Joomla! Discussion Forums



It is currently Wed Nov 25, 2009 3:45 am (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: How secure is Joomla?
Posted: Fri Jul 28, 2006 4:22 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Fri Jul 14, 2006 11:28 pm
Posts: 20
Sorry for the broad spectrum of this thread, but in an article posted here:

http://tinyurl.com/z9d5w

It discusses security flaws of web 2.0 applications.  So do we all need to be
concerned?  Can anyone suggest steps to take?


Top
  E-mail  
 
Posted: Fri Jul 28, 2006 5:15 pm 
Joomla! Hero
Joomla! Hero
Offline

Joined: Sun Aug 28, 2005 5:03 pm
Posts: 2404
Joomla itself is very good at security. the recent spate of hacks have all been aimed at 3rd party extentions that are weak.

I do not know for sure but I do remember reading that AJAX was not something the Devs were actually looking at using for much in J!

So I don't expect to see much of it in any future releases of J!


Top
  E-mail  
 
Posted: Fri Jul 28, 2006 10:38 pm 
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Sun Apr 16, 2006 12:20 am
Posts: 3060
Location: 127.0.0.1
From other topics, it has been discussed that Joomla! rolls out security updates very quickly after "holes" are discovered. One of the team members noted that Joomla! reports most of the "holes" in the system. Most of the sites that are hacked are running outdated versions of Joomla!, outdated versions of extensions, or extensions that are unsecure.

_________________
Backup, backup, backup! Never forget to backup.
*JoomlaPack can not only backup your site, but help you migrate it as well!*


Top
   
 
Posted: Fri Jul 28, 2006 11:06 pm 
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Mon Sep 05, 2005 3:50 pm
Posts: 248
I think the article you're pointing to is mainly saying before you rush off to use a new piece of technology (in this case AJAX) as a programmer, you need to remember the basics (such as security). It's not saying that it's impossible to make AJAX applications secure, just that people tend to forget about it.

With AJAX, I think it's easy for programmers to forget that anyone can craft an HTTPRequest that looks like it's coming from an AJAX application without actually coming from that AJAX application. It's another attack vector to be aware of.

david


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

Quick reply

 



Who is online

Users browsing this forum: No registered users and 13 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group