Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

powdarrmonkey

Edu Supporters
  • Posts

    5,017
  • Joined

Everything posted by powdarrmonkey

  1. That's just an MDB as a back-end - Access itself has concurrency and row-level locking built in. Agreed. Access is much faster to build straightforward applications in though, and I'm a firm believer that clunkiness is something you design around.
  2. Why is Access 'clunky'?
  3. (disclaimer: I have my Debian hat on; other distributions have their own way of doing things) Yes. It depends how you define "up-to-date". It will give you a version that has been specially packaged for your system and tested by a wide audience, and which is considered stable enough for production use. It may not be the latest and greatest release available. The team looking after Moodle in Debian recently had an injection of fresh blood and they've very active now, especially in security support. The PTS has details of available versions (generally, you want to look at stable, stable-sec(urity) and our release process.) Better than that: install the apticron package, which will email you a report when packages are available (taking careful note of #587597 and #613628 along the way). You're making work for yourself in a couple of ways: - you have to keep an eye out for available packages yourself - you get to do all the testing yourself - you have to backport patches for security releases by hand, if you don't want to upgrade completely whereas with a package from your favourite distribution, you get: - a much wider testing audience than you could emulate yourself - security support from the distribution, even after Moodle stop supporting an old release - automatic installation, upgrade and maintenance by a team who know Moodle and the distribution very well indeed - a chance to contribute to all these things For example, we track all vulnerabilities issued with IDs from the Common Vulnerabilities and Exploits project. That page demonstrates just why you should be keeping up with security releases - remember, all that information is available to the world, including students with itchy fingers. One final thought: if you run a Debian box anywhere, you really should be subscribed to debian-security-announce, where Debian Security Advisories are published.
  4. National Rail have made it quite clear that anybody using 'their' data in interesting ways is in big trouble. Totally unreasonably, of course... but that's part of the reason for the lack of services.
  5. If you're going to host your own box of some flavour of Linux and Moodle, please for the love of the monkey fish use a packaged version of Moodle. You will be glad of the security support and upgrade handling in a year's time.
  6. There have previously been disclosures for SQL injection vulnerabilities and XSS vulnerabilities in that component, so this looks like the SQL attack. All the quoted requests returned HTTP 401, which is "Unauthorized, but specifically when authentication is possible and has failed or not yet been provided", so that's good. Always wipe the box clean before you bring it back up (and next time, preserve the evidence!)
  7. I'm very happy with Insight (web ordering, edu pricing and free NDB on anything, it's especially attractive).
  8. Both services discussed in this thread use the words "personal non-commercial". It is not helpful to anybody reading this thread to muddy the very clear license terms by discussing how schools are non-commercial. Schools who do not make the distinction are in danger of breaking the law*. * not legal advice
  9. Uh?? So "personal non-commercial" doesn't include "personal"?
  10. Ours came from Burconix, tell them Warwick sent you.
  11. "Personal" does.
  12. No. http://grooveshark.com/terms:
  13. From: Adobe Reader 10.0.1 enterprise download is actually bug-filled version 10.0.0 « The Angry Technician
  14. WSUS doesn't just "push out" updates unless you tell it to, or you enable automatic approval. Nobody in their right mind would enable automatic approval for service packs.
  15. email him. You're going to reveal your address anyway, so it doesn't make any difference.
  16. Then you should make that clear. "I woud..." [sic] != "I have experienced and it worked...". This is a data gathering exercise and I really, really don't want it to descend into opinion. I'll take your experience into consideration.
  17. No, you don't. You have wrapped the number in single quotes, so it is cast to a string before evaluation. This is a BAD thing and it can lead to hard-to-find bugs.
  18. as above:
  19. Mmm, Sharepoint is one of the options on my list to evaluate... not going to prejudice it though. MatthewL, p858snake: thanks for your opinions, but I deliberately asked "what do you do", not "what do you think I should do". I want an idea of how the problem has been solved in other schools.
  20. What are your specs?
  21. That's fair enough, but you still shouldn't be evaluating it as a string: if ($lib_opened['active'] == 1)
  22. WordPress › Free WordPress Themes
  23. Why are you evaluating $lib_opened as a string?? Is it supposed to be a boolean value? Don't evaluate "if 1", evaluate "if true": if ($lib_opened['active'] == true) which protects you against rogue values. (For reference, 0 == false and !0 == true.) Then you can take a short cut, and use your variable's sensible name to make it easier to read: if ($lib_opened['active'])
  24. lesson #1: your caps key is between Shift and Tab.
  25. On my list of things to achieve before I die is this note: It's currently just a global mapped drive. There are guidelines for its use but: there is no standardised filing system, so important documents get 'lost' and my phone rings it's impossible for departments to see how much space is being consumed no security controls are in place to prevent tampering it's a dumping ground for all sorts of rubbish, and staff do not tidy up after themselves A solution should allow staff to share documents between themselves and departments where applicable, but should not be a dumping ground for any old rubbish. It should be easily accountable, regimentally organised and easy to maintain. I'm researching in other ways but briefly, I'd like to survey EduGeek members for how you deal with this problem. Please don't turn it into a bash-fest, flamewar or other -ism. TIA.
×
×
  • Create New...