Joomla! 1.0.13 [ Sunglow ] is now available for download.
Joomla! 1.0.13 features:
* Several low-risk security fixes
* Improved password storage system
* Easier control over Register Globals Emulation
* An Itemid backwards compatibility setting
* Improved administrative session security
* Improved HTTP/HTTPS switchover support
Because Joomla! 1.0.13 is a security release, it is important that you upgrade but we strongly recommend that you take extra precautions when performing this upgrade. This release features several improvements to the password storage system designed to help protect the future security of your Joomla! powered website. These changes will cause compatibility issues with some 3rd Party Extensions, especially bridges. If your Joomla! site utilizes bridges to other applications or extensions that have their own login system such as Community Builder, Virtuemart, or others you should not upgrade your site until those extensions have also been updated.
The changes to the password storage system should be transparent to your Joomla! site's users. As users login for the first time after your site has been upgraded, their passwords will automatically be converted from the old password storage system to the new system. Because of this automatic conversion of passwords, it is important that you backup your entire database before performing this upgrade. Once the process of converting passwords has started, it cannot be reversed.
Release Information
1.0.13 is available as a full package, which contains all Joomla! files or as patch packages which contain only the files that have changed since previous Joomla! 1.0.x version.
* 1.0.13 Full Package
* 1.0.13 Patch Packages
* 1.0.13 Version Information
* 1.0.13 Changelog
Improved Password Storage System
Encryption and hashing technologies are constantly evolving as new processes become known and more time and energy is invested in breaking old systems. The unforunate result of this continuous evolution is that the md5 hashing system is showing its age and has become easier to break with the introduction and rapid development of high-quality rainbow tables. To combat this problem, Joomla! 1.0.13 now features salted hashes which will automatically pad a password string with 16 randomly generated characters to make the hash exponentially more difficult to reverse-engineer or guess. As users login to your Joomla! powered website, their passwords will be automatically converted from the old password storage system, to the new system. The transition should be completely transparent to both you and your users. However, there is no way to reverse this process so it is important that you take all precautions when performing this upgrade and make sure you have a complete database backup before beginning.
Easier Control over Register Globals Emulation
Joomla! has always featured the ability to emulate PHP's register globals setting. However, controlling this feature has always been one of the more difficult aspects of configuring your Joomla! installation because it required manually editing a core file. For Joomla! 1.0.13, all that is history. Joomla!'s register globals emulating controls have been moved into the Global Configuration settings to allow for fast and easy control over this feature. The advantages of this change are two-fold: 1) it will be easier to secure your Joomla! powered website and 2) disabling register globals emulation will help you identify some extensions that will not work in Joomla! 1.5.
Itemid Backwards Compatibility Setting
With the release of Joomla! 1.0.12 came a few changes to the behavior of Joomla! infamous Itemid system. Many people were dissatisfied with the changes and insisted on reverting their Joomla! powered websites back to the previous behavior. To address this problem, Joomla! 1.0.13 now features an Itemid compatibility setting that can be found in the Global Configuration manager. The setting allows you to choose between the Itemid behavior in Joomla! 1.0.12 and the Itemid behavior found in Joomla! 1.0.11 and prior.
Improved Administrative Session Security
To address a potential issue known as "session fixation" attacks, we have implemented some small changes into Joomla! 1.0.13 to improve the security of administrative sessions. Administrative sessions will now be destroyed and recreated with each request in order to prevent session fixation and session hijacking attacks.
SSL Switchover Support
Joomla! 1.0.13 has address a few lingering bugs in the HTTP/HTTPS switchover support reintroduced in Joomla! 1.0.12. SSL switchover support should now work fluidly with seemless transitions between encrypted and unecrypted pages.
Minggu, Juli 29, 2007
Joomla! 1.0.13 Released
Diposting oleh bnparte di 08.52 79 komentar
Kategori : Web Development
Sabtu, Juli 28, 2007
Securing your administrator directory using .htaccess files
To protect your administrator panel a bit more against hacking attempts, you can protect your administrator directory using htaccess files.
