Dear community,
I would like to start a discussion regarding Moodle Security. One of my main concerns I do have about using Moodle is regarding security since we have lof of security flaws and holes on PHP scripting language specially on sql injection techniques. This is the main reason I did not adopt Moodle yet. I would like to understand and start a discussion about a few topics regarding this subject:
1) What do you think about a specific Forum about Security ?
2) What are the steps needed to make Moodle secure? (directory permissions, database handling etc..)
3) Concerns about using moodle in a hosted service (my example)
4) Steps to identify security holes and steps for a fast report to Moodle community in order to develop fixes/patches quickly
5) What do you think about creating a Moodle Security quick start Guide?
Thanks!
My regards
Alex.