21
Anonymous
Re: Are Xoops sites under attack???
  • 2007/11/9 9:51

  • Anonymous

  • Posts: 0

  • Since:


@Damaster,

There's a certain irrefutable logic about what you say.

Quote:
preachur wrote:
What is the problem with protector? I HOPE it works....


I think that what irmtfan means is that proper documentation would enable users to understand the effect that changing Protectors settings might have. At least, that's how I read it.

GIJoe is a securtity guru and an excellent coder and developer. Were there to be a problem with Protector then he would sort it. v3.04 (and 3.04a) have been around for quite a few months now so it's reasonable to assume that there's nothing fundamentally wrong. GIJoe would have fixed things if there were as he's that sort of chap.

Rather than fixing code, v3.15beta is adding new features meaning that he's confident in v3.04. That's good enough for me.

I agree with what Damaster, irmtfan and Catz are saying - the Protector module wouldn't be quite so critical if the core/modules' code were more secure.

"Big Up" for GIJoe

22
tom
Re: Are Xoops sites under attack???
  • 2007/11/9 12:28

  • tom

  • Friend of XOOPS

  • Posts: 1359

  • Since: 2002/9/21


Quote:
IMO ( and it is just my opinion) if a CMS can be beat by random recognize attacking programs, it is a waste of time to continue with it.
xoops can not be beat that easy if you do some basic security advices:
1. always use the latest stable version of cores and modules.
2. dont use alpha and beta and unknown modules from unknown developers.
3. use "protector" as an alternative for bad coding in modules and ???Core??? and even misconfiguration in your server.
4. pay attention to security warnings.


I don't disagree.

Allow me to make an analogy.

You have some jewellery valued at $100,000 locked up in a yale safe, bolted down within a room in your house, if someone knows how to hack that safe, they will get in however if they didn't know you had that jewellery or where that safe is, then it certainly make their job harder.

Hence removing references that your site is XOOPS and what version it is can help to evade being hacked, as your not advertising you jewels in public.

Quote:
I agree with what Damaster, irmtfan and Catz are saying - the Protector module wouldn't be quite so critical if the core/modules' code were more secure.


+1

23
irmtfan
Re: Are Xoops sites under attack???
  • 2007/11/10 4:05

  • irmtfan

  • Module Developer

  • Posts: 3419

  • Since: 2003/12/7


i dont disagree too.
any additional security is worth to be added.
but i like to deal with security and simplicity of a CMS.
also it is not wise to put your jeweleries in a free basket.

Login

Who's Online

486 user(s) are online (116 user(s) are browsing Support Forums)


Members: 0


Guests: 486


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Jul 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits