By charles on Friday, 07 March 2014
Posted in General Issues
Replies 1
Likes 0
Views 723
Votes 0
with Easy Social 1.2 about to be released I would like to know more about the security features that have been added! With a number of Jomsocial and Easy Social Sites being hacked in recent months I believe one should be Pro-active than waiting for a hacker. When checking the data it seem the hackers out of China and India was using the same type of attack on Easy Social and JomSocial.

Now Jomsocial has issued an patch and have asked it members to update their component to 3.1.04. with a social component like Easy Social there are so many ways to attack it or hack it, that I would love to hear how Stackideas is addressing some of the basic security issues?

Do you intend to use or integrate secondary security file into Easy Social in the future? Or add some type of country blocking feature? Or security posting options? Or
Secondary htaccess and php.ini security files?

I have reviewed your post about Easy Social 1.2 and all the new features, but I would like for you to also touch on some of the new security features or options when you release a new update or major upgrade...

Now on the fun side of things can we now call Easy Social the Jomsocial Killer? Wait! Should we wait until Easy Social 1.3!
Hello Charles,

I am not too sure if I really understand you here. The basic security checks which we perform is mostly done on the "token" generation to prevent users from getting exploited via CSRF. All our SQL queries are routed through proper escape methods so it is highly unlikely that an SQL injection would occur.

Also, I think I need to correct you here but there's no sites that are being hacked by EasySocial till date. If you can provide me with some evidance or proof or perhaps the log files, we would most definitely check on those areas.

By the way, security issues are not really "security features". Most issues with hacks are more often bugs. In other words, when a hacker finds a flaw / bug in the system, it tries to manipulate it so unless our extension are like Admin Tools, or JFirewall there is no such thing as "security features"
·
Friday, 07 March 2014 02:00
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post