11
McDonald
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/2 23:54

  • McDonald

  • Home away from home

  • Posts: 1072

  • Since: 2005/8/15


I have tested Herve's XOOPS 2.0.17 version a couple of days ago on my test server.
The installation did not seem to give a problem, but I couldn't reach the site (blank page).
As far as I remember something went wrong with setting up the database tables.

12
MadFish
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/3 2:55

  • MadFish

  • Friend of XOOPS

  • Posts: 1056

  • Since: 2003/9/27


Quote:
the hash's are in the db, so the best logical solution to protecting those hash's would be to prevent those hash's being retrieved by unauthorised users, to do that you have to secure the system better to prevent hash's being retrieved either by sql injection or whatever. prevention is better than cure.


Adding a salt prior to hashing user passwords would be a simple way to render the hashes useless to an attacker and block dictionary attacks (so long as the salt can be protected).

13
instantzero
Re: Xoops 2.0.17 released (Unofficial version) by Hervé

Quote:

jmorris wrote:
Also, there is a patch for most if not all the bugfixes ready on SF.net. If people want to make something useful, they're allowed to test / review the available patches, or even apply them to a 2.0.16 and release some kind of "patched 2.0.16 with bugfixes not yet entirely official"

"If people want to make something useful" LOL
As everybody can see, the bugfixes submitted by everybody was not used in any version

Quote:

jmorris wrote:
I would strongly encourage anyone who wishes to maintain compatibility with the future versions of XOOPS to NOT use this unsupported version.

I would strongly encourage anyone not to hear him
Really, are you so bored on xoops.org ?


Quote:

vaughan wrote:
i'm not even entirely convinced that the changes made to the password are fully necessary anyway

Listen to the security expert

Your forums are full of this :
Quote:

Post removed by moderator
Please Note: The original text of this post was posted by someone else then the apparent author.

How do you believe this was made ?

Really, are you so bored on xoops.org ?
Anything better to do than to denigrate the work made by the others ?

PS : In how many times this answer will be "moderated" ?

14
vaughan
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/3 9:47

  • vaughan

  • Friend of XOOPS

  • Posts: 680

  • Since: 2005/11/26


herve, what has that thread on XC got to do with what i have said here? absolutely nothing.

and what i have said here makes perfect sense. "If the system was secure and unauthorised users were prevented from gaining access to the database or were unable to get the opportunity of retrieving the password hash's in the first place, it would make no difference if the passwords were plain text or encrypted because they would be unable to exploit the system in order to get them"if they can't retrieve the hash, then they can't crack the hash!!

If a burglar is breaking into your house, don't buy a dog or change your furniture in order to stop it happening again. Fix the problems that the burglar used to gain entry in the first place!!

now don't take this the wrong way and think that i think plain text passwords are secure.. lol because I don't.. i used as an example.

15
giba
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/3 11:04

  • giba

  • Just can't stay away

  • Posts: 638

  • Since: 2003/4/26


This is plus an example that we must respect and be thankful with much affection because we need to evolve.

When still she was a child was taught me that the good ideas were equal to a small plant that it needed to be watered with affection to generate fruits.

If all time that good ideas to appear here not to water our plant, it finally will die.


Initiatives as this of the Herve must be applauded and to leave the community to choose what of good it exists to be used to advantage or everything.

To finish, yes, some bug-fix are excellent and already they would have to be in Core the much time and us we will go to incorporate these changes with certainty with the had credits in our parallel version in Brazil.


Debtor for sharing these ideas and solutions in the practical one with work.

Sorry my poor english, using translator.

[pt_br]
Este é mais um exemplo que devemos respeitar e agradecer com muito carinho porque precisamos evoluir.

Quando ainda era uma crian?a me foi ensinado que as boas idéias eram iguais a uma pequena planta que precisava ser regada com carinho para gerar frutos.

Se toda vez que boas idéias surgirem aqui n?o regarmos a nossa planta, ela finalmente morrerá.

Iniciativas como esta do Herve devem ser aplaudidas e deixar a comunidade escolher o que de bom existe para ser aproveitado ou tudo.

Para finalizar, sim, alguns bug-fix s?o relevantes e já deveriam estar no core a muito tempo e nós iremos incorporar estas mudan?as com certeza com os devidos créditos em nossa vers?o paralela em brasil.

Obrigado por compartilhar estas idéias e solu??es na prática com trabalho.
[/pt_br]

Momento Zen (hope)

With the sweat of its face it will gain its bread.

Com o suor do seu rosto ganhará o seu p?o.


[edited by Giba]

If you it liked these new features created for herve Rate Thread with 5 points, if no, Rate Thread with 1, but Rate.

16
JMorris
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/3 12:28

  • JMorris

  • XOOPS is my life!

  • Posts: 2722

  • Since: 2004/4/11


Quote:

instantzero wrote:
Quote:

jmorris wrote:
Also, there is a patch for most if not all the bugfixes ready on SF.net. If people want to make something useful, they're allowed to test / review the available patches, or even apply them to a 2.0.16 and release some kind of "patched 2.0.16 with bugfixes not yet entirely official"

"If people want to make something useful" LOL
As everybody can see, the bugfixes submitted by everybody was not used in any version


Yet.

Quote:

instantzero wrote:
Quote:

jmorris wrote:
I would strongly encourage anyone who wishes to maintain compatibility with the future versions of XOOPS to NOT use this unsupported version.

I would strongly encourage anyone not to hear him
Really, are you so bored on xoops.org ?


Bored? Actually, I've been quite busy lately working with other community members on the new sites. I hope you enjoy the results of our collaborative work. So, no, I'm not bored, but thank you for asking.

The ultimate issue here is that Herve's Personal Release is not compatible with the current [stable] version of XOOPS and will not be compatible with future versions of XOOPS. Therefore, it is strongly advised that users who wish to maintain compatibility with the "Official" XOOPS version, that you do not use this unofficial release.

Of course, everyone can choose for themselves, but just know that this unofficial release will not be supported. Even Herve himself stated that in his release announcement.
Insanity can be defined as "doing the same thing over and over and expecting different results."

Stupidity is not a crime. Therefore, you are free to go.

17
Sm0ka
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/3 13:23

  • Sm0ka

  • Just popping in

  • Posts: 41

  • Since: 2003/12/25


Post removed by moderator

Please Note: The original text of this post was posted by someone else then the apparent author.
"Sm0ka" I know not what i know, but i know what i do not know, therefore i am complete.

18
Will_H
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/3 15:06

  • Will_H

  • Friend of XOOPS

  • Posts: 1786

  • Since: 2004/10/10


Post removed by moderator

Please Note: The original text of this post was posted by someone else then the apparent author.

19
Burning
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/3 15:16

  • Burning

  • Theme Designer

  • Posts: 1163

  • Since: 2006/8/22


Post removed by moderator ? What's wrong... 2.0.17 or initial post ?
Still learning CSS and... english

20
vaughan
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/3 15:31

  • vaughan

  • Friend of XOOPS

  • Posts: 680

  • Since: 2005/11/26


ok stop with the unnecessary bumping.!!!! or the thread will be closed!

biteronboard's post was not edited by a moderator, he posted that message himself.. lol

Login

Who's Online

321 user(s) are online (240 user(s) are browsing Support Forums)


Members: 0


Guests: 321


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Nov 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits