Visit BoonEx Page at Facebook

Facebook

Join BoonEx group at LinkedIn

LinkedIn

Follow BoonEx on Twitter

Twitter

Subscribe to BoonEx Blog RSS feed

RSS
unoboonex

Dolphin 7 Security Audit

This week current Hookie build has undergone a professional security audit by independent specialist - Frank Ruske.

The audit resulted in a handful of "finds", which we're working on right now. Expect proper changes to be incorporated into the next beta. Hope this won't put off the release date.

bad
14
good
 
 

Comments

elcentcom
elcentcom(positive) 35 days agocomment permalink
 
great news, thanks Andrew. It was a big concern after my experiences with various versions.
 
bad
0
good
 
 
JLMARTIN
JLMARTIN(positive) 35 days agocomment permalink
 
Fantastic news! On a side note, it would be interesting to learn about the security protocols and checks you guys put the software under prior to final release.

Thanks!
 
bad
0
good
 
 
mickscool
mickscool(positive) 35 days agocomment permalink
 
Thanks Andrew..it was nice to know about the security audit. It would be nice to get it audited from some other security auditing companies as well and get it certified. We need to make it bullet proof :)
 
bad
1
good
 
View 3 replies to this comment
 
Zarcon
Zarcon 35 days agocomment permalink
 
Thanks Andrew.. Nice to know we will have security awareness in place.
 
bad
0
good
 
 
CALTRADE
CALTRADE 35 days agocomment permalink
 
Wow is the new site a mess on my computer. Andrew, if you are already talking about the schedule slipping one day after you announced it, why don't you just skip that next "beta" and go directly to the RC? I couldn't see what purpose another beta served anyway. I think you got the memo, but we need the upgrade path - and the sooner the better.
 
bad
0
good
 
View 1 replies to this comment
 
greymatters
greymatters(positive) 35 days agocomment permalink
 
Want to give you Great Thanks for security checking by an expert. This is a big issue today as Dolphin need write permission for lots of files.

Great Going.
 
bad
0
good
 
 
sacramento
sacramento 35 days agocomment permalink
 
thanks for the update!
 
bad
0
good
 
 
shaneed
shaneed 35 days agocomment permalink
 
Well, that's good to hear about those finds. But i really really hope there won't be a lot of code change. (praying). Cause...

Even if is beta, i don't expect lots of structure changing, so i'm on my way to live site with it. :)
 
bad
0
good
 
 
croquette
croquette 34 days agocomment permalink
 
I hope that we shall have not need to wait more lontgemp for the dophin 7, because it is already very stable and any autrex updated could be afterward made. Fast fast fast the version RC lol
 
bad
0
good
 
 
marioantoci
marioantoci 34 days agocomment permalink
 
lock it up.
 
bad
0
good
 
 
tuba
tuba 34 days agocomment permalink
 
GOOD LUCK HERE IS A BUG WITH FACEBOOK CONNECT:
Method(actionLoginFormhttp:) was not found in module(facebook_connect)
 
bad
0
good
 
 
gameutopia
gameutopia 32 days agocomment permalink
 
Nice to see that additional 3rd party checkups for security are part of the development. Hope it doesn't set back d7 stable too much, but nice to see extra steps are being taken and considered this time around. Hope we will still see d7 stable before the end of the year, and d7 beta 8 or RC very soon. Looking forward to it.
 
bad
0
good
 
 
Dwain
Dwain(positive) 32 days agocomment permalink
 
Glad to see the things coming together in a positive manner. Thanks!
 
bad
0
good
 
 
bigal0228
bigal0228 31 days agocomment permalink
 
Here is one "security audit" I ran:

Google Index of /templates/tmpl_uni
You will get the following result. I know that the majority of the results will be for 6.1X sites, but there are tens or hundreds of results for 7.X sites as well.

Results 1 - 10 of about 28,000 for index of /templates/tmpl_uni.

Too many dolphin owners stop at the installation process and never do much more than change a banner or two. While Boonex is doing everything they can to make Dolphin a reliable and secure product, it's up to the site owner to protect their site as well. You can do the same search for /ray , /inc, and a few more common directories and get about the same results. Try these directory searches on your own sites and see what the results are.
 
bad
0
good
 
 
hj2008
hj2008 31 days agocomment permalink
 
gfgfdgfd
 
bad
0
good
 
 
hj2008
hj2008 31 days agocomment permalink
 
gfgfdgfdgdfggdfg
 
bad
0
good
 
 
peterdaniel
peterdaniel 29 days agocomment permalink
 
Here's one:

If a database error occurs (this is what i got-"#1030 - Got error 28 from storage engine"), then your sensitive info about your hosting account, such as the path to your files, your username and your PASSWORD will appear on the homepage of your website, for everyone to see. This is what it happened to me last night with the beta7. This is not so cool..

Anyways this is a great project!Keep up with the good work!
 
bad
0
good
 
 
mastermindsro
mastermindsro(negative) 29 days agocomment permalink
 
15 October 2009:
"
1. We'll release one more beta shortly.
2. We'll release RC1 by the end of next week.
"
It's that a deadline, a joke or both? I still can't see that beta coming around even this week..
 
bad
1
good
 
View 2 replies to this comment
 
oldes
oldes(positive) 28 days agocomment permalink
 
Thans Andrew, I am glad to see that you are putting more time to security... I am hoping to put see the final 7.0 soon
 
bad
0
good
 
 
fruske
fruske(positive) 27 days agocomment permalink
 
hi all. I made the audit,this is my username here. So if you like to get similar services just contact me :)
 
bad
2
good
 
View 1 replies to this comment
 
westmerch
westmerch 25 days agocomment permalink
 
Hi Boonex :)

Any update on the release?

By the way, D7 is awesome, what a work you guys did there, good job to the team!
 
bad
0
good
 
 
shaunbaird
shaunbaird(positive) 24 days agocomment permalink
 
I think it's very commendable that this project continues to inspire.
The vision of the founders is immense despite the frustration sof members, IM here all the way and aim to make dolphin a major part of my financial future.
 
bad
0
good
 
 


Post a Comment

Please login to post a comment.

This Post
 
 
unoboonex Blog
All Blogs
Found a bug? Have a suggestion? We really value your feedback!
 
PET:3.30769395828