PEAK XOOPS - Re: Xoops Protector 2.35 in englishin japanese

Re: Xoops Protector 2.35

Target Downloads
Subject
Summary

List posts in the topic

normal Re: Xoops Protector 2.35

msg# 1.1
depth:
1
Previous post - Next post | Parent - Children.1 .2 | Posted on 2005/3/8 19:13
GIJOE  ÀèǤ·³Áâ   Posts: 4110
Quote:
I'm convinced of the added value of the protector module, but i would like to remark a minor security risk in the config.
What you said is right.

Althogh Protector's password itself is not so important, some administrators can set it same as his important password.

It sounds an issue of usages.
I've just added an notice like this.

"Don't set this password same as your important password"

Anyway, it is better if any password is encrypted.
It will be added into Protector >= 2.4.

Quote:
I have also noticed some problems , when I use relative urls in real html code enabled comments of the polls modules, I hope to find out why tomorrow.

What is the problem ?
HTML comment is disabled automatically by Protector.

It is a protection against XSS.
Votes:0 Average:0.00

Posts tree

  Advanced search


Login
Username or e-mail:

Password:

Remember Me

Lost Password?

Register now!