There are a few options available: restrict access by ip address and password protection
Restrict access by IP Address
If you are in the possession of a static IP Address it might be a wise idea to only allow access to the Joomla! administrator panel from that address. This can be easily done in the following way. Create an empty .htaccess file in your administrator directory. Put the following in it:
Order Deny,Allow
Deny from all
Allow from 10.0.0.150
Change 10.0.0.150 in your static internet ip address. You can also use partial IP Addresses: 10.0.0
When you visit the admin panel from any other address than the one in here, you will see a 403 Forbidden error. You can add multiple address by separating them by comma's: 10.0.0.150,10.0.0.151
Password protection
You can also create an extra barrier by adding password protection to your administrator directory. Some admin panels like webmin and cpanel support the creation of password protected directories through their admin panel. For others, these are the steps to follow:
Create an empty file .htaccess in your Joomla! administrator directory. Put the following in it:
AuthType Basic
AuthName "Joomla Administrator"
AuthUserFile /full/path/to/joomla/administrator/.htpasswd
require valid-user
Modify the /full/path/to/joomla to match where your site is.
Then create an empty file .htpasswd in the same directory. You will have to enter the user name and encrypted password in that file. An easy tool to create this line is: http://www.flash.net/cgi-bin/pw.pl. Enter the user name and password and click encrypt.
On the next page you will see the user name and password that will have to be put in the .htpasswd file:
admin:1M8rRxU7VA6Ic
Copy and past that line in your .htpasswd file and things should work. To add another user, encrypt the user name and password and put them on the line below the first one.
Diposting oleh bnparte di 07.51 3 komentar
Kategori : Web Development
Kamis, Juli 19, 2007
Creating Favorite Icon
Favorite icon appears to the left of your link in either address bar or in favorites menu of your browser. It gives your website more personality, better visibility in favorites menu and is easy to create.
You'll need:
* Image editor software
* Icon Editor Software.
If you need icon editor, I recommend you PixelToolbox, which you can download for free.
Using your favorite image editor create 256 color, 16x16 pixels image and save it as a .gif, or if you are using PixelToolBox .png or .bmp file.
Open your Icon editor software and import the image you just created.
If you are using PixelToolbox, on the start screen select Windows Icon; 16x16; 8 bit 256 color pallet; click start.
In the new window click Import and navigate to the image you created.
Edit image if needed and save it as favicon.ico on your hard drive.
Upload the icon to the root folder of your web site.
Browser will automatically look for and display the icon you created. However, if you want to help browser find the icon put following between head tags of your web page:
To test your icon, delete all temporary internet files from you machine, go to your web site and add it to your favorites folder. See how your icon looks between other links. You want your icon to stick out, so you may want to change some colors or shapes. Just make sure to clear your browser cache before you test new icons.
More resources:
http://bewebmaster.com
Diposting oleh bnparte di 10.52 1 komentar
Kategori : Web Development
Displaying An RSS Feed On Your Website Using PHP And MagpieRSS
These days everybody wants to have fresh content on their web site. Search engines like to see dynamic web pages, where the content is updated on a regular basis. Static pages that have information that doesn't change are not only boring, but less likely to be visited by a search engine spider than a page that changes every time it is displayed.
By using RSS and the MagpieRSS toolkit, you can import data from another web site or news source and display that information on your own site.
First, download the MagpieRSS kit from http://magpierss.sourceforge.net.
Next, unpack the archive, into a directory off your root on your web site called "rss".
Then, create a directory off your root called "cache". CHMOD this directory to 777.
You'll need to know the URL for the feed that you want to display. You can find this by searching for "RSS feed" in Google, or by going to one of the many sites that allow you to search thrown various sources for feeds. Syndic8.com is one, for example.
