1
russel1
a secure xoops website howto ?
  • 2005/9/6 6:17

  • russel1

  • Just popping in

  • Posts: 16

  • Since: 2005/1/12


Hi I have been trying several things these last few days but can't anywhere.
Here is what I want:
A website with news, forums, downloads, rss, aboutus, photoalbum, donations. I guess this is not that difficult.
The problem is security. After asking a few ppl they told me "watch out XOOPS is insecure". So the key point here is security. What should I use to have (an as mutch as possible) secure website. Protector is one I guess.
I guess I should stay with 2.0.x. But what about all the other things? Should I use the 1.4 news, the cbb forum? what download module? and the others..? Please help. I am lost


Thanks

2
hyperpod
Re: a secure xoops website howto ?
  • 2005/9/6 6:21

  • hyperpod

  • Quite a regular

  • Posts: 359

  • Since: 2004/10/4


Nothing is 100% secure.

You want it to stay more secure?

Make sure you install patches as soon as they come out.

Just like ANY internet scripts.


Also, not sure why security is so ultra important... sounds like you are running a hobby site.


Will you be keeping secret CIA documents on this server as well?


One word of advise, dont let your friends make you so paranoid. Did they offer any better solutions?




Cheers,
Daniel Hall / XOOPS Module Development & Theme Design
Free XOOPS Support > My Wish List

3
russel1
Re: a secure xoops website howto ?
  • 2005/9/6 6:59

  • russel1

  • Just popping in

  • Posts: 16

  • Since: 2005/1/12


I know that nothing is 100% secure that's why I said "as mutch as possible"

I will keep everything patched, but if I go for 2.0.x, how long will it be supported?

Security is magor because this site will be on one of my machines so I don't want that to be hacked.


Yes they did. (athough I don't know if they are better) they told me about drupal and mambo


Thanks for answering

4
Chappy
Re: a secure xoops website howto ?
  • 2005/9/6 7:53

  • Chappy

  • Friend of XOOPS

  • Posts: 456

  • Since: 2002/12/14


Been with XOOPS for about two years now. I can tell you that in that time, as far as I am aware, the devs have been very careful to fix any security breaches in a very timely manner. Elsewhere on this site you will find security raised as a concern, as it should be.

There is preventive security that is reflected in the coding. I am NO expert in that. What I do know is the performance I seen when security issues have been reported. There have not been a lot of alerts from the security watchdogs. When there have been, it has been addressed immediately. Here's a quote discussing the xmlrpc vulnerability several versions back from http://www.gulftech.org/?node=research&article_id=00086-06292005:

Quote:
Special thanks to Jan Pederson from XOOPS for acting so quickly on this very high risk issue. Very prompt, very professional!


This is what I have observed since starting with xoops. Moreover, the xmlrpc vulnerability was not limited by any means to xoops.

I cannot speak to drupal or mambo.

I do feel a great deal of confidence that XOOPS will do as much as possible to make itself secure. If you want further evidence of the concern for security in the coding, find some of the not so distant discussions about username vs displayname in 2.2.
MMM...It tastes like chicken! ...

5
brash
Re: a secure xoops website howto ?
  • 2005/9/6 8:23

  • brash

  • Friend of XOOPS

  • Posts: 2206

  • Since: 2003/4/10


You'll probably find that your webserver (be it apache or IIS) will be of greater risk of getting hacked than Xoops. If you are wanting tight security, there are so many levels you should be concentrating on before your choosen CMS, as it is the last port of call. As you've mentioned there though, I would say the Protector module is a must for anyone security concious, but this alone is by no means a security solution.
IT Headquarters
Innovative IT Solutions

6
russel1
Re: a secure xoops website howto ?
  • 2005/9/6 9:59

  • russel1

  • Just popping in

  • Posts: 16

  • Since: 2005/1/12


Thanks all for anwsering. I trust XOOPS and it's developers otherwise I wouln't even be talking about it. But my question is more of WHAT should I use . eg:

xoops core 2.0.13.1 (I guess 2.2.x is too new)
news 1.3 or 1.4 ?
newbb 1.x or cbb?
xgal or xgallery ?
xdonations or ... ?
wfchannel or ...?
xoopsfaq or smartfaq ?
protector

The goal is to get an (as mutch as possible) trouble-less and secure site up. Features are not that important.
If I use news, newbb and faq that are not part of the official 2.0.13.1 what should I do when a new version of XOOPS comes out.


Thanks again

7
davidl2
Re: a secure xoops website howto ?
  • 2005/9/6 10:10

  • davidl2

  • XOOPS is my life!

  • Posts: 4843

  • Since: 2003/5/26


For version - I would recommend 2.0.13.1

CBB is an ongoing development, which has replaced newbb

Smart modules are constantly being updated, so I would recommend SmartFAQ over XoopsFAQ.

8
khana
Re: a secure xoops website howto ?
  • 2005/9/6 10:23

  • khana

  • Just popping in

  • Posts: 15

  • Since: 2005/1/11


Hi,
And I recommend that the protector must be downloaded from not this official site but the GIJOE's.http://www.peak.ne.jp/xoops/
latest version is maybe 2.52

Login

Who's Online

230 user(s) are online (155 user(s) are browsing Support Forums)


Members: 0


Guests: 230


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Apr 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits