Students able to cheat.

Students able to cheat.

by R Ullrich -
Number of replies: 6
Can someone else confirm?   If a student is enrolled in a course and they view an assignment that they have subitted by changing the student number in the URL they can view other students' files?  evil
Average of ratings: -
In reply to R Ullrich

Re: Students able to cheat.

by Gustav W Delius -

Yes, provided they know the filenames of other students' submissions. This is generally true of all files uploaded to Moodle, not only in the assignment module. Anyone who can guess the filename of an uploaded file can access it. This long-standing problem will go away when Moodle 2.0 uses a proper DMS.

In reply to Gustav W Delius

Re: Students able to cheat.

by Ger Tielemans -
The same flaw is in the teachers forum: if you link a remark in the teacher-forum to a studentview, they can use that link to visit any page in the teacher forum, there is no access right check in the teacher forum.
In reply to Ger Tielemans

Re: Students able to cheat.

by Martin Dougiamas -
Picture of Core developers Picture of Documentation writers Picture of Moodle HQ Picture of Particularly helpful Moodlers Picture of Plugin developers Picture of Testers
This is not true - there are checks for this and have been for a very long time.

If you feel you can duplicate this please file a bug in the bug tracker with detailed information.
In reply to Martin Dougiamas

re: security flaw in teacher forum

by Ger Tielemans -
Our school server prints that it is version: 1.2 development (2003111400)

I checked it myself again...
- I create a forum
- I attach a file to a message
- I link that file as a resource

...OOPS, yes you are right, it says that I must be a teacher, so that is OK.

But..
- If I create a thread with several messages
- And I link the header of the thread to a section
- THEN the student has access to that complete thread: If a teacher has somewhere in that thread a forgotten remark, or forgets this link and starts to use this thread like the other threads, or an other teacher with access rights who does not know/see this link (or an insecure warning) in the forum..triest.

Or:
If  a creative teacher wants to show the student answer 12 in the thread, then you can link to the button on the next card with show previous answer, same effect, no check

So is this a bug? no Is this a security flaw? yes (Teacher should always realise, but he is a human... or not have the chance to do this? to protect this human?)

In reply to Ger Tielemans

Where's the 'flaw' in the teacher forum?

by Martin Dougiamas -
Picture of Core developers Picture of Documentation writers Picture of Moodle HQ Picture of Particularly helpful Moodlers Picture of Plugin developers Picture of Testers
I still don't understand what you are talking about, sorry, Ger.

My link in the parent to your post is to the "header of a thread" (by which I assume you mean the "first post in a discussion") and you don't have access to that.

Can you post an actual URL that allows students access to the teacher forum?

And why are you still using 1.2 dev!!?   surprise
In reply to Martin Dougiamas

Re: Where's the 'flaw' in the teacher forum?

by Ger Tielemans -

Lets start at the end: why am I using still this version?

  1. everything works smile
  2. We have 1237 users on it
  3. We have 146 running and try-out courses on it
  4. we made lots of small patches, for example
    1. to integrate the gradebook with columns
    2. to make the excelsheet download working for grades (and gradebook)
    3. to make the short answerfield longer (user request)
    4. to allow Novell UN/PWs working
    5. to connect LDAP
    6. to allow the adminuser to surpass the LDAP for special users
    7. to change several fields from input to echo (not overrule email form LDAP, let users use forward email instead..)
    8. to hide the header of a hidden section for users (user request)
    9. to jump from the bold current day to the section of current week in our calendar
    10. etc..

Bill Gates offers several versions of his product windows. Bill offers you to check your system and advises you which patches to install. But YOU (= I ) choose..

OK, a small version of this would be:

  • The technical hats of Moodle make a long list of approved patches for each release and situation
  • For a new release this list is updated: some patches are no longer necessary
  • Until this day I have the choice to use only the limited core set of Moodle or do a lot of handtuning myself. (And with version 2.0 in the near future, the support for 1.3 will slowdown?)

By the way, Bill extended the promissed expiration date of Windows98 again...so..1.4?


Ok, I tested the situation  in beta 1.3 (other server) Yes there it is gone, nice, thanks..

(I cannot give you there a handmade account, because I did not yet implement the patch to surpass the LDAP.)

Average of ratings: Useful (1)