Get XOOPS XOOPS FAQ Forums News Themes Modules
New Posts New Topics All Forums Index General Modules Themes Development International XOOPS.org

XOOPS vs. Herko Coomans

Make a donation

Please select an amount to donate


Do you want your username revealed with your donation?
Yes - List me as a Generous Donor
No - List my donation as from an Anonymous Donor


Search

Local Support Sites

Cumulus Tag Cloud

admin Arabic banner block Christmas comments cumulus DayDawn dhsoft e-Commerce E-Learning Google GUI hacks instant-zero jQuery module news Nordic Olédrion oxygen PageRank security SEO simple-XOOPS sport tag Theme wiki xoops

New Users

Registering user

# 96568

dvsshoescom

Welcome to XOOPS!
XOOPS Code hosted on SourceForge


 Bottom   Previous Topic   Next Topic

#1 Posted on: 2008/11/9 11:25 Security regarding the plain text login of Xoops 2.0
Hi

Using Xoops 2.0.18.2, the default login block is conducted over plain, unencrypted, http instead of https.

I know that Xoops uses the PHP md5crypt() function for converting the string to an MD5 value for storage in the database.

Prior to the string arriving at the server though, the login form can be intercepted? So why is https not used by default for the login block, in the same was as it is for Yahoo and Hotmail logins?


Top


Lost Doggies UK and Ted Smith Photography
tedsmith
Home away from home
Joined:
2004/6/2 6:00
From Derbyshire, England
Posts: 1122
(Show More) (Show Less)
#2 Posted on: 2008/11/9 14:03 Re: Security regarding the plain text login of Xoops 2.0
well even md5 is insecure.

but on the regard of https as default..

for the ability to use https, your server needs to have a verified SSL certificate that has been registered with the certificate authorities. and that costs money. not everyone uses it, and it's only really necessary for sites that have dealings with cash or credit card details or confidential information.

but just because you use SSL doesn't mean it's secure.. the transport is encrypted yes, but it doesn't protect you from the middle man if your site has been breeched, as then they will have access to the plain content aswell as the encrypted layer and public keys.

Top

yeppers
Just popping in
Joined:
2008/9/15 9:20
Posts: 27
(Show More) (Show Less)
#3 Posted on: 2008/11/9 16:39 Re: Security regarding the plain text login of Xoops 2.0
I'm not attacking Xoops - I'm just asking what the thinking process is behing using plain text logins with very little emphasise being placed on the https option. If you didn't know it was there, you'd struggle to find it. And that is my point really - the option of using HTTPs should be made more obvious.

True - it costs to have a validated certificate, but not a self generating one. That costs nothing.

And yes, https won't protect against a breached server, but it will add a layer of protection to a server that has not been breached and is better than sending passwords down the line in the plain.



Top


Lost Doggies UK and Ted Smith Photography
tedsmith
Home away from home
Joined:
2004/6/2 6:00
From Derbyshire, England
Posts: 1122
(Show More) (Show Less)
#4 Posted on: 2008/11/9 21:44 Re: Security regarding the plain text login of Xoops 2.0
Quote:
And that is my point really - the option of using HTTPs should be made more obvious


I dunno, it seems pretty obvious to me. The option to use it is in the first preference page an admin is going to tinker with (admin>system>preferences>General Settings).

How would you make it more obvious?

Top


Never let a man who does not believe something can be done, talk to a man that is doing it.
sailjapan
Moderator
Joined:
2005/11/16 6:27
From Osaka
Posts: 1536
(Show More) (Show Less)

 Top   Previous Topic   Next Topic


You can view topic.
You cannot start a new topic.
You cannot reply to posts.
You cannot edit your posts.
You cannot delete your posts.
You cannot add new polls.
You can vote in polls.
You cannot attach files to posts.
You cannot post without approval.

[Advanced Search]