Get XOOPS XOOPSXOOPS FAQFAQ ForumsForums NewsNews ThemesThemes ModulesModules
New Posts New Topics All Posts All Forums Index General Modules Themes Development International XOOPS.org

Search

Donat-O-Meter

Make donations with PayPal!
Stats
Goal: $100.00
Due Date: May 31
Gross Amount: $65.00
Net Balance: $61.80
Left to go: $38.20

Donations
studioC  ($25)May-17
Anonymous ($15)May-16
Anonymous ($25)May-4

Learn XOOPS Core

Local Support

Advertisement

XOOPS Code hosted on SourceForge

Cumulus Tag Cloud

2 2.5 2.6 3.0 2013 Abuse adslight AntiHarvesting AntiMalUser AntiSpam API Ban banner Beats billige black Blocks blue Captcha cell Christmas chronolabs content Conversion database demo docek download Dresses editor evden eve facebook Federated floor free Gateway herre Honeypot Human IP jQuery kantor lamps Legal log logger mobile module modules Monster MyAlbum-p Networks newbb news Notices online PageRank pdf Permissions pink Plugin portal Prevention profile project Protector publisher release Rights rmcommon Room sale security Server site Size Smarty Spam statistics stem Studio tag tags tdmcreate template Theme themes userlog website Whitepaper Winter XML XooLaT xoops Xoopspoll Xortify xthemes Yolande ZendFramework

New Users

Registering user

# 136029

Relentless

Welcome to XOOPS!




Bottom   Previous Topic   Next Topic  Register To Post



#1 Posted on: 2012/3/25 17:46 Security and social engineering
This thread is to continue a good discussion started >>here<<

Question is what we can do to make xoops more secure when working with user accounts. We could make xoops safer by adding tricks like password expire, but is adding safety by coding really the way to go? Don't we forget about social engineering and educating our visitors how to prevent abuse of their identity and login credentials?

Top


The Dutch speaking XOOPS community has moved!
____________________________________

For Dutch support now go to www.nlxoops.nl
flipse
Moderator
Moderator
Joined:
2005/9/15 4:11
From The Netherlands
Group:
Registered Users
Community Coordinator (temporary)
Posts: 701
(Show More) (Show Less)


#2 Posted on: 2012/3/25 18:40 Re: Security and social engineering
The reason why social engineering attacks work so well is because most people are lazy and use the same password on every site.

With Browsers saving your passwords this can help as long as you are the only one using your computer (Or account) and you don't have a virus.

As far as Browser issues it really doesn't matter what browser or which OS you are using.

For instance with Firefox if you use sync to sync your passwords across different computers but don't protect the password list with a secure password you might as well have the same password across all of the sites...

Other than people making sure they use different passwords on every system and that they are not easy passwords it is not simple. You can educate the users but if they don't care there is nothing short of coding that you can do to force the issue.

As an example lets look at the Xoops system and two items that have been done for security reasons.

The secure.php file that has been added as well as the whole trusted path series is a good thing. I always used something similar with my database information but who else here did? If you have a problem on your system and the web server dumps the whole directory then a hacker can get easy access to your database information without the information being outside the document root.

Another thing was putting the prefix on the database tables. This was done so even if someone had access to the database name they could not easily choose the right tables. Who would have done this if it wasn't forced?

The point is you see more and more systems forcing the users to use specific setups for their passwords for a reason.



Top


Attending College working towards Bachelors in Software Engineering and Network Security.
redheadedrod
Home away from home
Home away from home
Joined:
2008/2/26 10:05
From Grand Rapids, MI
Group:
Registered Users
Posts: 1069
(Show More) (Show Less)


#3 Posted on: 2012/3/25 22:19 Re: Security and social engineering
I think, we could add some choices for the Admin in the Config, to decide how secure his XOOPS installations should be.

For example, the Admin could decide on issues like:

- what is the minimum length of the required password
- should special characters be required
- when should the password expire (e.g. every 6 months)

So by letting the Admin decide how rigid they want to be with security, we will make a better XOOPS, without forcing it on people.

Reg. education, we could add to Registration the same "password security" check as it is during installation, so the user is aware that his passwords is not secure. (BTW - to check your own password, check it on the Website from Steve Gibson, a known security expert)

To create a SUPER SECURE passwords, go to another side by Steve Gibson.

Some people are recommending longer but easy to remember passwords than short and complex. See this article, although the discussion is still going on, as you see from this article.

However, the password suggested by the first author "yummy salted peanuts" seemed to be pretty secured, as tested by Heystack Website





Top


Please support XOOPS & DONATE
Use 2.5.6 | Debugging | Requests | Bugs
Mamba
Moderator
Moderator
Joined:
2004/4/23 13:58
From Ohio, USA
Group:
Webmaster
Registered Users
Designer Group
Posts: 6939
(Show More) (Show Less)







You can view topic.
You cannot start a new topic.
You cannot reply to posts.
You cannot edit your posts.
You cannot delete your posts.
You cannot add new polls.
You can vote in polls.
You cannot attach files to posts.
You cannot post without approval.
You cannot use topic type.
You cannot use HTML syntax.
You cannot use signature.

[Advanced Search]