Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: Vulnerability testing of SugarCRM

  1. #1
    pkruithofjr is offline Member
    Join Date
    Jul 2009
    Posts
    7

    Default Vulnerability testing of SugarCRM

    I have a potential customer that is concerned about security.

    The asked for any documentation/reports that we could provide to show that the software has been tested for vulnerabilities.

    Is this kind of information available to the community?

    Thanks,

    Piet

  2. #2
    RandyLee's Avatar
    RandyLee is offline Sugar Team Member
    Join Date
    Oct 2008
    Posts
    605

    Default Re: Vulnerability testing of SugarCRM

    We tested sugar by several security testing tools, e.g. chorizo, paros. But I am afraid I can't show you the report.

    Better Sugar, Better Life!

  3. #3
    roblaus's Avatar
    roblaus is offline Sugar Community Member
    Join Date
    Dec 2006
    Location
    Vienna / Austria
    Posts
    2,850

    Default Re: Vulnerability testing of SugarCRM

    And why can't you show the report? Because it's so negative? Can you at least tell the result?

    Because I am getting the same questions and if I show your post to my prospects I will probably sell. But not Sugar.
    __________________________
    Robert Laussegger
    http://www.iscongroup.net

    Bei Fragen: support@iscon.at
    Die deutschen Sprachdateien für SugarCRM und das deutsche Handbuch gibt es hier: http://goo.gl/kPsAz
    Ab sofort auch mit 6.4.2

  4. #4
    RandyLee's Avatar
    RandyLee is offline Sugar Team Member
    Join Date
    Oct 2008
    Posts
    605

    Default Re: Vulnerability testing of SugarCRM

    Sugar pass these security tools before they are released, we solved the security problem detected by them for every release, even patches. As we know, everything is improving, including the security testing tools...

    Better Sugar, Better Life!

  5. #5
    SugarDev.net is offline Sugar Community Member
    Join Date
    Feb 2008
    Posts
    1,401

    Default Re: Vulnerability testing of SugarCRM

    Why are solved security bugs not made public?
    Developers go here
    Businesses go there (Dutch)

    Modules:
    SugarDev.net Developer Tools | Config | Dutch Language Pack
    "Nothing gets fixed unless there is a bug"

  6. #6
    RandyLee's Avatar
    RandyLee is offline Sugar Team Member
    Join Date
    Oct 2008
    Posts
    605

    Default Re: Vulnerability testing of SugarCRM

    All of them are filed in Bug tracker, if you want to review, you can search your problem in Bug tracker system.

    Better Sugar, Better Life!

  7. #7
    eggsurplus's Avatar
    eggsurplus is offline Sugar Community Member
    Join Date
    Dec 2005
    Location
    Minnesota
    Posts
    2,343

    Default Re: Vulnerability testing of SugarCRM

    That is just a great stance. Sounds like a very proprietary and closed approach to security. I hope that my systems aren't found by someone who knows about any vulnerability while I don't due to Sugar's non-disclosure policy.

  8. #8
    pkruithofjr is offline Member
    Join Date
    Jul 2009
    Posts
    7

    Default Re: Vulnerability testing of SugarCRM

    Honestly, I think it makes sense to publish these kinds of reports in the Sugar community. It's a bit inefficient to ask your various users, resellers or developers to generate this kind of information on their own.

    It also does a great deal to address any concerns with open source from our customers.

    Piet

  9. #9
    andopes's Avatar
    andopes is offline A Sugar Hero | Help Forum Moderator
    Join Date
    Jul 2006
    Location
    São Paulo - Brazil
    Posts
    8,335

    Default Re: Vulnerability testing of SugarCRM

    The concept of Community and Open Source is to share knowledge to improve some open source application, just like SugarCRM.
    So if this report would be a public one, community users would help Sugar fixing them.
    I believe Sugar should consider a policy like that.

    Best regards
    André Lopes
    DevToolKit / Project of the Month - June 2009
    Lampada Global Services- Open Source Solutions
    Avenida Ipiranga, 318
    Bloco B - CJ 1602
    São Paulo, SP 01046-010
    Brazil
    Office: +55 11 3237-3110
    Mobile: +55 11 7636-5859
    e-mail: andre@lampadaglobal.com

    Lampada Global delivers offshore software development and support services to customers around the world.
    Lampada is proud to be a SugarCRM Gold Partner, revolutionizing Customer Relationship Management.

    I DO NOT answer questions through PM and Email. If you need some help post your question into SugarForum.

  10. #10
    SugarDev.net is offline Sugar Community Member
    Join Date
    Feb 2008
    Posts
    1,401

    Default Re: Vulnerability testing of SugarCRM

    Quote Originally Posted by RandyLee View Post
    All of them are filed in Bug tracker, if you want to review, you can search your problem in Bug tracker system.
    http://www.sugarcrm.com/crm/?option=...&button=Search

    This query returns quite a lot of security issues which are unaccessible by me, even though they are all closed (fixed). This makes it very hard for me to asses the dangers a client is having with his particular version. I also believe this is called security through obscurity.
    Developers go here
    Businesses go there (Dutch)

    Modules:
    SugarDev.net Developer Tools | Config | Dutch Language Pack
    "Nothing gets fixed unless there is a bug"

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Web Services Testing SugarCRM
    By myunus in forum Developer Help
    Replies: 5
    Last Post: 2007-01-15, 02:54 PM
  2. SugarCRM email XSS vulnerability and how to protect yourself
    By ayavilevich in forum General Discussion
    Replies: 12
    Last Post: 2006-10-14, 05:39 AM
  3. News:Vulnerability of PHP
    By MerkaBatistaT130 in forum General Discussion
    Replies: 2
    Last Post: 2005-07-06, 02:28 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •