With cPanel & WHM 11.28 the ability for server owners to provide custom webmail applications was introduced. To demonstrate this feature we introduced the Atmail Open plugin. Recently Atmail Inc., the creators of Atmail Open, decided to no longer provide…
Archive for CMS
The following disclosure covers the Targeted Security Release 2012-05-31. Each vulnerability is assigned an internal case number which is reflected below. Information regarding cPanel’s Security Level rankings can be found here: http://go.cpanel.net/securitylevels Case 59634 Summary Arbitrary File Write vulnerability in…
cPanel is pleased to announce the release of cPanel & WHM 11.32.3.19 to the RELEASE tier. This monumental release comes from a new development style; focusing on delivering resolution to cases as soon as possible instead of waiting for the next…
The June issue of the Joomla Community Magazine is here!
Our stories this month:
Editor’s Introduction
Summer of Opportunity, by Alice Grevet
Feature Stories
Three Archetypes of Open Innovation Processes & Joomla!, by Ricky D’Cruze
Joomla and Beyond, My First Experience, by Joe Sonne
Meet Joomla!’s 2012 Google Summer of Code Students, by Chad Windnagle
Project News
Leadership Highlights – June 2012, by Alice Grevet
Events
JoomlaDays from China to Greece, by Jacques Rentzke
Book Reviews
“PHP and MySQL 24-Hour Trainer” – the Go-to Resource for PHP and MySQL Novices, by Milena Mitova
Designers
Designing Joomla! Websites – Form vs Functionality, by Phehello Mofokeng
Developers
CMS Testing, by Niels Braczek
Site builders
.htaccess File That FREAKIN Works!, by Cindy Montano
Use Firebug to tweak template CSS, by Daniel Riefstahl
Business Matters
Hosting: Awesome Revenue Stream or Big Headache?, by Gabe Wahhab
The Ultimate Marketing Guide For Joomla Extension Developers, by Luke Summerfield
RFP’s, Proposals, and Contracts – Part 2, by Mike Carson
Google Summer of Code
Project: JGoogle Package, by Aaron Schmitz
Project: Workflow Engine, by Florian Voutzinos
Project: Language Installer for Joomla!, by Javier Gomez
Project: JMediawiki Package, by Prasath Nadarajah
Project: Javascript and CSS Compression API, by Kavith Thiranga Lokuhewage
Project: RESTful Web Service API, by Stefan Neculai
Project: Social Package, by Diana Prajescu
In our next issue
We want to publish your Joomla! story in the next JCM issue! So take a look at our Author Resources content to get a better idea of what we are looking for, and then register to become a JCM author and submit your Joomla! story!
cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system. If your…
The first release candidate (RC1) for WordPress 3.4 is now available. If you haven’t tested WordPress 3.4 yet, now is the time!
cPanel is very excited about the HostingCon debut of cPanel University! cPanel University is a cPanel Certification that you can use to brag about how much you know about cPanel & WHM. That is if you can pass. We don’t…
Been hanging out with a few WordPress.org hackers — Scott, Nacin, and Otto — the last few days in a BBQ-fueled haze of hacking to make plugin directory better. There are over 19,000 plugins listed and they’re really the heart and soul of WordPress for many people, so they deserve a little tender loving care. […]
You may have heard the news that future releases of cPanel & WHM will include SEO and Marketing Tools by Attracta. With over 2 million websites running SEO and Marketing Tools, Attracta makes the world’s most popular SEO Tools. cPanel…
Each year, the WordPress core development team meets in person for a week to work together and discuss the vision for WordPress in the coming year. As annual events go, it’s easily my favorite. Don’t get me wrong, I love attending WordCamps and local WordPress meetups (which are awesome and you should try to attend […]
cPanel & WHM servers using the default cPanel PHP CGI configuration are not vulnerable to the command line switch vulnerability. A recently disclosed flaw in PHP’s CGI implementation allows malicious users to remotely view and execute source code. The exploit…
The May issue of the Joomla Community Magazine is here!
