We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 6726
    • 7,075 Posts
    I have seen a few concerns about security that should normally be fixed for 0.9.2, but since I don’t have access to the Security issues logged in Flyspray I can’t have an overall picture of where MODx stands in this area.

    Here is the thing : I have been contacted by a big french foundation to build their website (with a public and a private section), it’s a possible 10 000 € contract.

    They’re interrested by MODx capabilities compared to Joomla, Typo3 and Drupal and I have succeeded the first round of selection, we’re now 3 out of 10 possible contractors. Questions are now going into more details and one of the key items is how secure the application is and also how do we compare to those other CMS ?

    Of course every system can be hacked, but would it be easy, not very easy, hard or very hard to hack MODx ?
    Are there reports of MODx websites being hacked ? How many, how severe ?

    Also, did anyone use https for MODx powered website ? What security improvement benefit would that bring ?

    I have to meet the client wednesday, so any input is very welcome here ! In the longer run, it’d be nice for me to have those elements since I’ll inevitably have questions about security when advocating MODx on forums...

    Thanks !!!
      .: COO - Commerce Guys - Community Driven Innovation :.


      MODx est l'outil id
      • 25663 MODX Staff
      • 12,272 Posts
      I’m not aware of any MODx sites being hacked actually. Netnoise should be able to comment on MODx’s "hackability".

      https only encrypts the data between the browsers and the server, so it would only prevent someone from sniffing passwords or sensitive data.

      My understanding is that as long as someone uses the DBAPI to access the database, MODx should be pretty darned secure.
        Ryan Thrash, MODX Co-Founder
        Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
        • 6726
        • 7,075 Posts
        Thanks Ryan !

        About https: that’s what I suspected...

        I am currently on #modx on IRC and Susan added having sessions stored in DB would be safer and apparently can be done modifying config.inc.php, but don’t know how yet... She also said if you’re on a dedicated server, having the config.inc.php out of the web folder could be added security.

        I know NetNoise had a few issues ID’ed that he wanted to nail for 0.9.2, will that make it into the release ?

          .: COO - Commerce Guys - Community Driven Innovation :.


          MODx est l'outil id
          • 25663 MODX Staff
          • 12,272 Posts
          All of Netnoise’s issues will be in 0.9.2.
            Ryan Thrash, MODX Co-Founder
            Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
            • 21255
            • 215 Posts
            Hi David,

            MODx in 0.9.1 has currently some (more or less) serious issues, but I’m sure the upcoming 0.9.2 will not be easy to hack.

            If it’s about 10.000 € you should allow your MODx installation a dedicated server. Then you don’t have to care (so much) where config.inc.php is located or where sessions are stored (btw: storing in files is the fastest method), ...
            I’m sure, if a MODx installation gets hacked, it’ll most probably due to a bad configured webhost or careless snippets/plugins, but I have never heard of a hacked MODx system.
              • 6726
              • 7,075 Posts
              I am very glad to see that those issues will be fixed for 0.9.2 grin

              This is great news for me and my upcoming meeting (I am the underdog here...)
              and for all MODx users of course laugh

              About the dedicated server : I will go that way, definitely. I was not aware of the benefits in terms of security...
              Thanks a lot for the quick answer smiley
                .: COO - Commerce Guys - Community Driven Innovation :.


                MODx est l'outil id