To display data from a single source, you can use code similar to this:
require_once('rss/rss_fetch.inc');
$news_feed = '';
error_reporting(E_ERROR);
$rss = fetch_rss("http://www.url-of-the-rss-feed.com");
$items = array_slice($rss->items, 0);
foreach ($items as $item )
{
$news_feed .= '' . $item['title'] . '' . $item['summary'] . '';
}
echo $news_feed;
MagpieRSS not only decodes the data, but it will also cache the data so it will retrieve news articles only once per hour.
Utilizing RSS in this fashion will allow your web site to have fresh content displayed constantly, and will (hopefully!) keep the search engine spiders interested in your site. The more the spiders index your site, the more pages you will have listed in the search engines. And with more pages listed in the search engine indexes you have a much better chance of attracting people to your web site.
Diposting oleh bnparte di 10.45 0 komentar
Kategori : Web Development
Mengenal Web 2.0
umber : Benpinter.Net
Web 2.0 adalah buzzword terbaru di dunia internet. Berbagai inovasi dan fitur-fitur baru yang muncul di dunia web membawa suatu pandangan baru tentang jenis situs web atau aplikasi web yang disebut web 2.0.
Istilah web 2.0 disebut-sebut oleh Dale Dougherty dari O’Reilly Media yang melakukan brainstorming dengan Craig Cline dari Media Live untuk menghasilkan ide konferensi di mana mereka menjadi host. Akhirnya pada bukan Oktober 2004 O’Reilly Media, Battele dan MediaLive mlakukan konferensi web 2.0 pertama dan kedua pada bulan Oktober 2005.
Sebelum muncul istilah web 2.0 yang sering digunakan adalah istilah semantic web.
Ada beberapa karakteristik teknis maupun umum yang menggambarkan suatu situs merupakan situs tipe web 2.0
Secara teknis atau teknologi:
- Memanfaatkan CSS, valid XHTML, dan Microformat
- MS ClickOnce
- Teknik Rich Application seperti Ajax
- Java Web Start
- Flex/Lazlo/Flash
- XUL
- Syndikasi data dengan RSS/Atom
- Agregasi dari RSS/Atom
- URL yang bersih dan berarti
- Mendukung posting ke weblog
- Menggunakan API REST (Representational State Transfer) atau XML Web Service
- aspek jaringan sosial
Umum:
- Mudah untuk memasukkan data atau mengambil data dari sistem
- Pengguna memiliki datanya sendiri pada situs
- Berbasis web murni
Bila dibandingkan antara web 1.0 dengan web 2.0 secara contoh:
Web 1.0 Web 2.0
DoubleClick -> Google AdSense
Ofoto -> Flickr
Akamai -> BitTorrent
mp3.com -> Napster
Britannica Online -> Wikipedia
Personal Websites -> Blogging
evite -> Upcoming.org dan EVDB
spekulasi nama domain -> Optimasi Search Engine
page view -> Cost per click
screen scraping -> Web services
publishing -> Participation
content management system -> Wikis
direktori (taksonomi) -> Tagging(”folksonomy”)
stickiness -> Syndication
Dapat dikatakan bahwa web 2.0 menyajikan suatu layanan web yang berpusat pada user di mana user dimudahkan untuk menggunakan berbagai layanan yang ada. Misalkan dalam hal user interface suatu situs web yang menggunakan teknologi flex (aplikasi rich internet berbasis flash dari macromedia yang sekarang adobe), lazlo(platform aplikasi flash open source) atau menggunakan ajax secara intensif seperti gmail atau google map maka situs itu bisa dikatakan merupakan situs tipe web 2.0.
Anda bisa mencoba aplikasi-aplikasi ajax atau Rich Internet Application berbasis flash pada situs-situs berikut:
http://www.gmail.com
http://www.lazlomail.com
http://map.google.com
http://mail.yahoo.com (Anda harus daftar dulu di link yang ada pada What’s New untuk mencoba versi user interface terbarunya yang sudah memanfaatkan Ajax)
Perlu anda ketahui bahwa Ajax adalah kependekan dari Asynchronous Java Script yang memungkinkan aplikasi web yang lebih interaktif dan kaya fitur sehingga menyerupai kemampuan aplikasi desktop.