Our stories this month:
EDITOR’S INTRODUCTION
Joomla! Around the World…, by Dianne Henning
FEATURE STORIES
5 Steps Towards Successful Time Management, by Gabe Wahhab
Joomla Events Website Launch, by Mike Carson
Pros and Cons of Partnering with a Web Design Agency, by Luke Summerfield
PROJECT NEWS
Leadership Highlights for April 2012, by Alice Grevet
SITEBUILDERS
Drupal to Joomla! Migration – Truthout.org, by Jon Neubauer
Best Ukrainian sites made on Joomla CMS, Part 3, by Denys Nosov
DESIGNERS
Design Trends – Parallax Designs, by Peter Bui
How to convert Joomla 1.5 template to Joomla 2.5 template, by Tuan Bui
Free Your Fonts From the Web Safe Straight Jacket, by John Hooley
BUSINESS MATTERS
6 Powerful Tips for Every Multilingual Website, by Gabe Wahhab
Skyrocket Your Joomla! Business By Leveraging Subcontractors, by Luke Summerfield
RFP’s, Proposals, and Contracts – Part 1, by Mike Carson
ADMINISTRATORS
Joomla ACL: Configuring back-end ACL, by Jen Kramer
EVENTS
A Tale of Two Cookies, by Paul Orwig
Joomla Events Around the World in May 2012, by Jacques Rentzke
The First Joomla!Day in Iran, by Hagen Graf
In our next issue
We want to publish your Joomla! story in the next JCM issue! So take a look at our Author Resources content to get a better idea of what we are looking for, and then register to become a JCM author and submit your Joomla! story!
EasyApache 3.12 improves CloudLinux’s modhostinglimits, modmono compatibility on CentOS 4, and mod_ruid2 to suPHP support We are excited to announce the release of EasyApache 3.12. The latest version provides numerous updates. CloudLinux’s mod_hostinglimits has been updated to 0.9-5. This will…
WordPress 3.3.2 is available now and is a security update for all previous versions. Three external libraries included in WordPress received security updates: Plupload (version 1.5.4), which WordPress uses for uploading media. SWFUpload, which WordPress previously used for uploading media, and may still be in use by plugins. SWFObject, which WordPress previously used to embed […]
As you may already know, we have been working hard to release 11.32.2 in our production tiers. It is currently available in EDGE, CURRENT, and RELEASE tiers. Currently over half of cPanel & WHM installs are running 11.32.2. This release…
WordPress 3.4 Beta 2
Howdy, folks! Another week, another beta. Since we released Beta 1 last week, we’ve committed more than 60 bug fixes and feature adjustments based on testing and feedback. If you’ve been testing Beta 1, please update to Beta 2 to make sure things are still working for you. If you are a theme or plugin […]
I see a lot of sites get hacked a ton of different ways. This is a topic, that could go on for days. There are 3 major ways, that sites get hacked bad passwords, insecure permissions, out of date software. […] ↓ Read the rest of this entry…
J and Beyond, an International Joomla! Conference, is back for the third year.
For 3 days in May (18th -20th) Joomla! developers and site builders from over 30 countries will gather in Bad Nauheim, near Frankfurt, right in the heart of Europe.
The programme for J and Beyond is created by the participants through a public “Call for Papers” and this year for the first time we will be integrating the Joomla! Project Roadmap sessions.
J and Beyond is your opportunity to:
- Learn from others
- Present your ideas
- Plan for the future
- Meet the people behind the avatar
- AND most importantly – to have fun!
You can find out more by visiting http://jandbeyond.org.
Joomla Roadmap Meetings
The second Joomla Roadmap meeting will be taking place during J and Beyond 2012.
The purpose of this meeting is to get more people more intensely involved with the development of Joomla itself. While there will be room for on-the-fly topics, the main topics or features have been selected ahead of time based on suggestions from the community. You can find our more by clicking here.
Location
Bad Nauheim is right in the centre of Europe not far from Frankfurt (approx 35km). This historic spa town has become a world leading centre for medical care and recovery but is perhaps more famous for being the place where Elvis Presley was stationed during his time in the US Army. You can find our more by clicking here.
J and Beyond News in More Languages
Joomla today announces that its core files have been downloaded more than 30 million times from Joomla.org. Joomla now averages around 1 million downloads every month.
