We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 4673
    • 577 Posts
    Just wondering how is the code looking in regards to security?

    NO, I’m not worried about sloppy programming so stop that tongue

    However, in the same light, what about the possiblity of having an outside source give us a stamp of approval or something? Might be good for press releases and such.
      Tangent-Warrior smiley
      • 27385
      • 15 Posts
      That’s a good idea . . . It would look good from the outside. Not only is ModX compatible, but it’s also secure.
        • 32241
        • 1,495 Posts
        Hey, that’s true!

        From marketing view, we can gain more interest from outside, if we can prove ourself as a secured system. Do you have any experience or sources, where we can get outside approval about our system security carsten?

        Sincerely,
          Wendy Novianto
          [font=Verdana]PT DJAMOER Technology Media
          [font=Verdana]Xituz Media
          • 32241
          • 1,495 Posts
          What test is it?
            Wendy Novianto
            [font=Verdana]PT DJAMOER Technology Media
            [font=Verdana]Xituz Media
            • 31337
            • 258 Posts
            Quote from: netnoise at Jan 15, 2006, 10:52 AM

            First test failed ;-)

            w3m -header "Referer: http://www.google.de'< <script>document.location.href='http:%3A%2F%2F%77%77%77%2E%67%6F%6F%67%6C%65%2E%64%65';</script>"
            




            Which URL did you target that at?
              • 6726
              • 7,075 Posts
              Nice to report vunerability, but maybe let’s avoid posting recipes for attack as long as there is no patch/fix tongue

              I guess if you figured it out, some people will, but let’s not give this possibility to the widest audience sad
                .: COO - Commerce Guys - Community Driven Innovation :.


                MODx est l&#39;outil id
                • 21255
                • 215 Posts
                Sorry, I see that wasn’t such a good idea. I removed my postings about that.
                  • 31337
                  • 258 Posts
                  Could you please file this in the bugtracker? Specifically, please mention in the bug report that the visitor stats page should strip out javascript before rendering the page.

                  Thanks
                    • 6726
                    • 7,075 Posts
                    Thanks for doing it so quickly smiley

                    Anyway, that’s good to have someone like you to help test MODx security grin

                    Are there other test you could run ? Did you submit this into FlySpray (would be a good idea I guess) ? (reading my mind, vbrilon wink )
                      .: COO - Commerce Guys - Community Driven Innovation :.


                      MODx est l&#39;outil id
                      • 31337
                      • 258 Posts
                      Quote from: davidm at Jan 15, 2006, 04:36 PM

                      Nice to report vunerability, but maybe let’s avoid posting recipes for attack as long as there is no patch/fix tongue

                      I guess if you figured it out, some people will, but let’s not give this possibility to the widest audience sad

                      I respectfully disagree. If he figured it out, chances are someone has as well. Security through obscurity has never worked and never will. We owe it to our MODx users to notify them as soon as problems such as these are discovered so they can at least mitigate any damage before an official patch is released.