How safe is LimeSurvey?

More
4 years 6 months ago #90517 by Raptor
Raptor created the topic: How safe is LimeSurvey?
I am new to LimeSurvey. And this is my first encounter with the software.

First I have to admit that your job is very helpful to our college and community.

I am concerned about the security of the application and the possible attacks or backdoors that by installing this application on my server, it can cause for me. How can I be sure about the security of the software? What can I do to increase the security, as an admin?

Thank you for your help and I am only asking this because I found these on the net:

www.exploit-db.com/exploits/19330/
www.exploit-db.com/exploits/18508/
www.exploit-db.com/exploits/4544/
www.exploit-db.com/exploits/4156/

Thank you
And please keep up the good job.

Please Log in to join the conversation.

More
4 years 6 months ago #90525 by Fred01
Fred01 replied the topic: How safe is LimeSurvey?
That's a good question. Limesurvey is a lot like any "user generated content" application and users can try to exploit that. And because it's open source anyone can look under the hood and look for exploits

But then, anyone can also report problems to the developers also. I know they respond quickly to this stuff. Here's an example from the bugs site. Look around and you'll see others.
bugs.limesurvey.org/view.php?id=7105

There are some installation security hints in the manual. Most of this is typical Linux application security: docs.limesurvey.org/Installation+security+hints

BTW, most of those exploits you posted are ancient. :)
The following user(s) said Thank You: Raptor

Please Log in to join the conversation.

More
4 years 6 months ago #90528 by Mazi
Mazi replied the topic: How safe is LimeSurvey?
Two of these issues are from 2007 so they are more than 5 years old. Another one refers to the old 1.91 version which isn't used that much and the latest issue is already fixed as well.

Anyway, if you find any further issues, please file a ticket at our Bugtracker and we will fix it as soon as possible.


Best regards/Beste Grüße,
Dr. Marcel Minke
(Limesurvey Head of Support)
Need Help? We offer professional Limesurvey support
Contact: marcel.minke(at)survey-consulting.com'"
The following user(s) said Thank You: Raptor

Please Log in to join the conversation.

More
4 years 5 months ago - 4 years 5 months ago #92073 by Raptor
Raptor replied the topic: How safe is LimeSurvey?
I know. And thanks for calling them ancient not anything else... ;)
I just wanted to have a ruler to measure how sure I can be with my lovely LimeSurvey installation, that's all.
Last Edit: 4 years 5 months ago by Raptor. Reason: I forgot to mention sth

Please Log in to join the conversation.

More
4 years 5 months ago #92121 by lowprofile
lowprofile replied the topic: How safe is LimeSurvey?
If an exploit is discovered for pre 2.0 ..eg 1.92+ 120919 will there be any patches?

Please Log in to join the conversation.

More
4 years 5 months ago #92134 by c_schmitz
c_schmitz replied the topic: How safe is LimeSurvey?
No, sorry.

Best regards

Carsten Schmitz
LimeSurvey project leader

Please Log in to join the conversation.

More
4 years 5 months ago #92259 by StuartMark0
StuartMark0 replied the topic: How safe is LimeSurvey?
On a similar note, what happens when I delete any survey post completion, does it deletes just the tables or everything from my server or Lime Survey's server? Is there any possibility that someone can sneak in later and get an access to the deleted surveys?(Survey script, Datafile, Tokens along with contact list)

Please Log in to join the conversation.

Did you already participate in our customer survey?

Don't miss your chance for great prices.

Please click here to participate:

Start now

Start now!

Just create your account and start using Limesurvey today.

Register now