The Joomla community attributes the continued growth in the number of individuals, companies and organizations using the CMS to an aggressive development road map that included the release of Joomla 1.7 in July 2011. The CMS also began adhering to a six-month release cycle meaning more product enhancements being introduced more often. New features in the latest version included multi-database support, one-click version updating, predefined search options and language-specific font settings.
Another key factor in the growth in use of Joomla is that a significant number of government agencies have adopted Joomla, which powers about 3,100 government agencies’ Websites, blogs and intranets. Some features that have driven government adoption include one-click version updates, access control oversight, multilingual capabilities and the Joomla Platform that enables developers to build multipurpose, multi-device applications like mobile and cloud computing apps and enterprise business systems that can run independent from the core CMS. However, organizations using Joomla are not just isolated to government agencies. Recently, an industry research firm reported that Joomla powers at least 1.6 million Websites.
Moreover there has been an explosion in the number of Joomla extensions. More than 2,000 Joomla extensions have been introduced since March 2011. These extensions developed by Joomla’s community of thousands of developers provide added features not found in the core Joomla CMS. By providing compelling new features, these extensions drive Joomla’s widespread adoption in every imaginable industry, from nonprofits to some of the world’s largest financial institutions.
“It is an exciting time for Joomla given its strong position powering 2.7 percent of the Web, combined with its unique opportunity to influence the next wave of mobile and cloud Web development,” Paul Orwig, the new president and former treasurer of Open Source Matters, a nonprofit created to provide organization, legal and financial support to the Joomla project, said in a statement. “The platform split that enables Joomla to be used for developing mobile and cloud computing apps is a welcomed new wave of innovation for the Joomla community.”
As of the end of March 2011, Joomla was downloaded about 22 million times, meaning its adoption rate has grown about 40 percent over the last year. Joomla began keeping track of the number of CMS downloads in 2007. However, the Joomla CMS was first made available in 2005, which means the real number of downloads is presumably much higher.
With 2.7 percent of the Web running on Joomla, it is used for everything from small personal Websites and blogs to some of the largest enterprise, highest trafficked Websites and Intranets, including those operated by Citibank, eBay, General Electric, Harvard University, Ikea, McDonald’s, Sony, many large nations and more. Due to its power and elegance, the most inexperienced user to the most seasoned Web developer can use it.
WordPress 3.4 is ready for beta testers! As always, this is software still in development and we don’t recommend that you run it on a production site — set up a test site just to play with the new version. If you break it (find a bug), please report it, and if you’re a developer, try to […]
Houston, TX — cPanel & WHM version 11.32, which released today to the RELEASE tier, offers numerous updates, including enhancements to mail functionality and login screens. It also officially supports DKIM and includes the Logaholic web analytics application. This latest…
Houston, TX — cPanel & WHM version 11.32, which released today to the RELEASE tier, offers numerous updates, including enhancements to mail functionality and login screens. It also officially supports DKIM and includes the Logaholic web analytics application. This latest…
The April issue of the Joomla Community Magazine is here!
Our stories this month:
Editor’s Introduction
The Reel Deal, by Alice Grevet
Feature Stories
Worksy Makes Joomla User-Friendly for Non-Techies, by Ronni K. G. Christiansen
When in Rome, do as the Romans do, in Japan!, by Norito H.Yoshida
10 Joomla! Prejudices, by Angie Radtke
Best Ukrainian sites made on Joomla CMS. Part 2, by Denys Nosov
Project News
Leadership Highlights from March 2012, by Alice Grevet
Events
JoomlaDay in Iran, Algier, and The Netherlands, by Jacques Rentzke
2012 CMS Expo Learning and Business Conference, by Dianne Henning
Joomla! in Education
Joomla! GSoC 2012, by Jon Neubauer
Administrators
Joomla! Versions and Updates Explained, by Mark Dexter
Are You Sure You Want To Do It Yourself?, by Theo van der Zee
Customizing the Admin Menu, by Randy Carey
Designers
- Award-winning Joomla web site featured by Apple in the new iPad campaign, by Victor Drover
Developers
New from Joomla! Press: Joomla! Programming, by Jacques Rentzke
J!Day Guatemala & J!Platform, by Guillermo Bravo
Check username availability with Ajax, by Nicola Galgano
Site builders
Website Case Study: Global Online Magazine, by Adam D’arcy
Business Matters
Maximizing Your Agency’s Joomla! Expo Experience, by Luke Summerfield
Nine Points to Leverage when Selling a Joomla! 2.5 Upgrade, by Don Cranford
5 Vital Items to Consider When Raising Your Hourly Rate, by Gabe Wahhab
In our next issue
We want to publish your Joomla! story in the next JCM issue! So take a look at our Author Resources content to get a better idea of what we are looking for, and then register to become a JCM author and submit your Joomla! story!
