PHP 中的开源 CMS 与安全事实!

发布于 2024-11-06 08:38:47 字数 154 浏览 0 评论 0原文

我对 Joomla、Drupal、wordpress 和小型 cms 配置有经验。但我的一位客户询问上述 cms 的安全级别。我从来没有考虑过安全风险,这对我来说真的很新。在考虑安全级别和最小风险时,我可以在什么基础上选择最好的 CMS?我们可以为服务器提供什么样的安全性来使应用程序高度安全?

I have a experience on Joomla, Drupal, wordpress and small cms configuration. But one of my client is asking about the security level in the above cms. I never thought about the security risks and it's really very new to me. On which basis i can choose which is best CMS when considering about the security level and minimum risks? And what kind of security we can provide to the server make the application highly secured?

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(1

入怼 2024-11-13 08:38:47

你提到的所有大型CMS产品都应该没问题。看看还有谁在使用它们;这是判断产品到底有多好的好方法。例如,白宫使用Drupal。这个事实让我对 Drupal 充满了信心。

重要的是确保您及时了解已发布的所有安全修复程序。

所有这些产品中的绝大多数安全问题都来自您可能安装的非核心模块。如果您确实担心安全性,我建议将您使用的模块数量保持在绝对最低限度。

在您确实需要使用外部模块的地方,请进行彻底的调查以了解它的效果如何:它多久更新一次?是否存在可能导致安全问题的已知错误?它的使用有多广泛?正如我上面提到的核心 CMS,谁在使用它?

您还应该确保您的网络服务器是安全的。不仅仅是您的 CMS 会为黑客提供入侵途径。关闭所有不需要的端口和服务。确保所有可能的内容都已加密(使用 SFTP,绝对不是 FTP)。如果您使用基于 PHP 的 CMS(例如 Drupal),请使用安全强化的 PHP 版本 (Suhosin) 而不是基本版本。

最后,您应该接受这样的事实:无论您的软件有多好,无论您多么警惕,您仍然可能会遭到黑客攻击。更糟糕的是,您甚至可能在不知情的情况下遭到黑客攻击。即使是最好的软件也有可以被利用的缺陷。因此,在任何人都可以访问任何真正敏感的数据之前,您应该努力实现多层安全保护。

All the big CMS products you mentioned should be okay. Look at who else is using them; this is a great way to judge how good the product really is. For example, Drupal is used by the White House. This fact gives me a lot of confidence in Drupal.

The important thing is to make certain that you keep up-to-date with any security fixes that are released.

The vast majority of security problems in all these products come from non-core modules that you might install. If you're really worried about security, I suggest keeping the number of modules you use to an absolute minimum.

Where you do need to use an external module, do thorough investigations to find out how good it is: how often is it updated? are there any known bugs with it which may be security issues? how widely used is it? And as I mentioned above with the core CMS, who is using it?

You should also ensure that your web server is secure. It's not just your CMS that will provide routes in for a hacker. Close all un-necessary ports and services. Make sure that everything possible is encrypted (use SFTP, definitely not FTP). If you're using a PHP-based CMS such as Drupal, use a security-hardened PHP version (Suhosin) rather than the basic version.

Finally, you should accept that no matter how good your software and no matter how vigilant you are, you could still get hacked. Worse, you could get hacked without even knowing about it. Even the best software has flaws which can be exploited. For this reason, you should aim to have several layers of security before anyone can get to any genuinely sensitive data.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文