Lalu pemanfaatan tag untuk pengkategorian data yang disubmit oleh user sendiri sehingga user lain dapat mencari atau menemukannya menggunakan tag-tag juga merupakan salah satu karateristik jenis web 2.0.
Contoh situs yang memanfaatkan tag-tag untuk contentnya adalah:
http://del.icio.us
http://wwww.technorati.com
http://www.digg.com
http://www.standpoint.com
http://www.askeet.com
Desentralisasi seperti Napster atau pun Bittorrent juga merupakan bagian dari teknologi web 2.0 karena tidak ada server terpusat yang melayani berbagai kebutuhan pengguna tetapi mendayagunakan komputer jaringan pengguna yang ada di dalamnya.
Publikasi artikel, berita yang sebelumnya didominasi situs resmi seperti cnn.com, news.com, atau detik.com, kompas.com untuk Indonesia, sekarang sudah mulai disaingi oleh publikasi non resmi dari perorangan atau lembaga yang tidak ada hubungannya dengan publikasi data media seperti biasanya melalui blog sehingga kadangkala informasi dari blog bisa lebih cepat atau lengkap.
Aplikasi blog ini juga merupakan bagian dari web 2.0.
Dalam aplikasi blog ini juga biasanya disediakan fasilitas sindikasi di mana kita dapat menampilkan judul berita dari sumber lain sehingga kita dapat menampilkan judul content dalam berbagai blog menggunakan aplikasi yang bisa membaca sindikasi itu, baik lewat browser web maupun aplikasi desktop. Ketersediaan sindikasi ini atau pemanfaatan sindikasi untuk menampilkan berita juga merupakan bagian dari teknologi web 2.0.
Pemanfaatan web service serta REST sebagai teknologi pendukung merupakan salah satu karakteristik web 2.0 di mana kita dapat membangun aplikasi web tanpa menyediakan atau membuat fungsi-fungsi pendukung aplikasi sendiri tetapi memanfaatkan fungsi-fungsi aplikasi yang disediakan dari web lain melalui kedua teknologi ini. Jadi misalkan anda ingin menyediakan search engine di situs Anda, maka Anda bisa membuat aplikasi yang memanggil fungsi-fungsi layanan search dari Google atau Yahoo menggunakan REST/Web Service sehingga seakan-akan aplikasi Anda dapat menyediakan layanan ini tanpa membuat fungsi search sendiri.
Pemanfaatan partisipasi user secara menyeluruh juga merupakan bagian karakteristik dari teknologi web 2.0, contohnya adalah Wikipedia di mana content dari wikipedia ini dibuat oleh banyak sekali pengunjung yang langsung dapat mengedit isi dari wikipedia sehingga wikipedia menjadi ensiklopedia dinamis yang terus bertambah isinya setiap saat sehingga dapat mengalahkan kelengkapan isi ensiklopedia lain.
Ebay, Amazon maupun Google juga merupakan situs-situs yang mempelopori web 2.0 di mana mereka memanfaatkan respon user untuk content atau layanan yang mereka sediakan.
PageRank dari Google memanfaatkan klik dari user pada hasil pencarian untuk memberikan penilaian ketepatan hasil pencarian, Ebay memanfaatkan pengguna untuk layanan jual beli melalui internet di mana penjual dapat dinilai oleh pembeli-pembelinya secara online, sedangkan Amazon merupakan situs e-commere yang memanfaatkan respons user untuk menghasilkan pencarian produk yang lebih sesuai serta memberikan informasi produk apa adanya melalui fasilitas review.
Dari berbagai uraian ini, semoga Anda dapat mengerti arti web 2.0 dan membedakan suatu situs adalah situs web 2.0 atau tidak.
Link untuk mengetahui web 2.0 lebih lanjut:
http://www.wikipedia.com/Web2.0
http://www.oreillynet.com/pub/a/oreilly/tim/news/2005/09/30/what-is-web-20.html
Diposting oleh bnparte di 08.07 1 komentar
Kategori : Web Development