Zikula: A Flexible Open Source Content Management System
home | forum | international support | contact us

Support Forum

Start ::  Community ::  Feedback & Suggestions ::  better attention for security

Moderated by: Support Team

Goto page : Previous Page 1 | 2
Bottom
better attention for security

  • Link to this postingPosted: 04.12.2005, 19:43
    Profile Homepage
    Landseer
    rank:
    Steering Committee Steering Committee
    registered:
     January 2003
    Status:
    offline
    last visit:
    21.08.08
    Posts:
    846
    manarakhave a look at the last posts in the support forum about all those hacked sites and reconsider the proposal for a security / hack relief forum?


    *I* would expect such a forum on pnphpbb.com icon_smile

    -----
    "He is not dangerous, he just wants to play...."
  • Link to this postingPosted: 04.12.2005, 20:42
    Profile
    sampson
    rank:
    Helper Helper
    registered:
     September 2004
    Status:
    offline
    last visit:
    01.07.06
    Posts:
    269
    Quote
    *I* would expect such a forum on pnphpbb.com

    So you are saying that PNphpBB2 should have a security forum for all secuirty issues in PostNuke. Like the bbcode issue with pnForum, the xmlrpc issue and so on. I assume you mean this or perhaps you are just being a smart ass.
  • Link to this postingPosted: 04.12.2005, 20:48
    Profile Homepage
    Landseer
    rank:
    Steering Committee Steering Committee
    registered:
     January 2003
    Status:
    offline
    last visit:
    21.08.08
    Posts:
    846
    I was refering to the security issues in PNphpBB that lead to compromised PN installations. pn_bbcode is also not a core file although it is distributed in .761. BTW, you can use it without pnForum too.

    And please, watch the smilie, again: icon_smile

    Frank

    -----
    "He is not dangerous, he just wants to play...."
  • Link to this postingPosted: 04.12.2005, 20:57
    Profile
    sampson
    rank:
    Helper Helper
    registered:
     September 2004
    Status:
    offline
    last visit:
    01.07.06
    Posts:
    269
    Well if people would keep their installations updated then that would solve the secuirty issues but then short of having the code expire or something, not much way that you can make people do that. I still see installs of PNphpBB2 around using the alpha version thats 3 or 4 years old.
  • Link to this postingPosted: 01.03.2008, 05:31
    Profile
    tekmac
    rank:
    Freshman Freshman
    registered:
     February 2007
    Status:
    offline
    last visit:
    29.02.08
    Posts:
    12
    [quote=larsneo]
    Quote
    server stuff is usually beyond the scope of any application forum - there are definitly better places to discuss this kind of stuff...


    i consider PN as one of the safer CMS available, after some very bad experiences that lead me to it in the first place. but due to this experiences i also try to apply any possible safety / security option possible. and for me as "semi-experienced noobee with prob solving skills" when getting the right info and tips / short how to... the initial idea of a dedicated forum area doesn't sound half bad.

    i don't see why "server stuff is usually beyond the scope of any application forum..."!!! more so, if it involves "server stuff" directly related to the application. it would be USERFRIENDLY to find info on the application website / forum and not have to search the whole internet, would defy claims as above your post about the bad security (i do not agree with that statement) by helping less experienced users to avoid probs due to expert advice how to prevent probs.

    considering the rather dismal content of the Wiki and the lack of any other decent documentation for PN (i would go as far as calling it the worst documented professional CMS) it makes a forum with as much information as humanly possibly even more important.

    i am sure (even by reading related posts) that the PN community has many experts being able to provide valuable info to this much thought after security probs!

    just my 2cents
    tekmac

  • Link to this postingPosted: 01.03.2008, 19:55
    Profile Homepage
    kaffeeringe.de
    rank:
    Professional Professional
    registered:
     September 2002
    Status:
    offline
    last visit:
    14.08.08
    Posts:
    855
    Wow. You dug out a 3 year old discussion! icon_biggrin

    1. There has been done a lot regarding security in .8 - please take a look at the security center which gives you loads of information about your server enviroment and it points out the worst settings.
    2. Most other things are too complicated for newbies and often even not possible in shared hosting enviroments - which is still the suggested enviroment for new users. In these cases the only thing a user can do is to check Apache, MySQL and PHP versions and ask the provider to keep them up to date.
    If you have your own server you should be able to find the required information on the internet. There's no sense in reproducing other site's content for people here in the forums who are not able to find them on their own icon_wink
    3. There is a pretty lenghty Wiki entry about Secruity that I am sure is still updated by larsneo.

    -----
    best regards from Kiel, sailing city

    Steffen Voss

    Member of the PostNuke Steering Committee
    Follow The Zikulan at Twitter
Goto page : Previous Page 1 | 2

Start ::  Community ::  Feedback & Suggestions ::  better attention for security

Main Menu

Extensions Database

Documentation

Development

Login





 


 Log in Problems?
 New User? Sign Up!

Donate to Zikula