We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 7231
    • 4,205 Posts
    I brought this inside since it is not a public opinion wink

    Quote from: rthrash at Dec 09, 2008, 05:26 AM

    The current Reflect issue is noted in the Security thread as the top item (also going out via RSS and email feeds as encouraged before you ever download MODx). If users choose to ignore the security topic ... what can we do?
    I agree 100%, and in a perfect world this would be more than adequate. However, many modx users are not always technically inclined (and many don’t visit the forums regularly or subscribe to feeds or even speak fluent english). Since my days at modx this is the most significant security problem that has come up and how it is handled may be crucial to the history of the project (the masses remember the bad longer than the good, and with the long tail of the web the bad will stay available for some time). It may not be modx’s problem (even though the reflect script was packaged with modx default install) but when the blame gets tossed it will be under modx’s shadow.

    Anyway, I would rather that modx gets blamed for doing "to much" rather than "not enough" as far as getting the word out regarding potentially serious security risks. Maybe a blog post on this issue explaining that the problem is not related to modx and why would be an interesting idea.

    Anyway, talk is cheap (that’s why its only worth 2¢). Just thought I would vent my concerns.
      [font=Verdana]Shane Sponagle | [wiki] Snippet Call Anatomy | MODx Developer Blog | [nettuts] Working With a Content Management Framework: MODx

      Something is happening here, but you don't know what it is.
      Do you, Mr. Jones? - [bob dylan]
      • 6726
      • 7,075 Posts
      I have noticed a bunch of posts about the RFI exploit, and people do not seem to systematically read security notices or subscribe to the feed. You’re right that this has to be handled as it always has : acknowledge the problem and communicate about it. Now, we can do better communication but nobody can say we suffer from the "Not Invented Here" syndrom you can sometime come accross in some communities rolleyes

      I think Jay’s answer was spot on (content and tone wise), and security notices directly in the manager might just be the answer. We can’t be expected to do much more than that, a security forum and a rss feed.

      We definitely can’t replace people’s brain tongue
      If you don’t look out for security and are not concerned with it, there is only so much you can do for people...
        .: COO - Commerce Guys - Community Driven Innovation :.


        MODx est l'outil id
        • 33372
        • 1,611 Posts
        Quote from: dev_cw at Dec 09, 2008, 02:28 PM

        I brought this inside since it is not a public opinion wink

        I think that was a wise decision, since not everything said about this topic might be appropriate for the general public.

        However, I don’t know that I agree with what seems to be the premise of your argument, to wit that the MODx team has erred on the side of doing too little rather than too much. I know that you suggested that a notice be put on the MODx home page, but to me that a) seems overly alarmist and therefore more harmful to MODx’s reputation, and b) anyone who comes to the MODx site looking for info because they’ve been hacked should already be able to find it easily, since it’s anything but hidden. So other than that, what more would you suggest that the team do?

        I certainly think that this can and should be a learning experience, but I see more opportunity for learning how to prevent future issues than different ways to respond to this one (since I think the response was actually very good). For example, I’d definitely review all .php files included in the release (and perhaps also the repository) and make sure that nothing is executable that doesn’t need to be and what needs to be is secure. The practice of including snippet code with a .php extension should certainly be ended, since that just seems like tempting fate for no reason to me.

        And maybe the warnings shown when register_globals is set to ON should be much more dramatic than they are now, since apparently they aren’t dire enough to scare some people into taking them seriously.

        I also definitely recommend integrating a security and updates RSS feed into the Manager, although I wouldn’t be surprised if some of the sites that were hacked hadn’t been logged into in a long time.

