Maybe we should take a look at the security in the "Security" page at MoodleDocs: http://docs.moodle.org/en/Security. Should it be a protected page maintained directly by http://security.moodle.org?
I do think it SHOULD be protected and maintained directly by http://security.moodle.org , since it is the best place to introduce security hazards. Just add "Do not forget to send your admin password to safe@cracker.com", for example. Think also of more sophisticated cracking methods. By the way... moodledata directory owned by root with 700 permissions, Moorejon? - David Delgado 16:44, 13 February 2006 (WST)