Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Looking for a secure CMS
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
g3n
Guru
Guru


Joined: 13 Dec 2003
Posts: 543
Location: México

PostPosted: Mon May 23, 2005 7:01 pm    Post subject: Looking for a secure CMS Reply with quote

I'm starting to develop a CMS but i don't know what security holes this kind of software has, i would like to see some code of a secure cms or if anyonw can provide orientation on cms security it would be appreciated.
_________________
--[G]--
Back to top
View user's profile Send private message
dejima
Tux's lil' helper
Tux's lil' helper


Joined: 16 Jul 2004
Posts: 130
Location: Greece

PostPosted: Tue May 24, 2005 9:58 pm    Post subject: Reply with quote

By CMS do you mean something like phpNuke?

If you mean something like this then I would suggest postNuke which is coded in a better way.
Also I would also suggest ezpublish found in http://www.ez.no/community which is much more advanced from al the Nukes.
Check out also mambo and typo3.
Back to top
View user's profile Send private message
bone
Apprentice
Apprentice


Joined: 07 Jun 2002
Posts: 255
Location: Midwest, USA

PostPosted: Tue May 24, 2005 10:22 pm    Post subject: Reply with quote

I was part of the DEV/Admin team for postnuke up until 2 years ago. 2 of the 3 surviving founders and 90% of the DEV team left the project to fork xaraya (www.xaraya.com) because of vision differences with the remaining founder. I have seen both phpnuke and postnuke have security flaws, (I hate to toot our own horn) of which the same problems were not encountered with xaraya. If I were to suggest a CMS, this would be the one.

jt
Back to top
View user's profile Send private message
bixit
n00b
n00b


Joined: 30 Nov 2002
Posts: 6

PostPosted: Wed May 25, 2005 7:06 am    Post subject: Reply with quote

You should take a look at eZ Publish http://ez.no/community

There is also a demo at http://ez.no/ez_publish/demo
Back to top
View user's profile Send private message
DaveHope
Tux's lil' helper
Tux's lil' helper


Joined: 16 Sep 2004
Posts: 117
Location: Dorset, United Kingdom

PostPosted: Wed May 25, 2005 7:17 am    Post subject: Reply with quote

Rather than looking for secure code to comapre yours with and risk claims that you have copied code, why not get a pen test done on the software when it's complete ? - I'm sure there are plenty of peple in the Gentoo community which would lend a hand.
Back to top
View user's profile Send private message
g3n
Guru
Guru


Joined: 13 Dec 2003
Posts: 543
Location: México

PostPosted: Wed May 25, 2005 8:22 pm    Post subject: Reply with quote

DaveHope wrote:
Rather than looking for secure code to comapre yours with and risk claims that you have copied code, why not get a pen test done on the software when it's complete ? - I'm sure there are plenty of peple in the Gentoo community which would lend a hand.

Tnx, of course i will open a test version when it's all done (at least the v1.0) but i want to check what problems they have run into, not just ripping the code. For example, in php nuke there's a xploit for the already md5'ed password and stuff and i'm checking them. That's what i'm trying to do.
_________________
--[G]--
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum