[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Demexp-dev] Re: Two questions: account password change and PHP allow_ur

From: Augustin
Subject: [Demexp-dev] Re: Two questions: account password change and PHP allow_url_fopen requirement
Date: Sun, 29 Oct 2006 21:38:47 +0800
User-agent: KMail/1.8.2

Hi David,

Ooops! I forgot to reply to this mail...

On Monday 23 October 2006 01:58 am, David MENTRE wrote:
> Hello Augustin,
> I have two questions related to your code and Drupal:
>  1. Is it possible for the demexp admin in Drupal to change the demexp
>     password of a Drupal user? It happens that demexp users loose their
>     passwords and I need to be able to give them a new one.

??? Did you code a method for that? 
As you know, I haven't implemented any of the admin methods yet.
If you feel it's urgent, I'll work on the admin methods as soon as the new 
site is launched.

>  2. Can Drupal and your demexp module work with allow_url_fopen
>     disabled? It is apparently the cause of a great number of recent
>     attacks:
>       Remote file inclusion vulnerabilities

Drupal developers, just like in any major open source CMS project, take 
security matters very seriously. 
If we apply all security patches as they are released, we have nothing to 
In my module, I use the Drupal API precisely so that I can code secure code 

I am not sure if the core of Drupal needs it, but some contrib modules use it 
(though we may not need them). 
allow_url_fopen is ON at a major host I am using for one of my sites.

The problem is not about it being ON or OFF, but insecure code that do not 
validate and sanitize variables. 

If it makes a difference, turn it on, and be happy :)


Because we and the world need to change.
Intimate Relationships, peace and harmony in the couple.
Revolutionary Psychology, White Tantrism, Dream Yoga...
Condorcet, Approval alternative, better voting methods.

reply via email to

[Prev in Thread] Current Thread [Next in Thread]