Avoiding Sensitive Information Leakage in Moodle

نویسندگان

  • V. Gayoso Martínez
  • L. Hernández
  • A. Queiruga Dios
  • A. Hernández Encinas
  • J. Martín Vaquero
چکیده

During the last years, the use of virtual learning frameworks has increased in the academic community. On account of the requirements derived from the Bologna process, many European universities started to change their education systems to new ones based on information and communication technologies. Those systems are most times based on web environments where the security is an essential issue. In this contribution, we provide an introduction about the e-learning platform Moodle, as well as an overview of the most important attacks against this system. Then, we focus on a specific type of attack that allows illegitimate users to obtain the username and password of other users when making a course backup in some specific versions of Moodle. In order to illustrate this information we describe a real attack against a Moodle 1.9.2 installation, which should encourage Moodle administrators to update their versions or backup configurations in case they are affected by the vulnerability described in this work. We complete our contribution with a list of security recommendations that can be used to secure any Moodle installation. 1

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

An Information Flow Control Model for Both Object-Oriented and Non-Object-Oriented Systems

Preventing information leakage during system execution is essential for a system that manages sensitive information. The prevention can be achieved through information flow control. Many information flow control models have been developed, in which most are for object-oriented systems. In our opinion, the procedural C language is still in used heavily. Therefore, an information flow control mod...

متن کامل

Don't Trust Your Roommate, or, Access Control and Replication Protocols in "Home" Environments

A “home” sharing environment consists of the data sharing relationships between family members, friends, and acquaintances. We argue that this environment, far from being simple, has sharing and trust relationships as complex as any general-purpose network. Such environments need strong access control and privacy guarantees. We show that avoiding information leakage requires both to be integrat...

متن کامل

Privacy Leakage in Multi-relational Databases: A Semi-supervised Learning Perspective1

In multi-relational databases, a view, which is a contextand content-dependent subset of one or more tables (or other views), is often used to preserve privacy by hiding sensitive information. However, recent developments in data mining present a new challenge for database security even when traditional database security techniques, such as database access control, are employed. This paper pres...

متن کامل

MRBAC/AR: an Information Flow Control Model to Prevent Both Intra- and Inter-Application Information Leakage

Preventing information leakage during program execution is essential for modern applications. This paper proposes a model to prevent information leakage for objectoriented systems, which is based on role-based access control (RBAC). It is named MRBAC/AR (modified RBAC for both intrAand inteR-application information flow control) because it is a modification of RBAC96. It offers the following fe...

متن کامل

Characterizing Dynamics of Information Leakage in Security-Sensitive Software Process

Minimizing information leakage is a crucial problem in DRM software development processes, where security information (e.g., device keys and S-BOX of CPRM systems) must be rigorously managed. This paper presents a method to evaluate the risk of information leakage in a software process for security-sensitive applications. A software process is modeled as a series of sub-processes, each of which...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014