View previous topic :: View next topic |
Author |
Message |
g3n Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
![](images/avatars/691506587417e8bb7b6ffe.gif)
Joined: 13 Dec 2003 Posts: 543 Location: México
|
Posted: Mon May 23, 2005 7:01 pm Post subject: Looking for a secure CMS |
|
|
I'm starting to develop a CMS but i don't know what security holes this kind of software has, i would like to see some code of a secure cms or if anyonw can provide orientation on cms security it would be appreciated. _________________ --[G]-- |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
dejima Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/42355470740fbb3d5d8072.gif)
Joined: 16 Jul 2004 Posts: 130 Location: Greece
|
Posted: Tue May 24, 2005 9:58 pm Post subject: |
|
|
By CMS do you mean something like phpNuke?
If you mean something like this then I would suggest postNuke which is coded in a better way.
Also I would also suggest ezpublish found in http://www.ez.no/community which is much more advanced from al the Nukes.
Check out also mambo and typo3. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
bone Apprentice
![Apprentice Apprentice](/images/ranks/rank_rect_2.gif)
![](images/avatars/gallery/BaldursGate/baldursgate2_anomen.gif)
Joined: 07 Jun 2002 Posts: 255 Location: Midwest, USA
|
Posted: Tue May 24, 2005 10:22 pm Post subject: |
|
|
I was part of the DEV/Admin team for postnuke up until 2 years ago. 2 of the 3 surviving founders and 90% of the DEV team left the project to fork xaraya (www.xaraya.com) because of vision differences with the remaining founder. I have seen both phpnuke and postnuke have security flaws, (I hate to toot our own horn) of which the same problems were not encountered with xaraya. If I were to suggest a CMS, this would be the one.
jt |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
bixit n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 30 Nov 2002 Posts: 6
|
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
DaveHope Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/1930309330417d605c0e9cd.gif)
Joined: 16 Sep 2004 Posts: 117 Location: Dorset, United Kingdom
|
Posted: Wed May 25, 2005 7:17 am Post subject: |
|
|
Rather than looking for secure code to comapre yours with and risk claims that you have copied code, why not get a pen test done on the software when it's complete ? - I'm sure there are plenty of peple in the Gentoo community which would lend a hand. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
g3n Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
![](images/avatars/691506587417e8bb7b6ffe.gif)
Joined: 13 Dec 2003 Posts: 543 Location: México
|
Posted: Wed May 25, 2005 8:22 pm Post subject: |
|
|
DaveHope wrote: | Rather than looking for secure code to comapre yours with and risk claims that you have copied code, why not get a pen test done on the software when it's complete ? - I'm sure there are plenty of peple in the Gentoo community which would lend a hand. |
Tnx, of course i will open a test version when it's all done (at least the v1.0) but i want to check what problems they have run into, not just ripping the code. For example, in php nuke there's a xploit for the already md5'ed password and stuff and i'm checking them. That's what i'm trying to do. _________________ --[G]-- |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|