PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
papamike
Theme Guru


Joined: Jan 11, 2006
Posts: 135
Location: Southern Influence

PostPosted: Sun Dec 04, 2011 7:22 pm Reply with quote Back to top

Quote:
The risk is out there so why not act now? What is the major reason to ignore this topic and not enhance pwd-database-security? This would benefit all Ravennuke sites/users and drive Ravennuke to be more secure CMS.


RavenNuke has about the best development team that I've seen. If they run across something that should be fixed I am confident that they will fix it. You seem to be grabbing bits and pieces of articles and pasting them here. Then running off of those.

Most security breaches that you read about are usually the work of an insider just trying to prove a point. Just like the person who has been making these little puny attacks against my website since I started responded to this topic. Went from 0 to 50.

In my 35+ years as a Network Engineer I've never seen anyone more entrenched with the idea of security. When a network is first setup and running, all kinds of possible attacks are run off grid in an attempt at breaching security. When found they are corrected.

Anyhow, I do enjoy using a product as secure as RavenNuke, definitely a hot ticket item.
View user's profile Send private message Visit poster's website
duck
Involved
Involved


Joined: Jul 03, 2006
Posts: 267

PostPosted: Sun Dec 11, 2011 2:57 am Reply with quote Back to top

I agree with Crypto and just because you don't see a lot of cases of Ravennuke password hacks exposed does not make for a good argument not to beef security. One can argue back that there isn't many reported cases because Ravennuke is off the hackers radar because it is so sparsely used nowadays compared to other cms's. Nobody is interested in hacking RN sites because most of them have nothing of value to offer them. I mean if you want to search for Vul's in a CMS wouldn't you want to aim your efforts at something like word press or Druupal etc which have millions of sites each or would you prefer to aim at a cms that has a handful? Incidentally I had an RN site compromised. Not actually due to the code itself but by users stupidity and the fact their is not much built into it to help alleviate the weaknesses caused by user stupidity. Things like salts and other hashing methods could do immense effort to reduce those vulnerabilities.
View user's profile Send private message
nuken
RavenNuke(tm) Development Team


Joined: Mar 11, 2007
Posts: 1535
Location: North Carolina

PostPosted: Sun Dec 11, 2011 6:34 am Reply with quote Back to top

This is something the RN Team will look at for future releases. RN 2.5 is too far along to add anything else to. A change like this would require much testing and planning as to how do you deal with existing passwords stored in the database.
View user's profile Send private message Send e-mail Visit poster's website
Guardian2003
Site Admin


Joined: Aug 28, 2003
Posts: 6373
Location: Vsetin, Czech Republic

PostPosted: Sun Dec 11, 2011 9:06 am Reply with quote Back to top

I think the easiest way to deal with password changes is to force a reset so the user has to go through the 'lost password' routine.
My main concern with changing the encryption method is how it might affect some 'ported' modules or 'bridges' that utilise their own authentication method.
Obviously it would be too much of an issue if we had a full Auth API that could deal with registrations, logging in, lost passwords and authentication etc so it could be extended for use in bridges.
I actually had to do something similar recently in my Job Board module as I needed to create stand alone accounts for Job Seekers and Recruiters that fitted around the existing RN routines.
View user's profile Send private message Send e-mail Visit poster's website
crypto
Worker
Worker


Joined: Aug 02, 2004
Posts: 159

PostPosted: Sun Dec 18, 2011 1:07 pm Reply with quote Back to top

nuken wrote:
This is something the RN Team will look at for future releases. RN 2.5 is too far along to add anything else to.

We know that scheduling is a hard task because there is lots to do and resources are limited. Let's hope that "for future releases" doesn't mean that it will take a long time... IMHO this should be highly prioritized and the 'release target' should be put more like an upcoming few months, not like a year(s) Smile.
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum