|
|
|
|
|
|
|
![]() |
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
![]() |
#1 | |
The only guys who wear Hawaiian shirts are gay guys and big fat party animals
|
Quote:
not something you're going to whip up real quick after getting a couple of ideas from some webmasters, who are people in the marketing business. This has been our business for twelve years, developing effective protection. Over those twelve years we've put over a THOUSAND hours into research and development and we STILL have a very long TODO list. Our biometrics seem to work pretty well, now on to some other needed improvements to stay ahead of the hackers. It also sounds like you're not familiar with basic server variables like REMOTE_USER, so you're definitely looking at some schooling before you get into the development. My suggestion - you develop whatever members' area CMS features you do a good job with, make something new that's really neat, and leave the security to the people who do security 24 / 7 / 365. We'd love to work with you and we can build in some cross-compatibility where your members' area content stuff can work with our security stuff, but please, "security" mechanisms developed by those who have no background in security or understanding of the principles of web security are flat out DANGEROUS. We've seen far too many login systems that a hacker can use to dump the whole user database. Actually this board is an example - it's a great message board, the script is made by some people who really know how to make a great message board. However, as I demonstrated on Netpond, the authentication is wide open. All that I have to do in order to get full admin access is make a post. When the admin reads my post, I have their password. Great software, vBulletin, but they aren't security experts so they don't know how to do authentication right (nor should they know, that's OUR job, and we don't need to know how to build message boards). Last edited by raymor; 2009-02-05 at 08:05 PM.. |
|
![]() |
![]() |
![]() |
|
|