        Any other ideas?
          "Things are not what they appear to be; nor are they otherwise." - Buddha

          "Well, gee, Buddha - that wasn't very helpful..." - ZAP

          Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
          • 7231
          • 4,205 Posts
          However, I don’t know that I agree with what seems to be the premise of your argument, to wit that the MODx team has erred on the side of doing too little rather than too much. I know that you suggested that a notice be put on the MODx home page, but to me that a) seems overly alarmist and therefore more harmful to MODx’s reputation, and b) anyone who comes to the MODx site looking for info because they’ve been hacked should already be able to find it easily, since it’s anything but hidden. So other than that, what more would you suggest that the team do?
          I did not mean to infer that the team erred at all. To me personally I think the action was adequate and enough. I lost no sleep over this at all. But I am always on the forum and may have been one of the first to erase the troublesome file. I worry about the lesser savvy users who are less aware, they can have problems and not understand why it is not modx’s fault and complain about it and these complaints would end up getting some weight while doing a search for "modx security" for example.

          Google ’RFI Exploit’ and modxcms.com is in top 4, that can’t be good.
            [font=Verdana]Shane Sponagle | [wiki] Snippet Call Anatomy | MODx Developer Blog | [nettuts] Working With a Content Management Framework: MODx

            Something is happening here, but you don't know what it is.
            Do you, Mr. Jones? - [bob dylan]
            • 33372
            • 1,611 Posts
            Quote from: dev_cw at Dec 09, 2008, 06:06 PM

            I did not mean to infer that the team erred at all.
            Maybe "erred" was the wrong word, since it doesn’t sound as if you’re offering criticism (which can, of course, be constructive) but rather advocating for doing more to address the current issue. What I don’t understand, however, is what more the team can do. This particular cat is already out of the bag, and anyone who wants to put it back in can easily find instructions for doing so (poor kitty!).

            Note that the Google result that you posted is to the MODx team’s response to the exploit, which in my mind is a good thing. It means that people looking for info on how to deal with this exploit will find it here, and in addition it allows the MODx team to shape the public’s perception of the problem (which is better then someone else doing it). So to me those results demonstrate the effectiveness of the team’s response to this issue so far.
              "Things are not what they appear to be; nor are they otherwise." - Buddha

              "Well, gee, Buddha - that wasn't very helpful..." - ZAP

              Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
              • 7231
              • 4,205 Posts
              What I don’t understand, however, is what more the team can do.
              Here are a few ideas:
              1) pull a feed of the latest Security Notice / Announcement over to the home page of modxcms.
              2) Identify in the notice the ’level’ of the threat (high, medium, small)
              3) Add more information regarding the threat and the solution in the notice
              4) Add a prominent notice area for the foreign language forums. As it is, the announcements section is two levels deep and the notice does not get much visibility (I added a notice in the portuguese forum but was not sure if it was a support or an announcement topic).

              Note that the Google result that you posted is to the MODx team’s response to the exploit, which in my mind is a good thing.
              Arguable point of view, not sure if I share it. I would rather not see modx there at all (in the company of phpbb, joomla and other exploited visctims such as google), bad kitty. The results issue (if it is an issue) could have been avoided with a different post title for the warning (which could be another point, more descriptive titles, users who know what RFI Exploit are will most likely be more aware of the dangers, it is the users who do not know what that is that need to be made aware, and those may have overlooked the notice since they did not know what it meant and don’t use Reflect).

              And on a final note, I think that this is a bit more serious a problem than the notices let on. Basically every copy of modx out there since Reflect was added to the package can have this problem. We know by the number of posts regarding register_globals that many hosts still insist on this setup. In many cases the end user (client) does not know that the developer disabled the warning since the server could not be changed (I have a client with the warning disabled, they were notified, but they have no idea what that means and have no control over this anyway, I obviously notified them and deleted the file and they were very happy I called).

