wazua Thu, Mar 19, 2026
Welcome Guest Search | Active Topics | Log In

2 Pages<12
Alma, which is the best website platform
g-mi
#11 Posted : Sunday, January 29, 2012 1:44:20 AM
Rank: New-farer

Joined: 1/10/2011
Posts: 29
Location: nyahururu
who is to blame the sysadmin or the developer? this again brings up the beef b2n the 2, where the sysadmin is a die hard believer in minimal installations and only stable releases on production system, on the other hand the developer wants to update their packages(untested ofcos) on a production system!!!
The opposite of love is not hate but apathy. So too, the opposite of courage is not fear but mediocrity
D32
#12 Posted : Sunday, February 19, 2012 10:48:36 AM
Rank: Member

Joined: 2/16/2012
Posts: 808
Kihangeri wrote:
Joomla has been exposed as a weak template which is easy to hark.

The Administration Police website has been hacked several times in the recent past. At the same time, most of the websites hacked appear to have been running the Joomla Content Management system:

Gurus caught napping


The best would have to be a customized organic system that was built from the ground up.

With such a system, hackers will have no idea of the architecture that was used, nor will they know the vulnerabilities. Of course the developers will need to meet the laid security policies, such as but not limited to SSL. They will also have to comply with the "Best Practices" in security.

With open-source-ware, hackers can easily study the open code, identify where the weakness is, then attack, while on the other hand, with a customized web app or website, the hacker would have to depend on luck, such as guessing a password. But before they can even begin guessing the password, they will have to find out where the login page is, since it is a customized system.

Even if joommla is fully updated, the plugins can open doors to the system and make the system vulnerable to hacks.

Yes, carelessness can also contribute to vulnerabilities.

A list of unsafe Joomla plugins:
http://docs.joomla.org/Vulnerable_Extensions_List

From SQL Injection to cross site scripting, and everything in between.

If you really do depend upon using an existing system, I would then highly recommend a migration to Drupal. It is powerful, highly customizable, not as easy to use compared to joomla. It is faster, more stable, more scalable and more secure, but an organic system is better.

A good comparisson of wordpress with joomla with drupal:
http://www.socialtechnol...omparison-cms-solutions

Anyone migrating to drupal will love CCK & Views - One or drupals best kept secrets.

Remember, even though there is technology to develop database driven websites, it is not always a must to do so, static websites have a place too. They are much more secure and faster than the best database driven websites. There is almost no vulnerability from the site itself. Should the site be disrupted, it would highly probably be from an attack on the server.

DDoS attacks on the server are common, that is what happened in the recent attack on the US Gov sites following the SOPA saga. A DDos attack is not really a hack, it simply causes the server to crash by flooding it with requests. DDos attacks cannot be prevented by the type of application or website running on the server. Once the server is down, rebooting it is probably all that will need to be done, to bring it back up, but going further to adjust the firewall rules based on the patterns that was observed in the log files, will help minimize the effects of future attacks.
They tried to bury us, they didn't know we were seeds.
KenyanLyrics
#13 Posted : Sunday, February 19, 2012 3:02:43 PM
Rank: Veteran

Joined: 4/16/2010
Posts: 906
Location: Nairobi
@D32 Joomla has CCK, and views in Joomla = template overrides.

Anyway, as you said government sites need to be built with some sort of proprietary system, either built from the ground up, or one of the expensive systems like Expression Engine or WordpressVIP. This will increase the barrier to entry for crackers.
D32
#14 Posted : Monday, February 20, 2012 12:21:27 AM
Rank: Member

Joined: 2/16/2012
Posts: 808
KenyanLyrics wrote:
@D32 Joomla has CCK, and views in Joomla = template overrides.

Anyway, as you said government sites need to be built with some sort of proprietary system, either built from the ground up, or one of the expensive systems like Expression Engine or WordpressVIP. This will increase the barrier to entry for crackers.


Yes, CCK and template overrides can be done in Joomla, but they do not come close to what can be accomplished with CCK & views in Drupal, more especially with views V.2 & V.3.
They tried to bury us, they didn't know we were seeds.
a4architect.com
#15 Posted : Monday, February 20, 2012 12:59:35 PM
Rank: Veteran

Joined: 1/4/2010
Posts: 1,668
Location: nairobi
wordpress is best for the creative mind..
As Iron Sharpens Iron, So one Man Sharpens Another.
2 Pages<12
Forum Jump  
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.

Copyright © 2026 Wazua.co.ke. All Rights Reserved.