Are Wrappers / I Frames safe

Discussion regarding Joomla! 2.5 security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Locked
cloudservices
Joomla! Fledgling
Joomla! Fledgling
Posts: 4
Joined: Wed Aug 06, 2014 7:48 am

Are Wrappers / I Frames safe

Post by cloudservices » Wed Aug 06, 2014 7:57 am

Hi All,
I have 100 + sites that i want to administer content easily.
I am thnking of using the wrapper componant to feed content off a mother site to the child sites..

My question is, is the using the wrapper a security risk.
If i use it to supply many sites, is it a vulnerability.

User avatar
Bernard T
Joomla! Guru
Joomla! Guru
Posts: 782
Joined: Thu Jun 29, 2006 11:44 am
Location: Hrvatska
Contact:

Re: Are Wrappers / I Frames safe

Post by Bernard T » Wed Aug 06, 2014 11:16 am

IFRAME is not danger by itself, it's only a HTML tag that displays content from another website. The insecurity starts if you don't have control over what content will that another website send to your visitors.

You could use Iframes, yes, but you are loosing functionality like history etc. It would be better if you develop or use existing component which fetches remote content (RSS?) and displays as a part of your website.
VEL Team || Security Forum || PHP/Web Security Specialist || OWASP member
JAMSS author http://forum.joomla.org/viewtopic.php?f=621&t=777957
Twitter: @toplak

cloudservices
Joomla! Fledgling
Joomla! Fledgling
Posts: 4
Joined: Wed Aug 06, 2014 7:48 am

Re: Are Wrappers / I Frames safe

Post by cloudservices » Wed Aug 06, 2014 11:48 am

Thanx BernardT,
The iframe content will be all from a mother site that i will control all the content.
And loosing functionality isny really an issue.
Any suggestions regarding companants i could use.

Thanx
Peter


Locked

Return to “Security in Joomla! 2.5”