 | News Feed |
 | Jobs Feed |
Sections
|
| feed this: |  |
Ivo Jansch's Blog: Apple, Microsoft and PHP are vulnerable
by Chris Cornutt August 26, 2008 @ 08:47:28
Ivo Jansch mentions an interesting comparison that CNet made on security and levels of vulnerability in a new blog post today. Their article mentions PHP right along side Apple and Microsoft in their list of "most vulnerable software".
This article once again demonstrates the cluelessness that some people have regarding what PHP is. First of all, PHP is not a vendor, so "Apple, Microsoft & PHP" does not make much sense. Furthermore, the only reason PHP even is mentioned in this context is that Joomla, Drupal and Wordpress appear in the list. So PHP, a programming language, gets blamed for the security flaws that are in these packages.
By their logic (applications written in a language on the list means the language is more insecure), they should have marked C as a more insecure language given the ratio of PHP to C software.
voice your opinion now!
apple microsoft vulnerable wordpress drupal joomla invalid conclusion
Paranoid Engineering Blog: CMS Battle Drupal va Joomla va Custom Programming
by Chris Cornutt July 03, 2008 @ 12:50:06
On the Paranoid Engineering blog, there's a recent post with a "CMS battle" of sorts between two of the more popular PHP-based content management systems out there - Drupal and Joomla.
It's hard to choose which one to use without trying them out. As usually, there are more options - home grown custom programming or even building your own CMS (which I was once stupid enough to do). Programming from scratch is always fun and beneficial for your skills, however, if you need things up and running in no time or you don't do (or don't want to do) any programming, using a CMS is the way to go.
His vote is for Drupal but he's included a long list of specs comparing the features of both so you can decide for yourself on which is the better fit.
voice your opinion now!
battle content management system cms drupal joomla compare
Zend Developer Zone: Building Websites with Joomla! 1.5
by Chris Cornutt June 06, 2008 @ 12:53:46
The Zend Developer Zone has posted a book review of an Packt book, "Building Websites with Joomla! 1.5" (by Hagen Graf - the book, not the review):
The book is a tutorial guide to Joomla! 1.5 and was already written and published during the development of Joomla! 1.5. This is the final version and it aims for "web developers, designers, webmasters, content editors and marketing professionals" and is suitable for anyone starting out with Joomla! 1.5, for people who upgrade to Joomla 1.5 and for those who just want a good printed guide/manual at hand.
The review steps through the chapters, highlighting points of interest and the wrapup uses terms like "great instructional value", "very passionate about Joomla!" and the fact that the only thing the reviewer sees missing of a chapter about security.
voice your opinion now!
joomla book review packt reference security
PHPClasses.org: Book Review - Building Websites with Joomla! 1.5
by Chris Cornutt May 01, 2008 @ 15:17:24
PHPClasses.org has posted a review of a new PHP-related book from Packt Publishing, "Building Websites with Joomla! 1.5":
This book is a tutorial guide to Joomla! 1.5. It was written and published during the development of Joomla! 1.5. It is intended for Web developers, designers, Web masters, content editors and marketing professionals. It is suitable for anyone starting out with Joomla! 1.5, for people who upgrade to Joomla! 1.5, and for those who just want have a good printed manual at hand.
R.L. (the reviewer) goes through some of the chapters, detailing their content including some of the software mentioned in them (like Fireboard and DOCman). He recommends the book to anyone looking for a good in-hand Joomla! resource but notes that a chapter on security would have been a nice addition.
voice your opinion now!
book review website joomla packt publishing
Zend Developer Zone: Mastering Joomla! 1.5
by Chris Cornutt April 10, 2008 @ 10:34:07
The Zend Developer Zone has posted a review of a new book from Packt Publishing that introduces you to the Joomla! content management system and how to create your own bits of functionality for it - Mastering Joomla! 1.5 - Extension and Framework Development.
Planning to write a few extensions for site's I host I was looking for a book that could at least in part be a replacement for this documentation. As I went through the site of Pact publishing My eye fell on this particular book because of the example chapter they show. And indeed now I have the book I'm in no way disappointed.
He mentions the target audience of the book (and how well it hits it), the approach the book takes to the topics it covers and specific looks at several of the chapter topics like web services, error handling, security and plug-in structure.
voice your opinion now!
book review phpclasses packt joomla extension development
Community News: Joomla!Day USA Announced
by Chris Cornutt September 28, 2007 @ 11:18:00
As mentioned by Elizabeth Naramore on the php|architect website, this year's Joomla!Day USA will be happening next month on October 13, 2007 in New York City:
The event is open to Joomla! fanatics or anyone who wants to learn more about the popular CMS (both using it and coding for it). It will run from 9:30 am - 5:00 pm ET.
There'll be both the regular conference and an un-conference sort of structure to the day allowing for times for official speakers and any audience members to present their ideas (audience speakers will still need to register a topic ahead of time, though). You can check out the official schedule on their site and get more information about the wheres and whens for the day.
voice your opinion now!
joomladay2007 joomla cms newyork ny joomladay2007 joomla cms newyork ny
Secunia.com: Joomla! Multiple Vulnerabilities
by Chris Cornutt July 30, 2007 @ 10:26:00
Secunia.com reports that multiple vulnerabilities have been found in the Joomla! content management system:
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious people to conduct session fixation attacks, cross-site scripting attacks or HTTP response splitting attacks.
The issues are marked as "less critical" but users should still update to the latest version to avoid these issues:
- Certain unspecified input passed in com_search, com_content and mod_login is not properly sanitised before being returned to a user
- Input passed to the "url" parameter is not properly sanitised before being returned to the user. This can be exploited to insert arbitrary HTTP headers.
- An error exists in the handling of sessions and can be exploited to hijack another user's session by tricking the user into logging in after following a specially crafted link.
See the original advisory post here.
voice your opinion now!
joomla content management cms vulnerability secunia joomla content management cms vulnerability secunia
|
Community Events
Don't see your event here? Let us know!
|