PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > ReviewPost Pro Support Forums > ReviewPost Suggestions

ReviewPost Suggestions Suggest ways to improve ReviewPost Pro.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old August 2nd, 2010, 11:51 PM   #1 (permalink)
Member
Verified Customer
 
Swanny's Avatar
 
Join Date: Jun 2002
Location: Western Canada
Posts: 382
Big Security No-No - "Powered by: Reviewpost 5.0"

So I finally upgraded my ReviewPost version 4.04 the other day. I noticed that in the footer it shows: Powered by: Reviewpost 5.0. Also, there is a meta tag <meta name="generator" content="ReviewPost 5.0" />. This is bad in my opinion.

You see, hackers can use version information to take advantage of vulnerabilities. For example, there have been a few "security updates" as you can see in your Announcements forum. If a hacker wanted, they could do a search in their favorite search engine for "Powered by: ReviewPost 4.0" and know that the software is not up-to-date, then proceed to take advantage of any known vulnerabilities. If the version number was absent from the HTML (meta/footer) then they would have a harder time doing this.

Please remove the version number from the meta tag and footer as it is a security concern. That is my suggestion.

p.s. The sky is not falling and I know plenty of software packages / scripts include version numbers. I'm not suggesting your product is not secure, I'm saying it is good security practice to hide the version number to anyone but the admin. Agree? Disagree? Comments?
__________________
My PhotoPost Installations are at:
FordF150.net - Ford Truck Enthusiast Site
FordFlex.net - Ford Flex Enthusiast Site
FordTaurus.net - Ford Taurus Enthusiast Site
FordFusion.net - Ford Fusion Enthusiast Site
Swanny is offline   Reply With Quote
Old August 3rd, 2010, 06:25 AM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,676
This is not a security vulnerability and is common place in software to have the version number as part of the copyright so I guess really its just preference.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
When did "Powered by Photopost" appear? pistebasher Photopost Pro Installation & Upgrades 13 July 11th, 2008 09:53 AM
Removing "Powered By Photpost" Stumeister2 Photopost Pro How Do I...? 3 January 6th, 2006 08:49 AM
Can I *move* the "Powered by . . ." jcall General Discussion 2 February 3rd, 2005 12:59 PM
Move "Powered by" mindbuster How Do I? - vBulletin 3.0.X 2 January 26th, 2005 02:13 PM


All times are GMT -5. The time now is 05:33 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0