Security Threshold Settings

guys, i know this has been addressed, however, i didnt see it in trac as a bug report. so i am listing it here as a bug because it has caused quite a stir from the community at large. yes it was suggested that the settings be disabled, and most of us have done that, but we still find from time to time, that there are forum posts about the Possible Security Attack notice.

Security Threshold Settings are malfunctioning.

Regards,

DosDawg

When a GIG is not enough --> Terabyte Dolphin Technical Support - Server Management and Support
Quote · 23 Feb 2010

It will be disabled by default since 7.0.1

Rules → http://www.boonex.com/terms
Quote · 24 Feb 2010

hey AlexT, thanks for the response. so the solution is to disable the security feature and not fix it? just making sure i understand?

Regards,

DosDawg

When a GIG is not enough --> Terabyte Dolphin Technical Support - Server Management and Support
Quote · 24 Feb 2010

hey AlexT, thanks for the response. so the solution is to disable the security feature and not fix it? just making sure i understand?

Regards,

DosDawg

it can not be fixed from our side... the problem is in PHPIDS

Rules → http://www.boonex.com/terms
Quote · 24 Feb 2010

Then it should be ripped out completely.

https://www.deanbassett.com
Quote · 24 Feb 2010

im sure it will remain in the source because it would take them months finding where its implemented across the site and that would take away time from creating mods to sell in the market. so we can wait for v8, and maybe the last remnants of this security threshold will be removed.

this was clearly never tested, seems to have been thrown together and something to say it was secure.

so if there is a problem with PHPIDS, what are you going to now do for securing the dolphin platform?

Regards,

DosDawg

When a GIG is not enough --> Terabyte Dolphin Technical Support - Server Management and Support
Quote · 25 Feb 2010

I know the emails are annoying, and most people have no clue what they mean.

But I actually find this useful.

Most of the time it stops spammers from even joining my site.

I think the real issues is PHPIDS is not configured to ignore harmless html, and the security  warning is non-existant in most parts of the site. The admin just gets emails.

It would be 100x more useful if it just striped out the offending bits, and alerted the user that there content was filtered due to bad content.

Light man a fire keep him warm for a night, light him ON fire & he will be warm the rest of his life
Quote · 26 Feb 2010
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.