View Single Post
  #5   Spotlight this post!  
Unread 28-06-2009, 15:07
ZInventor's Avatar
ZInventor ZInventor is offline
Registered User
AKA: Zeno Le Héricy
FRC #2915 (Riverdale Robotics Pandamonium)
Team Role: Alumni
 
Join Date: Feb 2008
Rookie Year: 2000
Location: Portland Oregon USA
Posts: 247
ZInventor is just really niceZInventor is just really niceZInventor is just really niceZInventor is just really nice
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

unfortunatley, the only person with contact info for moodle (other than the non-responsive online suport email) is the tech coord at our school, and he's on vacation.

my friend and i hand-coded the pages (there are several, but all are "included" by index.php)i've looked through every script, and none of them reference external files; whenever i get a new script or such that does, i download the source (if it's creative commons) and tweak it, removing any external references.

oddly, the only place that the code shows up is the "rendered" source. the files on our server are clean.

we'll be contacting moodle as soon as our tech gets back.

another funny thing, making me think that this has nothing to do with the code, is that when we renamed index.php to index1.php, the problem went away, for a couple days, but, so did our site (index1 will not get auto-called like index)

thanks for the ideas,

-Z
__________________
[center]