Sicherheitsbericht: Unterschied zwischen den Versionen

Aus MoodleDocs
Wechseln zu:Navigation, Suche
(Die Seite wurde neu angelegt: „{{Sicherheit}} {{Zum Übersetzen}} Als Administrator/in haben Sie auf der Seite ''Einstellungen > Website-Administration > Berichte > Sic…“)
 
Zeile 5: Zeile 5:
  
 
Dieser Bericht enthält folgende Einträge:
 
Dieser Bericht enthält folgende Einträge:
*[[report/security/report security check globals|Register globals]]
+
*register_globals
:register_globals is a PHP setting that must be disabled for Moodle to operate safely.
+
:Diese PHP-Einstellung muss in der PHP-Konfiguration Ihres Moodle-Servers deaktiviert sein, damit Moodle sicher funktioniert.
  
 
*[[report/security/report security check unsecuredataroot|Insecure dataroot]]
 
*[[report/security/report security check unsecuredataroot|Insecure dataroot]]

Version vom 4. Mai 2012, 15:54 Uhr


Baustelle.png Diese Seite ist noch nicht vollständig übersetzt.

Als Administrator/in haben Sie auf der Seite Einstellungen > Website-Administration > Berichte > Sicherheit Zugriff auf einen Sicherheitsbericht.

Dieser Bericht enthält folgende Einträge:

  • register_globals
Diese PHP-Einstellung muss in der PHP-Konfiguration Ihres Moodle-Servers deaktiviert sein, damit Moodle sicher funktioniert.
The dataroot is the directory where Moodle stores user files. It should not be directly accessible via the web.
If PHP is set to display errors, then anyone can enter a faulty URL causing PHP to give up valuable information about directory structures and so on.
Use of the "no authentication" plugin can be dangerous, allowing people to access the site without authenticating.
Allowing ordinary users to embed Flash and other media in their texts (eg forum posts) can be a problem because those rich media objects can be used to steal admin or teacher access, even if the media object is on another server.
Even the flash media filter can be abused to include malicious flash files.
User profiles should not be open to the web without authentication, both for privacy reasons and because spammers then have a platform to publish spam on your site.
Allowing Google to enter your site means that all the contents become available to the world. Don't use this unless it's a really public site.
Using a password policy will force your users to use stronger passwords that are less susceptible to being cracked by a intruder.
Setting a password salt greatly reduces the risk of password theft.
You should generally always force users to confirm email address changes via an extra step where a confirmation link is sent to the user.
The config.php file must not be writeable by the web server process. If it is, then it is possible for another vulnerability to allow attackers to rewrite the Moodle code and display whatever they want.
Make sure that you trust all the people on this list: they are the ones with permissions to potentially write XSS exploits in forums etc.
Review your administrator accounts and make sure you only have what you need.
Make sure that only roles that need to backup user data can do so and that all users who have the capability are trusted.
This checks that the registered user role is defined with sane permissions.
This checks that the guest role is defined with sane permissions.
This checks that the frontpage user role is defined with sane permissions.

Siehe auch