We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 7455
    • 2,204 Posts
    And this post is not open to the public and team member need to know
      follow me on twitter: @dimmy01
      • 6726
      • 7,075 Posts
      We totally agree ! Read the second part of my post again : Nice to report vunerability, but maybe let’s avoid posting recipes for attack as long as there is no patch/fix tongue

      I guess if you figured it out, some people will, but let’s not give this possibility to the widest audience sad


      My point was not to discourage reporting security issues, but avoid posting the recipes for attacks in public forums. Of course someone will also figure it out, but let’s not give people who normally wouldn’t be able to figure this out a toy to play with !

      Quote from: vbrilon
      I respectfully disagree. If he figured it out, chances are someone has as well. Security through obscurity has never worked and never will. We owe it to our MODx users to notify them as soon as problems such as these are discovered so they can at least mitigate any damage before an official patch is released.


      Dimmy, this post was originally in the public area of the forum, it was moved in the Project Team boards by Zi after I notified him tongue

      Quote from: Dimmy at Jan 16, 2006, 01:59 AM
      And this post is not open to the public and team member need to know
        .: COO - Commerce Guys - Community Driven Innovation :.


        MODx est l'outil id
        • 7455
        • 2,204 Posts
        Oops ok now its save to talk HACKING hehe
          follow me on twitter: @dimmy01
          • 33337
          • 3,975 Posts
          Dear all team members,

          Just need to plug my 2 cents about these security issues, I suggest to put some policies about security related things, so they never publicize initially, there are more bad guys out there, and if we pulically discuss these things, people with sites, posted in site showcase, will be at risk.

          So, how about a dedicated email address [email protected] to recieve this kind of reporting ?

          regards,

          zi
            Zaigham R - MODX Professional | Skype | Email | Twitter

            Digging the interwebs for #MODX gems and bringing it to you. modx.link
            • 25663 MODX Staff
            • 12,272 Posts
            Security auditing by professional sources is not cheap, I would guess. Did anyone have a solution to the problem?
              Ryan Thrash, MODX Co-Founder
              Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
              • 31337
              • 258 Posts
              Quote from: rthrash at Jan 16, 2006, 08:11 AM

              Security auditing by professional sources is not cheap, I would guess. Did anyone have a solution to the problem?

              See my post above. Just need the stats veiwer to strip out <script> tags in the URLs it show
                • 6726
                • 7,075 Posts
                Quote from: rthrash at Jan 16, 2006, 08:11 AM
                Security auditing by professional sources is not cheap, I would guess. Did anyone have a solution to the problem?

                It seems Netnoise has a solution :
                http://modxcms.com/forums/index.php/topic,2382.0.html

                A couple of guys like NetNoise, and all we need would be to make them part of the Testing Team to make MODx bullet proof smiley

                What do you think ?
                  .: COO - Commerce Guys - Community Driven Innovation :.


                  MODx est l&#39;outil id
                  • 25663 MODX Staff
                  • 12,272 Posts
                  Security should be a high priority... I’m all for it.
                    Ryan Thrash, MODX Co-Founder
                    Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
                    • 6726
                    • 7,075 Posts
                    Quote from: rthrash at Jan 16, 2006, 09:45 AM

                    Security should be a high priority... I’m all for it.

                    How about have NetNoise join the Testing Team then ? I know he’s still new around here, but he sure seems capable enough ! And should he want to, he could focus on security issues...

                    Just an idea, I wouldn’t want to cause "overstaffing" tongue
                      .: COO - Commerce Guys - Community Driven Innovation :.


                      MODx est l&#39;outil id
                      • 32241
                      • 1,495 Posts
                      Kinda agree with that.

                      I think it’s Ryan decision to do that, I believe he has a better eyes compare to us in determining who is the right person to join the team laugh

                      Note: It seems to me that he knows what he is doing, except the fact that he is still new to MODx.

                      Sincerely,
                        Wendy Novianto
                        [font=Verdana]PT DJAMOER Technology Media
                        [font=Verdana]Xituz Media