Can updates to the db introduce any security risk?

This forum is for general questions about extensions for Joomla! 2.5.

Moderators: pe7er, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
gogirl
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Fri Feb 01, 2013 9:52 pm

Can updates to the db introduce any security risk?

Post by gogirl » Tue Feb 05, 2013 4:20 pm

After purchasing a third party real estate component and modifying the php code in it, we have had strange files appear and dissappear. This not only caused complete disfunctional behaviour of the software but what might be a difficult to diagnose security leak. Now I just decided to drop the entire project start from scratch with a new joomla installation and with a new real estate component which does not permit testing unless you buy it first. We were told that "there's no need to edit any PHP code" but I would need to changing the data values in the database using phpmyadmin. This cannot possibly introduce any security risk."

I had really hoped to be able to use the product out of the box and the developer of the extension do not promise any customization code. I've read about SQL injection. I am not sure if it is completely unrelated to the answer I got but can this answer be trusted? I am not even sure if the answer came from a developer or not. Am I right in assuming that changes to php files and databases will increase the threats of files being hacked or give other security issues. (I can read and mostly understand php code but cannot run or test it and would rather not transfer files via ftp)

Locked

Return to “Extensions for Joomla! 2.5”