<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Design vs. Develop &#187; security</title>
	<atom:link href="http://www.designvsdevelop.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.designvsdevelop.com</link>
	<description>the department of planned spontaneity</description>
	<lastBuildDate>Thu, 19 Aug 2010 19:43:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Keep up with official Joomla! security updates</title>
		<link>http://www.designvsdevelop.com/keep-up-with-official-joomla-security-updates/</link>
		<comments>http://www.designvsdevelop.com/keep-up-with-official-joomla-security-updates/#comments</comments>
		<pubDate>Thu, 23 Oct 2008 15:13:46 +0000</pubDate>
		<dc:creator>Joe LeBlanc</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[joomla]]></category>
		<category><![CDATA[Joomla 1.5]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.designvsdevelop.com/?p=296</guid>
		<description><![CDATA[While helping people get the Podcast Suite up and running, I&#8217;m noticing that a lot of people are running vulnerable, outdated copies of Joomla! 1.5.x. Keeping your Joomla! site running with the latest patches is a MUST. The Joomla! core team, working groups, security team, and bug squad all jump in and help write a [...]]]></description>
			<content:encoded><![CDATA[<p>While helping people get the Podcast Suite up and running, I&#8217;m noticing that a lot of people are running vulnerable, outdated copies of Joomla! 1.5.x. Keeping your Joomla! site running with the latest patches is a <strong>MUST</strong>. The Joomla! core team, working groups, security team, and bug squad all jump in and help write a patch whenver a vulnerability is discovered. However, these patches do no good if they are not applied to your site.</p>
<p>So how do you stay on top of Joomla! security issues and releases? The <a href="http://www.joomla.org/download.html">download</a> page for Joomla! now has a handy form where you can sign up for email alerts. If you prefer RSS, use <a href="http://feeds.joomla.org/JoomlaSecurityNews">this</a> feed link. <em>(BTW: the current version as of this writing is 1.5.7, with a 1.5.8 maintenance release around the corner.)</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.designvsdevelop.com/keep-up-with-official-joomla-security-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing Alert &#8211; it&#8217;s not just email</title>
		<link>http://www.designvsdevelop.com/phishing-alert-its-not-just-email/</link>
		<comments>http://www.designvsdevelop.com/phishing-alert-its-not-just-email/#comments</comments>
		<pubDate>Thu, 29 May 2008 15:12:50 +0000</pubDate>
		<dc:creator>Joe LeBlanc</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.designvsdevelop.com/?p=275</guid>
		<description><![CDATA[You&#8217;ve probably received fraudulent emails from people posing to be a bank wanting you to log in to your account. A few weeks ago, I received a phone call from an automated machine claiming to be my bank with a message for me. It then asked for the last four digits of my social security [...]]]></description>
			<content:encoded><![CDATA[<p>You&#8217;ve probably received fraudulent emails from people posing to be a bank wanting you to log in to your account. A few weeks ago, I received a phone call from an automated machine claiming to be my bank with a message for me. It then asked for the last four digits of my social security number; hung up immediately and decided that I would call my bank later.</p>
<p>Today, I received a similar phone call and hung up again. I called my bank right away and they confirmed with the security department that they did not place this phone call. Had I given this information, who knows what would have happened?</p>
<p><strong>REMEMBER</strong>: only give personal information when <strong>you initiate</strong> a phone call with a trusted number. <strong>NEVER</strong> give your personal information when someone <strong>calls you</strong>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.designvsdevelop.com/phishing-alert-its-not-just-email/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joomla training in Chicago</title>
		<link>http://www.designvsdevelop.com/joomla-training-in-chicago/</link>
		<comments>http://www.designvsdevelop.com/joomla-training-in-chicago/#comments</comments>
		<pubDate>Tue, 18 Mar 2008 00:12:39 +0000</pubDate>
		<dc:creator>Joe LeBlanc</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[events]]></category>
		<category><![CDATA[joomla]]></category>
		<category><![CDATA[Joomla Expo]]></category>
		<category><![CDATA[Joomla University]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[seo]]></category>
		<category><![CDATA[templating]]></category>

		<guid isPermaLink="false">http://www.designvsdevelop.com/03/17/joomla-training-in-chicago/</guid>
		<description><![CDATA[In addition to Joomla! Expo, I&#8217;ll also be one of the trainers for Joomla University the next day. My specialty will be in writing Joomla! 1.5 extensions from scratch. However, if you&#8217;re more interested in security, SEO, templating, tinkering, or just getting your first site up, there are sessions there for you too!]]></description>
