https://gitlab.synchro.net/main/sbbs/-/issues/1239#note_10343
I get not alarming the community when there is a rare exploit that only affects 1 or 2 systems, Rob. But that’s not the case here. Disabling thhe
user account is the front-line defense used by not just Synchronet, but most other apps that provide user-level access control. Regardless, the feature is there, and so is the vulnerability. Fixing the issue is the correct course of action. Closing this issue feels more like a denial of its existence and an abandonment of the author when Sysops need him the most, whether they realize it or not. I’m not trying to be difficult, but
if this was any other software program, I believe this issue would have been handled differently. Support your community and they will return
that support.
Nick Boel wrote to Brian Davidson <=-thhe
On Sat, Sep 12 2026 01:28:10 -0700, Brian Davidson wrote to GitLab note
in main/sbbs:
https://gitlab.synchro.net/main/sbbs/-/issues/1239#note_10343
I get not alarming the community when there is a rare exploit that only affects 1 or 2 systems, Rob. But thatª€™s not the case here. Disabling
user account is the front-line defense used by not just Synchronet, but most other apps that provide user-level access control. Regardless, the feature is there, and so is the vulnerability. Fixing the issue is the correct course of action. Closing this issue feels more like a denial of its existence and an abandonment of the author when Sysops need him the most, whether they realize it or not. Iª€™m not trying to be difficult,but
if this was any other software program, I believe this issue would have been handled differently. Support your community and they will return
that support.
You do realize the issue was fixed before the issue was closed, right?
On Sat, Sep 12 2026 01:28:10 -0700, Brian Davidson wrote to GitLab note in main/sbbs:
You do realize the issue was fixed before the issue was closed, right?
Brian Davidson wrote to Nick Boel <=-
Re: User-Deactivate account: Still able to log in via SSH
By: Nick Boel to Brian Davidson on Sat Sep 12 2026 09:26 am
On Sat, Sep 12 2026 01:28:10 -0700, Brian Davidson wrote to GitLab note in main/sbbs:
You do realize the issue was fixed before the issue was closed, right?
Actually, I was not aware at the time I wrote that comment. I since removed the comment, not realizing it was broadcast to the entire
world.
I apologize for any confusion that this generated. I do not apologize
for having to defend the scope of the issuem nor the fact that this fix really needs to be backported to sbbs321e as a prod/fix event, if it hasn't already.
Part of the confusion stems from the fact that the issues screen does
not identify that code was committed, or that any merge action was
taken. This is why I was mislead into believing I had to continue to defend my position in order to get the fix. I was wrong.
So, "master" builds with the fix confirmed, I'm running that on my BBS.
It would be great to hear about sokmeone else running sbbs321e
rrelease build and whether or not their answer.cpp got the patch.
Beyond that, I end my involvement with this issue.
You do realize the issue was fixed before the issue was closed, right?
Haha! Pretty sure he doesn't... ;-)
Must be new if he thinks Rob needs some training on supporting his community... Sheesh.
https://gitlab.synchro.net/main/sbbs/-/issues/1239#note_10343
I get not alarming the community when there is a rare exploit that only affects 1 or 2 systems, Rob. But that's not the case here. Disabling thhe user account is the front-line defense used by not just Synchronet, but most other apps that provide user-level access control. Regardless, the feature is there, and so is the vulnerability. Fixing the issue is the correct course of action. Closing this issue feels more like a denial of its existence and an abandonment of the author when Sysops need him the most, whether they realize it or not. I'm not trying to be difficult, but if this was any other software program, I believe this issue would have been handled differently. Support your community and they will return that support.
| Sysop: | Angel Ripoll |
|---|---|
| Location: | Madrid, Spain |
| Users: | 18 |
| Nodes: | 8 (0 / 8) |
| Uptime: | 348:54:07 |
| Calls: | 1,332 |
| Calls today: | 1 |
| Files: | 2,689 |
| D/L today: |
3 files (269K bytes) |
| Messages: | 67,684 |