CMSMS - security record?

General project discussion. NOT for help questions.
Post Reply
mihai11
New Member
New Member
Posts: 8
Joined: Mon Jun 15, 2009 6:34 am

CMSMS - security record?

Post by mihai11 »

Hello,



Does CMSMS have a good security record?

People who are using it: did you had security breaches?



Regards,
Razvan
RonnyK
Support Guru
Support Guru
Posts: 4962
Joined: Wed Oct 25, 2006 8:29 pm
Location: Raalte, the Netherlands

Re: CMSMS - security record?

Post by RonnyK »

Razvan,

since the 1.2 series, no CMSMS hack has been reported.

Some sites have been hacked since then, but those were shared-hosting or other attacks, no CMSMS hacks.

Ronny
mihai11
New Member
New Member
Posts: 8
Joined: Mon Jun 15, 2009 6:34 am

Re: CMSMS - security record?

Post by mihai11 »

RonnyK wrote: Razvan,

since the 1.2 series, no CMSMS hack has been reported.

Some sites have been hacked since then, but those were shared-hosting or other attacks, no CMSMS hacks.

Ronny
I am really glad to hear this. I will use some modules that I will develop - and those are going to be secure. What also needs to be secure is the CORE of CMSMS.


Regards,
Razvan
User avatar
Grudgeuk
Forum Members
Forum Members
Posts: 20
Joined: Mon Nov 26, 2007 1:08 pm
Location: Ruthin, North Wales, UK

Re: CMSMS - security record?

Post by Grudgeuk »

I have to admit this is one of the best CMS's out there.  Seems to be very secure and I'm very happy with the speed patches are release when there are isssues.
Pierre M.

Re: CMSMS - security record?

Post by Pierre M. »

Hello,

the documentation includes a small security guide. Everybody can contribute hardening recipes.
The core has been reviewed and patched for holes. As an http thing a CMSms install can be protected with additional http things.
Off site backups always help.

Pierre M.
mihai11
New Member
New Member
Posts: 8
Joined: Mon Jun 15, 2009 6:34 am

Re: CMSMS - security record?

Post by mihai11 »

Pierre M. wrote: Hello,

the documentation includes a small security guide. Everybody can contribute hardening recipes.
The core has been reviewed and patched for holes. As an http thing a CMSms install can be protected with additional http things.
Off site backups always help.

Pierre M.
I agree with you: things can always be made more difficult for a potential hacker, but ... life would me much easier if CMSMS itself would be secure and it looks like it is - people from these board have confirmed it.
replytomk3

Re: CMSMS - security record?

Post by replytomk3 »

With all things from the security guide applied, I would worry more about keeping your admin and FTP passwords secure. Consequently, if your site was infected, do not blame CMSMS first, think whether it was a virus that stole your saved FTP password and sent it back to its creator.
mihai11
New Member
New Member
Posts: 8
Joined: Mon Jun 15, 2009 6:34 am

Re: CMSMS - security record?

Post by mihai11 »

replytomk3 wrote: With all things from the security guide applied, I would worry more about keeping your admin and FTP passwords secure. Consequently, if your site was infected, do not blame CMSMS first, think whether it was a virus that stole your saved FTP password and sent it back to its creator.
I am *not* using FTP and I don't recommend it to anyone. It would be much better to use SCP:
http://en.wikipedia.org/wiki/Secure_copy

Since I have a dedicated server, I can configure it the way I want. If you are on shared hosting, you might have to use FTP...
storyleader
Forum Members
Forum Members
Posts: 15
Joined: Mon Aug 14, 2006 1:10 am

Re: CMSMS - security record?

Post by storyleader »

Pierre M. wrote: the documentation includes a small security guide. Everybody can contribute hardening recipes.
I don't see the "small security guide." Where is it?

Thanks!
Do you want to learn to make your point with stories?
http://www.storydynamics.com/etips/
jmcgin51
Power Poster
Power Poster
Posts: 1899
Joined: Mon Jun 12, 2006 9:02 pm

Re: CMSMS - security record?

Post by jmcgin51 »

forum.cmsmadesimple.org/index.php/topic,19660.0.html
ironblaze94

Re: CMSMS - security record?

Post by ironblaze94 »

I have had 1 site out of 30 hacked but that was due to the hosting provider setting the FTP username and password as 'abc123'. I repeatedly told them to change it and then when the website was defaced it was the 'CMS fault'  ::)
Chinboy
Forum Members
Forum Members
Posts: 10
Joined: Tue Apr 14, 2009 2:37 pm

Re: CMSMS - security record?

Post by Chinboy »

ironblaze94 wrote: I have had 1 site out of 30 hacked but that was due to the hosting provider setting the FTP username and password as 'abc123'. I repeatedly told them to change it and then when the website was defaced it was the 'CMS fault'  ::)
I guess the word "DOH!!" comes to mind here  ;D
Post Reply

Return to “General Discussion”