              This is by no means a criticism, I think that the team handles security issues very well and extremely quickly, kudos to the team and the community. I am off to sleep (knowing someone out there is watching over modx).
                [font=Verdana]Shane Sponagle | [wiki] Snippet Call Anatomy | MODx Developer Blog | [nettuts] Working With a Content Management Framework: MODx

                Something is happening here, but you don't know what it is.
                Do you, Mr. Jones? - [bob dylan]
                • 33372
                • 1,611 Posts
                Just to clarify: You know of a case where someone built a site for a client using MODx and not only didn’t disable register_globals but also turned off the warning?!? If so, I’m in awe of this fact. That’s a truly impressive demonstration of shortsightedness and irresponsibility.

                Personally I have never yet encountered a web host where register_globals couldn’t be disabled. Sometimes I’ve had to ask the admins to do it for me, but it’s always been possible one way or another. If for some crazy reason it weren’t possible, I’d definitely switch hosts.
                  "Things are not what they appear to be; nor are they otherwise." - Buddha

                  "Well, gee, Buddha - that wasn't very helpful..." - ZAP

                  Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
                  • 25663 MODX Staff
                  • 12,272 Posts
                  Dad: don’t stick your head out the window as you’re driving down a narrow European alley way known for people opening heavy doors and having piano wire strung from the ground overhead. You’ll cut your head off or bash it in.

                  Kid: But my AC doesn’t work in the car and it’s hot .... *thwack*

                  Mom: I cannot believe the windshield of the car didn’t have a message sprawled across the window and spray painted on the hood too!


                  We’re not going to post a notice on the modx home page. If casual users aren’t visiting the forums, they’re probably not visiting the home page either, so that’s not going to do any good. Steps we took regarding this issue:

                  1) Told people to subscribe via RSS to security threads
                  2) Told people to subscribe via email to security notice thread
                  3) Put a huge warning sign in the manager telling them they’re likely to get hacked ... *sigh*
                  4) Addressed the issue in the first hours of finding out about it
                  5) Announced it in the security threads sending off email subscriptions and RSS feeds
                  6) Replaced the current distribution with a clean, fixed copy

                  In all fairness though, we’re going to have a more organized and coordinated international security response notification system and release system with the new marketing site. But no front page advertisements regarding security issues that may crop up in the future.
                    Ryan Thrash, MODX Co-Founder
                    Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
                    • 6726
                    • 7,075 Posts
                    I agree that this should not sit on the frontpage... as for international warning I usually relay them in the french announcement forums (but true, I did not this time... will do ASAP, I guess you’re right about setting up a system), I guess other moderators deal with it roughly the same way.

                    Edit : Added the french announcement.
                      .: COO - Commerce Guys - Community Driven Innovation :.


                      MODx est l'outil id
                      • 27708 MODX Staff
                      • 2,502 Posts
                      Great discussion here!

                      I’ve personally seen people post fixes in the forums about disabling the register_globals warning in the manager. That’s stupid and those people deserve what they get.

                      2nd the real lesson here is that some people are just not going to pay attention to warnings and when trouble comes they look outward to post blame.

                      That being said I would like to see a minor change in the way we post notices. I think as far as security update notices they should not be in the main security update feed but as a nag box within the manager interface. The thing is it must not be alarmist. It should be a nice polite message that "users should patch, upgrade or manually fix if applicable." Or some such.

                      The front page of the marketing site is no place for warnings or alarms. We could on the download page add a note that it for security it is recommended that users upgrade with a link to the notice.

                      I’ve had WordPress sites hacked and despite warnings and upgrade notices people still blamed Automattic for not doing enough.

                      I’ve also come to realize that it’s not enough to assume that people understand the vast importance of working on a secure server and that as a practice it makes sense to assume the least security for our installs.

                      Finally, we can create a best practices document for creating and packaging addons for MODx that gives hack/copy-and-paste php folks some clues on how best to ensure we’re not creating new vulnerabilities.

                      Cheers,

                      Jay

                        Author of zero books. Formerly of many strange things. Pairs well with meats. Conversations are magical experiences. He's dangerous around code but a markup magician. Blog ✦ Twitter ✦ LinkedIn ✦ GitHub