I still wonder over things like this
Open Source = anyone and everyone who wants to harm for one reason or the other, has the ultimate opportunity to work through all of the source code and find possible coding flaws, which if found, could in turn possibly lead to a successful hack.
I have written about this before and will probably do it again.
A couple of my popular sites have been previously hacked and as they say, once burnt twice shy.
My advice to anyone that uses Open Source:
- Don't tell the world you are using an open source system e.g. don't publish it on your website
- If you use an Open Source product for your clients, don't put them at risk by adding them to your portfolio without asking prior permission
- Remove any obvious code that is typical of the system you are using - this type of code is a typical point of search for bots on the look out for specific systems e.g. powered by "NAME" cms
- Where possible block / password protect the Admin / Manager interface
- MODx specific - Delete or disable where possible all unused plugins, modules and snippets from the Admin / Manager interface
- MODx specific - Remove all unused plugin, module and snippet files from the assets folder
- Backup your website and database on a regular basis - but don't override old backups (just in case a hack took place before you realised it and you have backed the hack up with the last DB/Site backup)
- Keep a fully "up to date" working copy of your website on your computer = localhost (EasyPHP, Wamp, Zend Server CE, XAMPP etc.)
If, lets say, one of the default snippets has a flaw and you don't actually use it, but you leave it as is, you are vulnerable to a hack
A great example was not so long ago, the "Forgot Manager Login" plugin in Evo - I personaly have never used it, nor have my clients, so I never install it. My sites were not affected by this hack, simply because the code wasn't on the server or in the DB.
Simple rule of thumb - get rid of what's not used, it limits the risk of being hacked.
The best place to look for people who are using Open Source - The projects Forum, a small suggestion - don't add your website to your public profile, and don't use your real or company name.
[ed. note: iusemodx last edited this post 13 years, 2 months ago.]