- Project: Joomla!
- SubProject: All
- Severity: Low
- Versions: 2.5.3 and all earlier 2.5.x versions
- Exploit type: Information Disclosure
- Reported Date: 2012-January-7
- Fixed Date: 2012-April-2
Description
Inadequate permission checking allows unauthorised viewing of some administrative back end information.
Affected Installs
Joomla! versions 2.5.3 and all earlier 2.5.x versions
Solution
Upgrade to version 2.5.4
Reported by Cyrille Barthelemy
Contact
The JSST at the Joomla! Security Center.
- Project: Joomla!
- SubProject: All
- Severity: Low
- Versions: 1.5.25 and all earlier 1.5.x versions
- Exploit type: Information Disclosure
- Reported Date: 2012-January-7
- Fixed Date: 2012-March-27
Description
Inadequate permission checking allows unauthorised viewing of administrative back end information.
Affected Installs
Joomla! versions 1.5.25 and all earlier 1.5.x versions
Solution
Upgrade to version 1.5.26
Reported by Cyrille Barthelemy
Contact
The JSST at the Joomla! Security Center.
- Project: Joomla!
- SubProject: All
- Severity: High
- Versions: 1.5.25 and all earlier 1.5.x versions
- Exploit type: Password Change
- Reported Date: 2012-March-8
- Fixed Date: 2012-March-27
Description
Insufficient randomness leads to password reset vulnerability.
Affected Installs
Joomla! versions 1.5.25 and all earlier 1.5.x versions
Solution
Upgrade to version 1.5.26
Reported by George Argyros and Aggelos Kiayias
Contact
The JSST at the Joomla! Security Center.
Joomla! 1.5.26 Released
The Joomla Project announces the immediate availability of Joomla 1.5.26 [senu takaa ama busani]. This is a security release. The Production Leadership Team’s goal is to continue to provide regular, frequent updates to the Joomla community. Learn more about Joomla! developement at the Developer Site.
Download
Click here to download Joomla 1.5.26 (Full package) »
Click here to download Joomla 1.5.26 (Upgrade packages) »
Instructions
- New installation and technical requirements
- Upgrade from an existing Joomla 1.5 version
- Migration from Joomla! 1.0.x
Want to test drive Joomla? Try the online demo or the Joomla JumpBox. Documentation is available for beginners.
Please note that you should always backup your site before upgrading.
Release Notes
Check the Joomla 1.5.26 Post-Release FAQs to see if there are important items and helpful hints discovered after the release.
Security
- High Priority – Core – Password Change Vulnerability. More information »
- Low Priority – Core – Information Disclosure. More information »
Issues Fixed
None.
Joomla! Bug Squad
Thanks to the Joomla Bug Squad for their dedicated efforts investigating reports, fixing problems, and applying patches to Joomla. If you find a bug in Joomla, please report it on the CMS Issue Tracker.
Joomla! Security Strike Team
A big thanks to the Joomla! Security Swat Team for fixing all reported security issues with this release. Members include: Airton Torres, Alan Langford, Bill Richardson, Elin Waring, Jason Kendall, Marijke Stuivenberg, Mark Dexter, Michael Babker, Rouven Weßling, Samuel Moffatt.
EasyApache 3.11.2 includes improvements to FastCGI, along with numerous interface adjustments The release of EasyApache 3.11.2 removes a previous patch that hindered FastCGI performance. This update also corrects a previous patch that resulted in problems with FcgidMaxRequestLen. Both, FastCGI and…
cPanel & WHM 11.30.6.6 provides major fixes for CentOS 4 as well as other minor fixes The recent end of life to CentOS 4 by CentOS, provided issues when updating or installing packages from YUM. cPanel located the correct…