Research Report: “Investigation on Security in LMS Moodle”
The research report attached to this post was published in the “International Journal of Information Technology and Knowledge Management, January-June 2011, Volume 4, No. 1, pp. 233-238“. It covers some major security flaws in Moodle that will not surprise anyone who has been following Moodle security issues for the past few years. I no longer need to use Moodle, but for those of you who do rely on it, don’t be fooled…just because I’m no longer dedicating time and effort to publically demonstrate major security flaws in the Moodle code and design, don’t take that as a sign that those problems no longer exist! I know of at least two major security holes in the latest version of Moodle and one of them is just as bad as this one I publicized not long ago…and like that vulnerability, it has been discussed in the Moodle forums for months and has received no attention by the devs. If that security issue is not addressed in the next few months, then I may do another “open demonstration” for the public…that seems to be the only way to force action by the Moodle lead dev.

Recent Comments