Discussion:
[Wikimetrics] down for a bit
Dan Andreescu
2013-12-10 19:38:47 UTC
Permalink
I'm taking wikimetrics down for a bit, I have to reset some passwords that
were accidentally leaked. I don't suspect anything bad happened as we
caught it within a few minutes.

Dan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.wikimedia.org/pipermail/wikimetrics/attachments/20131210/91faff35/attachment.html>
Dan Andreescu
2013-12-10 20:13:32 UTC
Permalink
Ok, it's back up. Let me know if you have trouble. I'll work on a
post-mortem and send it out shortly.
Post by Dan Andreescu
I'm taking wikimetrics down for a bit, I have to reset some passwords that
were accidentally leaked. I don't suspect anything bad happened as we
caught it within a few minutes.
Dan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.wikimedia.org/pipermail/wikimetrics/attachments/20131210/8a08d031/attachment.html>
Dan Andreescu
2013-12-10 20:17:30 UTC
Permalink
Ok, so the trouble was that a configuration file was exposed publicly by
accident. To fix the problem, the following steps were taken:

0. I stopped all wikimetrics services (queue and web)
1. Coren reset the labsdb password for my user, I copied and replaced it in
the db_config.yaml file
2. I reset the wikimetrics user db password and replaced it in
db_config.yaml
3. I reset the Flask secret key that guards sessions and replaced it in
web_config.yaml
4. I reset the Google OAuth consumer credentials and replaced them in
web_config.yaml
5. I did not reset the MediaWiki OAuth consumer credentials as these were
not leaked
6. I restarted apache and celery, and wikimetrics started serving again

I'm fairly confident that a reset secret key just means all people who were
logged in may have to login again. But there may be something unforeseen
that went wrong - just let me know.
Post by Dan Andreescu
Ok, it's back up. Let me know if you have trouble. I'll work on a
post-mortem and send it out shortly.
Post by Dan Andreescu
I'm taking wikimetrics down for a bit, I have to reset some passwords
that were accidentally leaked. I don't suspect anything bad happened as we
caught it within a few minutes.
Dan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.wikimedia.org/pipermail/wikimetrics/attachments/20131210/9268e341/attachment.html>
Loading...