rliskey wrote:
A great example of why is important to download applications ONLY from trusted sites!
I've linked to this topic as an example in the Administrators Security Checklist.
http://help.joomla.org/component/option ... temid,268/
EDIT: Topic title changed for increased clarity
I've been beating the drum on this since last year
It can only get worse IMHO.
As Joomla gets more secure, you will see more and more ingenious ways to subvert that security.
No where is that more true than the templates and extensions directory.
I have always maintained that ALL GPL code submitted to the JED MUST be archived ON Jforge.
If there is to be a code update, it is communicated to JForge and the version number is incremented.
Even if Joomla does not supply the download and defers to the developer (who may want a link to their site and registration before you can download - a behavior I deplore), an archived copy can protect users from having spy code introduced to their machine.
After download, they can compare a generated checksum of the code from site 'X' with the Joomla archived version.
There is an incredible risk of hijack and coercive code being introduced to the community.
Note that the above code connects to the home site and loads HTML DATA, IT COULD EASILY HAVE LOADED CODE INSTEAD TO BE RUN IN THE CONTEXT OF YOUR SITE! ( by returning a string and executing an EVAL against it)
This is very serious news... I hope we can take time off the "GREAT GPL DEBATE DEBACLE" to handle it properly
