Learn how easy it is to sync an existing GitHub or Google Code repo to a SourceForge project! See Demo

Close

Version 4.5 Big Brother/Google Analytics

Greg S
2008-12-11
2013-05-01
  • Greg S
    Greg S
    2008-12-11

    I have detected a lot of external communication with the dimdim 4.5 vmware appliance. I first noticed it when I was testing and my browser would hang when it was trying to reach google-analytics.

    Just for fun I grep'd all the files in the /usr/local/dimdim directory for 'google-analytics' and this is what came back:

    Directory ConferenceServer/apache-tomcat-5.5.17/:

    ./webapps/dimdim/html/layout2/NewConsole.jsp
    ./webapps/dimdim/html/popout/WorkspacePopout.jsp
    ./webapps/dimdim/html/envcheck/envcheck.jsp
    ./webapps/dimdim/share_wait/share_wait.html
    ./webapps/dimdim/api_sample_form.html
    ./webapps/dimdim/jsp/admin/AdminLogin.jsp
    ./webapps/dimdim/WelcomePage.html
    ./work/Catalina/localhost/dimdim/org/apache/jsp/html/layout2/NewConsole_jsp.java
    ./work/Catalina/localhost/dimdim/org/apache/jsp/html/layout2/NewConsole_jsp.class
    ./work/Catalina/localhost/dimdim/org/apache/jsp/html/popout/WorkspacePopout_jsp.java
    ./work/Catalina/localhost/dimdim/org/apache/jsp/html/popout/WorkspacePopout_jsp.class
    ./work/Catalina/localhost/dimdim/org/apache/jsp/html/envcheck/envcheck_jsp.java
    ./work/Catalina/localhost/dimdim/org/apache/jsp/html/envcheck/envcheck_jsp.class
    ./work/Catalina/localhost/dimdim/org/apache/jsp/jsp/admin/AdminLogin_jsp.class
    ./work/Catalina/localhost/dimdim/org/apache/jsp/jsp/admin/AdminLogin_jsp.java

    Now I haven't had time to look through the code to see exactly what's being reported, or set up a sniffer to see exactly what type of tracking/homing is going on, however I see it as a major security issue that this stand alone application is reporting back to google and trying to contact other outside hosts. Again, I don't know if this is a vestige of this particular vmware appliance install (I doubt it) but it would be nice to hear some comments from the developers on this subject.

     
    • Mitchell
      Mitchell
      2008-12-18

      Thank you Greg for posting this.  I emailed them as well about this.

       
    • Greg S
      Greg S
      2008-12-20

      No problem. If you hear back from anyone on this, please post the results. Thanks!