Quote:
Originally Posted by digioz
I absolutely agree with you on that. Its just that sometimes I am forced to install CMS for customers because they don't have the budget to pay for me to write one for them from scratch. Other then that I try to stay away from PHP CMS myself. 
|
same here when ever I install a cms for some one I take a cms that is a few versions behind and has plenty of security addons.
for example if I was to install phpnuke I would install version 7.8 (most exploits have been found already) patch it for known exploits. I then throw in a few extra security measures of my own and then also include nuke sentinel. Also remove any non needed modules, addons etc.
Ive been running version 7.8 on my server for 3 years now and not once the site has been breached but nuke sentinel has detected 1000's of attempts of known exploits.
Although Id like to add I wouldnt use phpnuke now as it seems to be a dying cms as most module creaters have moved on (me being one of them)!
I hear a lot of people like Joomla but everytime Ive played with it it seems so complicated. And with my bad experiences with it I refuse to add it. eg moving to and from windows and linux servers. When you do that you have to make lots of manual edits to update all the paths. Ais