And this post is not open to the public and team member need to know
We totally agree ! Read the second part of my post again :
Nice to report vunerability, but maybe let’s avoid posting recipes for attack as long as there is no patch/fix 
I guess if you figured it out, some people will, but let’s not give this possibility to the widest audience
My point was not to discourage reporting security issues, but avoid posting the recipes for attacks in public forums. Of course someone will also figure it out, but let’s not give people who normally wouldn’t be able to figure this out a toy to play with !
Quote from: vbrilonI respectfully disagree. If he figured it out, chances are someone has as well. Security through obscurity has never worked and never will. We owe it to our MODx users to notify them as soon as problems such as these are discovered so they can at least mitigate any damage before an official patch is released.
Dimmy, this post was originally in the public area of the forum, it was moved in the Project Team boards by Zi after I notified him
Quote from: Dimmy at Jan 16, 2006, 01:59 AMAnd this post is not open to the public and team member need to know
.: COO - Commerce Guys - Community Driven Innovation :.
MODx est l'outil id
Oops ok now its save to talk HACKING hehe
-
MODX Staff
- 12,272 Posts
Security auditing by professional sources is not cheap, I would guess. Did anyone have a solution to the problem?
Ryan Thrash, MODX Co-Founder
Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
Quote from: rthrash at Jan 16, 2006, 08:11 AM Security auditing by professional sources is not cheap, I would guess. Did anyone have a solution to the problem?
It seems Netnoise has a solution :
http://modxcms.com/forums/index.php/topic,2382.0.html
A couple of guys like NetNoise, and all we need would be to make them part of the Testing Team to make MODx bullet proof
What do you think ?
.: COO - Commerce Guys - Community Driven Innovation :.
MODx est l'outil id
-
MODX Staff
- 12,272 Posts
Security should be a high priority... I’m all for it.
Ryan Thrash, MODX Co-Founder
Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
Quote from: rthrash at Jan 16, 2006, 09:45 AM
Security should be a high priority... I’m all for it.
How about have NetNoise join the Testing Team then ? I know he’s still new around here, but he sure seems capable enough ! And should he want to, he could focus on security issues...
Just an idea, I wouldn’t want to cause "overstaffing"
.: COO - Commerce Guys - Community Driven Innovation :.
MODx est l'outil id