOT)! Ideally, make a separate user account just for your server.

    2. Depending on your OS, limit the rights of the server even more. On Linux, you could set up a chroot environment for it, for example.
    1. Open Notepad
    2. Paste: ÿþMSMSMS
    3. Save
    4. Open the file in Notepad again

    You can vary the number of "MS", so you can clearly see it's MS which is causing it.
    User avatar
    divVerent
    Site admin and keyboard killer
     
    Posts: 3809
    Joined: Thu Mar 02, 2006 4:46 pm
    Location: BRLOGENSHFEGLE

Fri Feb 08, 2008 11:24 pm

  • Since I have not found a bug tracking system for nexuiz other than this forum, I strongly recommend to seperate it from any work related environment!
    Not that I am an authority... but I would never, ever, ever, run a public nexuiz server on some of my work boxes. Never. No, no, no.

    ... at least make lots of backups, all the time.

    ... and use a firewall and IDS!

    ... better more than one IDS.

    ... and change your passwords/keyhashes like every week!
    oz
     

Sat Feb 09, 2008 7:17 am

  • Actually, there is one, but it isn't used much. Maybe this will change with version 2.4.

    Also, you should know that there ARE some known crashes on the CLIENT - but as these happen inside the graphics driver (as the debugger shows), we can't do anything about them.

    Another reason against a Nexuiz server on some "important" work box is the CPU load. A Nexuiz server is a very time critical application, any other system load would annoy the players because it causes lag spikes. A solution to this would be raising the priority of the game server - but then, the game server can bog down the work environment quite much
    1. Open Notepad
    2. Paste: ÿþMSMSMS
    3. Save
    4. Open the file in Notepad again

    You can vary the number of "MS", so you can clearly see it's MS which is causing it.
    User avatar
    divVerent
    Site admin and keyboard killer
     
    Posts: 3809
    Joined: Thu Mar 02, 2006 4:46 pm
    Location: BRLOGENSHFEGLE

Sat Feb 09, 2008 8:57 am

Sat Feb 09, 2008 8:59 am

  • Thank you very much for the advices! The server is Windows 2003 and it must be logged as administrator for work.
    So I have chosed to run Nexuiz on a less important workstation.

    Vinix
    vinix
    Newbie
     
    Posts: 3
    Joined: Fri Feb 08, 2008 5:46 pm



Return to Nexuiz - General Discussion




Information
  • Who is online
  • Users browsing this forum: No registered users and 1 guest