Archive

Posts Tagged ‘moodle security’

More Major Moodle Security Vulnerabilities Discovered

March 28th, 2010 3 comments

Moodle, the open source learning management system, has been plagued with major security and privacy vulnerabilities over the past couple of years with the severity of those issues seeming to be on a sharp upward trajectory. Information about another batch of very serious security and privacy issues was released yesterday (Saturday, 27 March 2010) with notice that everyone needed to upgrade.

Understand…these issues weren’t discovered yesterday…they have been in your codebase for a very long time…they were simply released yesterday to a select few people.

Categories: Moodle Tags:

Moodle — 1990′s LMS Technology in 2010?

February 27th, 2010 10 comments

Moodle should make my life easier, not harder. I do appreciate what it allows me to do—post course content without having to fashion an entire course web page on my own, include RSS feeds from other sources, have one central location for grades and hand-ins and such—but I feel that sometimes it is more lacking for power users than for beginners. Good software should accomodate beginners, advanced beginners, power users, and experts equally well, and in this sense Moodle fails.

Source: http://acdalal.wordpress.com/2010/01/11/my-moodle-wish-list/

Categories: Moodle Tags: ,

Moodle Security, Censorship, and Trust — An Observation

February 3rd, 2010 17 comments

It’s no secret that Moodle, the open-source learning management system, has suffered from some very serious security problems recently. And those security problems aren’t limited to individuals who simply buy a cheap, $5 hosting account, install Moodle using Fantastico, and try to set up an online class when they really don’t know what they’re doing.

In fact, some of the biggest Moodle security problems have impacted customers of some of the largest professional Moodle hosting providers–Moodle Partners–commercial companies endorsed and certified by Moodle to provide professional, enterprise-level services.

An Urgent Moodle Upgrade Notice — Upgrading is a Must!

November 26th, 2009 1 comment

Moodle released an urgent upgrade notice today, two weeks after this post.

To upgrade your Moodle 1.9.x or 1.8.x branch installs, see the following information published today on moodle.org:

http://docs.moodle.org/en/Moodle_1.9.7_release_notes
http://docs.moodle.org/en/Moodle_1.8.11_release_notes

In addition, if you are among the tens of thousands of people using the 1.7 or 1.6 branches (which, as of today, are still being offered for download on moodle.org), it seems support has been discontinued for those branches and there is no fix for your sites. Upgrading is your only option.

Update: The following was posted to the web less than an hour after the “Advanced notice to admins” email was sent out.

Moodle Password Salting: An Introduction to this New Feature

November 23rd, 2009 4 comments

This video introduces you to the new user password salting feature in Moodle and demonstrates how to add this to your site. If your Moodle site is older than the date of this blog post, then chances are your passwords are not secure…this video shows you how to add password salting to significantly improve the security of your site.

A Critical Moodle LMS Security Vulnerability — All Versions

November 12th, 2009 36 comments

EDIT: Start of edit posted on 25 Nov 09…
Moodle releases urgent upgrade notice on Nov 25th, two weeks after this post. To upgrade your Moodle 1.9 or 1.8 branch installs, see the following information.
http://docs.moodle.org/en/Moodle_1.9.7_release_notes
http://docs.moodle.org/en/Moodle_1.8.11_release_notes

If you are among the tens of thousands of people using the 1.7 or 1.6 branches (which, as of today, are still being offered for download on moodle.org), it seems support for those branches has been discontinued and there is no fix for your sites. Upgrading is your only option.
End of edit on 25 Nov 09
——————————————————————–