			<content:encoded><![CDATA[<p>In addition to Joomla! Expo, I&#8217;ll also be one of the trainers for <a href="http://joomla-university.eventbrite.com/">Joomla University</a> the next day. My specialty will be in writing Joomla! 1.5 extensions from scratch. However, if you&#8217;re more interested in security, SEO, templating, tinkering, or just getting your first site up, there are sessions there for you too!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.designvsdevelop.com/joomla-training-in-chicago/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A website resolution you can keep</title>
		<link>http://www.designvsdevelop.com/a-website-resolution-you-can-keep/</link>
		<comments>http://www.designvsdevelop.com/a-website-resolution-you-can-keep/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 01:42:55 +0000</pubDate>
		<dc:creator>Joe LeBlanc</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[drupal]]></category>
		<category><![CDATA[joomla]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[websites]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.designvsdevelop.com/?p=231</guid>
		<description><![CDATA[If you run a website, here&#8217;s a resolution you can keep: make sure your host is up to date. This is something that only takes a few minutes to check and can help you avoid hacker-induced headaches. With PHP being the most popular programming language used on the web, chances are your site uses it. [...]]]></description>
			<content:encoded><![CDATA[<p>If you run a website, here&#8217;s a resolution you can keep: make sure your host is up to date. This is something that only takes a few minutes to check and can help you avoid hacker-induced headaches. With PHP being the most popular programming language used on the web, chances are your site uses it. You&#8217;re definitely using PHP if you use popular programs such as <a href="http://www.joomla.org">Joomla!</a>, <a href="http://www.drupal.org">Drupal</a>, or <a href="http://www.wordpress.org">WordPress</a>. Even if you keep these programs up to date with the latest patches, your site can still be at risk if your host doesn&#8217;t keep PHP itself updated.</p>
<p>If you&#8217;re running Joomla! or Drupal, checking your current PHP version is easy. In Joomla! 1.0.x, log into the administrator backend and go to System &gt; System Info. The PHP version will be listed on this screen as well as under the PHP Info tab. In Drupal, use your admin login, then go to Administer &gt; Logs &gt; Status Report.</p>
<p>Aside from this software, there are other ways you can get the PHP version number. Most shared hosts often give you a control panel where you can log in and manage your account. If your host offers CPanel, the PHP version number will usually be displayed on the front page in the left column.</p>
<p>As a last resort, it&#8217;s easy to create a phpinfo() page you can use to get the version information. Open up a plain-text editor such as Notepad or TextEdit and add the following code:</p>
<pre>&lt;?php</pre>
<pre>phpinfo();

?&gt;</pre>
<p>Save this file as version.php (or anythingyouwant.php) and upload it to your web server using FTP to you web root directory. Then go to http://www.yoursite.com/version.php. Delete version.php from your server right away: you just want it to be available for a moment so you can get the information.</p>
<p>You now have your PHP version number. <strong>So now what?</strong></p>
<p>As of this writing, the current version of PHP is 5.2.5. If this is the version you have, congratulations! Your host is up to date with the latest stable copy of PHP there is. If you have a version of PHP that starts with 5 but isn&#8217;t the latest, check with your host to see if they&#8217;re in transition. A lot of hosts set aside some servers with PHP 5 when it first came out in July of 2004 for testing purposes. You might be on one of these servers.</p>
<p>If your PHP version is <strike>4.4.7</strike>4.4.8, your host has the latest stable version of PHP 4. Ask and see if they have a plan in place for upgrading your account to PHP 5. If your host is running a version of PHP earlier than 4.4.7, <strong>look for a new hosting provider immediately</strong>: your host is <em>at least</em> 7 months behind in applying security patches. Don&#8217;t count on them keeping you up to date in the future, they&#8217;ve already failed you.</p>
<p>As of this past Monday, no new versions of PHP 4 will be released and it is officially obsolete. On August 8th, the PHP team will not even release security updates for version 4.</p>
<p><strong>UPDATE</strong>: the PHP team released 4.4.8 the day after I posted this. The switch from .7 to .8 represents some security patches. It is not considered an entirely new version of PHP; everything should still be backwards compatible. If you are running 4.x.x, make sure your host upgrades you 4.4.8 promptly.</p>
<p>Aside from keeping up to date with software that&#8217;s being actively developed, there are other reasons to move to PHP 5. It performs faster and has new features your friendly open source programmers desperately want to use. The Joomla!, Drupal, and WordPress teams have all avoided writing code that only works on PHP 5 to make sure that you can run their software. Now is the time to return the favor and go with PHP 5!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.designvsdevelop.com/a-website-resolution-you-can-keep/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
