| How do you choose secure extensions? |
|
|
|
1. When was the last version released?
2. What kind of release is it? (Stable, Release Candidate (RC), Beta, Alpha)
3. Does the extension have a history of good security practices?
4. Is there a support community for this extension?
5. Is there only a Mambo version of this extension?
6. Is the extension generally bug free?
Bad Practices:
Bugs:
Although the Joomla! core is secure when configured correctly, third party extensions come in all flavors of age and quality. Unless you absolutely trust the extension developer, always review the code should before installing. The following is a list of typical areas of concern. 1. How complex is the extension?
2. Does the extension read or write files to your server?
3. Does the extension interact with other programs on your system?
4. Does the extension run with suid (set-user-id) privileges?
5. Does the extension validate all user input, such as in form fields and in the URL? 6. Does the extension use explicit path names when invoking external programs?
7. Is the extension secure against direct access throught the URL?
8. Is the extension secure against remote file inclusions? 9. Is the extension secure against SQL injections? 10. Is the extension secure against Cross Site Scripting (XSS)? 11. Does the extension need PHP register_globals ON, or Joomla! RG Emulation ON?
12. Does the extension provide higher database access to less privileged users?
|
New Joomla Templates
Social ConnectedName: Social ConnectedDescription: Social Connected is a new professional, easy to use Joomla template released by the Joomladesigns team which includes custom CSS style layouts for the Jomsocial and K2 Extensions. The Social Connected template includes the following features Three Jooml ...Owner: JoomlaDesignsTags: Computers, Communications, Business, Architecture
ExtendName: ExtendDescription: Extend is a professional easy to use Joomla template released by the Joomladesigns Team. The new Extend template supports the following features Includes Four different Joomla Templates Built-in colour picker to customize the template colour scheme Bui ...Owner: JoomlaDesignsTags: Business, Beauty, Architecture
NgineName: NgineDescription: Ngine is a new professional Joomla template from Joomladesigns.co.uk which supports a wide range of features including Five built-in Joomla templates Slide show Slide pop up boxes K2 CSS styles RTL support Six built in font styles Lots of module posi ...Owner: JoomlaDesignsTags: Software, Portal, News, Games
Simply City 2Name: Simply City 2Description: Simply City is a professional, fast loading Joomla template which is easy to use and includes a wide range of features. The web design also supports CSS styles for the popular K2 extension. The Joomla template includes the following features 3 multi col ...Owner: JoomlaDesignsTags: Computers, Communications, Business
Simply CityName: Simply CityDescription: Simply City is a professional, fast loading Joomla template which is easy to use and includes a wide range of features. The web design also supports CSS styles for the popular K2 extension. The Joomla template includes the following features 3 different ...Owner: JoomlaDesignsTags: Electronics, Computers, Communications, Business- Show more...







