when using the db api functions to run a query I see no way to get them to simply return on sql errors so that I can handle them myself. At the moment I get an ugly « MODx Parse Error » page and a dump of the sql query to screen, which is great for development but obviously a big security issue on a live site.
I am using PHP 5.2.3 so Exception handling is available to me but seems to have no effect.
modx version is 9.6.1
thanks
I think this is due to the use of the messageQuit function in dbapi.mysql.class.inc.php from document.parser.class.inc.php.
Don’t however know how to suppress this without changing the code of this function, doesn’t seem to have a use/don’t use boolean you can set anywhere.
Use MODx, or the cat gets it!
thanks, that’s pretty much what I thought. I’ll add this as a feature request
After a database corruption led to a user telling our client that he could delete the entire site thanks to seeing the mySQL error I have hacked the core. Following shamblett’s advice.
document.parser.class.inc.php
line 531 -> $this->messageQuit("Execution of a query to the database failed", ’’);
line 537 -> $this->messageQuit("Execution of a query to the database failed", ’’);
dbaip.mysql.class.inc.php
line 138 -> $modx->messageQuit("Execution of a query to the database failed", ’’);
Yes, it provides some information agreed, which is probably not desirable from a security standpoint but to take the information it provides and get to this conclusion
a user telling our client that he could delete the entire site thanks to seeing the mySQL error
is a massive leap. You’d need far more than this to do that kind of damage. Who is this user?
Use MODx, or the cat gets it!
Are there news on that issue? In 0.9.6.3 the parse error page is still exposing information to the public that is not meant to be public. And in every cyber-security seminar you’ll learn that such information really should not be displayed in anybody else’s browser. In this case, somebody else could get to know that a) the site runs under modx, and b) the web root directory. These both pieces are at least essential to base attacks on.
That is anyway one of the few things which really annoy me in modx. The reason why I wouldn’t deploy modx in environments of my direct or indirect responsibility is mainly this one issue.
-
MODX Staff
- 12,272 Posts
Revolution addresses this issue but it does still remain in Evolution/096x, as you’re aware. Revo should hit public beta very soon.
Ryan Thrash, MODX Co-Founder
Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me