sorry folks but I HAD IT
tools are great , congrates RussW and all the team
however , would you please tell me how do that helps in securing 1000's of joomla sites ? its really confusing for me and many others when i read this :
Quote:
In order for Joomla! to function correctly it needs to be able to access or write to certain files or directories.
If you see "Unwriteable" you need to change the permissions on the file or directory to allow Joomla! to write to it.
then i read again in the same spot :
Quote:
Mode Security:
RED The Directory is World Writable, this might expose your site to unwanted access or exploits
BLUE No `Execute` or `Read` bit set, file execution may be problematic in this directory
GREEN These permissions are reasonably sane, but may still require review. (Default Unix directory Mode is normally: `0755`)
i don't mean to get so negative here , but although i'm very familiar with joomla and read in this forum 100's of issues and how solve it or work around it , in fact i did my share of helping others and exchanging knowledge about it , but i can't help it anymore , this is getting so complicated that what is clear and safe now , won't be so the same next couple of hours .
i have installed joomla many many times , read all i can found about security , and i didn't try any other CMS till now except for joomla , i love it , i recommend it to all the people i know , but when it comes to file and folder permissions , we get no clear answer , putting in mind that "WE" means people who would love to have a beautifull interactive site with opensource CMS , and don't want to be experts in website security !!
if that is the case for all CMS out there , opensource or paid for , i find it very logical to stick to html simple pages with a few free services like auto responders and forms , etc .
all these details , evergoing modificatios , security alerts and updates , certain kind of hosting or you'll get problems , components modules mambots , which is safe and which is not etc etc ,
and in the middle of this race , some upgrade comes out tellining us , kiss your website good bye and start from scratch , and currently there are all kind of questions about numerous versions and problems reelated to it , then i look at the 1.5 which i never tried to even read about it , we have to wait to get the perfect release , which will take the focus , and start new questions and new issues to work on .
i know that the answer would be : this is how it takes , if you can't deal with it , you better find something else you can understand , and my answer for that would be : ok good , but i hope someday you reach to launch a FINAL STABLE RELEASE , which will need a FEW steps to make and a FEW updates to apply , then delete those old versions with its addons forever .
cheers