<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Joomla! Security &#8211; Ever been hacked? Sorting fact from fiction. Useful security tips for Joomla! users.</title>
	<atom:link href="http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/</link>
	<description>The latest hosting news and developments from the Rochen team.</description>
	<lastBuildDate>Wed, 02 Nov 2011 14:35:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
	<item>
		<title>By: I.Adam</title>
		<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/comment-page-1/#comment-11365</link>
		<dc:creator>I.Adam</dc:creator>
		<pubDate>Mon, 09 Nov 2009 23:57:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rochen.com/?p=3#comment-11365</guid>
		<description>May be slightly off topic but I am worried about my admin login info when I use free wifi or other public networks. Is there a way in joomla to not send my username and password in clear text? i do not have SSL on my site.</description>
		<content:encoded><![CDATA[<p>May be slightly off topic but I am worried about my admin login info when I use free wifi or other public networks. Is there a way in joomla to not send my username and password in clear text? i do not have SSL on my site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Hibbitt</title>
		<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/comment-page-1/#comment-9868</link>
		<dc:creator>Jon Hibbitt</dc:creator>
		<pubDate>Mon, 05 Oct 2009 12:26:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rochen.com/?p=3#comment-9868</guid>
		<description>Hi Chris,

Thanks for this excellent information, a quick couple of checks to ensure all was done according to your instructions was a big relief. This has got to be the reason why so many sites host with Rochen - you guys are on it.

Cheers,
Jon</description>
		<content:encoded><![CDATA[<p>Hi Chris,</p>
<p>Thanks for this excellent information, a quick couple of checks to ensure all was done according to your instructions was a big relief. This has got to be the reason why so many sites host with Rochen &#8211; you guys are on it.</p>
<p>Cheers,<br />
Jon</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Adams</title>
		<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/comment-page-1/#comment-1995</link>
		<dc:creator>Chris Adams</dc:creator>
		<pubDate>Thu, 19 Feb 2009 23:51:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rochen.com/?p=3#comment-1995</guid>
		<description>Hi Sam,

Yes, this is correct. The Joomla FTP Layer is not required for hosting with Rochen. I suspect there is something amiss with your configuration. Please drop a post into our Customer Forums: http://forums.rochen.com with further details or open up a support ticket referencing this comment.

Kyle, I have just seen your comment now while responding to Sam&#039;s one above. You can read more about CHMOD here: http://en.wikipedia.org/wiki/Chmod - a CHMOD of 777 means any user on the system can write to your files. In a shared environment it is very insecure but a lot of hosts require it. You don&#039;t need to use CHMOD of 777 anywhere at Rochen.

Thanks for your comments.

Chris</description>
		<content:encoded><![CDATA[<p>Hi Sam,</p>
<p>Yes, this is correct. The Joomla FTP Layer is not required for hosting with Rochen. I suspect there is something amiss with your configuration. Please drop a post into our Customer Forums: <a href="http://forums.rochen.com" rel="nofollow">http://forums.rochen.com</a> with further details or open up a support ticket referencing this comment.</p>
<p>Kyle, I have just seen your comment now while responding to Sam&#8217;s one above. You can read more about CHMOD here: <a href="http://en.wikipedia.org/wiki/Chmod" rel="nofollow">http://en.wikipedia.org/wiki/Chmod</a> &#8211; a CHMOD of 777 means any user on the system can write to your files. In a shared environment it is very insecure but a lot of hosts require it. You don&#8217;t need to use CHMOD of 777 anywhere at Rochen.</p>
<p>Thanks for your comments.</p>
<p>Chris</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam</title>
		<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/comment-page-1/#comment-1990</link>
		<dc:creator>Sam</dc:creator>
		<pubDate>Thu, 19 Feb 2009 21:07:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rochen.com/?p=3#comment-1990</guid>
		<description>Hi Chris,
Thanks of the advice re: security.  Question...
You wrote..&quot;..If you are hosting in a secured and tuned environment, like we have here at Rochen, then you don’t actually need the FTP layer to be enabled as extensions will install out of the box without ....You should disable the Joomla FTP Layer and ensure it has not stored your login details.&quot;

I couldn&#039;t install a Template without enabling the FTP layer.  Based on what you said, any idea why I wasn&#039;t able to install the Template if it Rochen doesn&#039;t require it?
Thanks,
Sam</description>
		<content:encoded><![CDATA[<p>Hi Chris,<br />
Thanks of the advice re: security.  Question&#8230;<br />
You wrote..&#8221;..If you are hosting in a secured and tuned environment, like we have here at Rochen, then you don’t actually need the FTP layer to be enabled as extensions will install out of the box without &#8230;.You should disable the Joomla FTP Layer and ensure it has not stored your login details.&#8221;</p>
<p>I couldn&#8217;t install a Template without enabling the FTP layer.  Based on what you said, any idea why I wasn&#8217;t able to install the Template if it Rochen doesn&#8217;t require it?<br />
Thanks,<br />
Sam</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Live Your Way</title>
		<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/comment-page-1/#comment-1339</link>
		<dc:creator>Live Your Way</dc:creator>
		<pubDate>Fri, 16 Jan 2009 22:06:58 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rochen.com/?p=3#comment-1339</guid>
		<description>Thanks for these pointers.  I run my own blog and, while I am familiar with networking and a little php, these little codlets of destruction are good to know about.  Thank you for the heads-up.  Great article!</description>
		<content:encoded><![CDATA[<p>Thanks for these pointers.  I run my own blog and, while I am familiar with networking and a little php, these little codlets of destruction are good to know about.  Thank you for the heads-up.  Great article!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kyle</title>
		<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/comment-page-1/#comment-1326</link>
		<dc:creator>Kyle</dc:creator>
		<pubDate>Thu, 15 Jan 2009 14:34:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rochen.com/?p=3#comment-1326</guid>
		<description>Quote from above:
&quot;...and you don’t need to set insecure global permissions like CHMOD of 777. Not having PHP configured in this way opens you up to cross-account attacks from other users on the shared server since you will need to CHMOD to 777 any directories Joomla! need to be able to write to...&quot;

I am a newcomer when it comes to security.  I am extremely unfamiliar with some of the terms you talked about in your article above.  What does CHMOD mean and numbers like 777...?

Also, where can I find the FTP layer to find out whether or not it is disabled.  Thanks for the help!</description>
		<content:encoded><![CDATA[<p>Quote from above:<br />
&#8220;&#8230;and you don’t need to set insecure global permissions like CHMOD of 777. Not having PHP configured in this way opens you up to cross-account attacks from other users on the shared server since you will need to CHMOD to 777 any directories Joomla! need to be able to write to&#8230;&#8221;</p>
<p>I am a newcomer when it comes to security.  I am extremely unfamiliar with some of the terms you talked about in your article above.  What does CHMOD mean and numbers like 777&#8230;?</p>
<p>Also, where can I find the FTP layer to find out whether or not it is disabled.  Thanks for the help!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rochen Blog &#187; Blog Archive &#187; Joomla! Events Rochen are Attending and Sponsoring. Joomla Hosting and Security.</title>
		<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/comment-page-1/#comment-1236</link>
		<dc:creator>Rochen Blog &#187; Blog Archive &#187; Joomla! Events Rochen are Attending and Sponsoring. Joomla Hosting and Security.</dc:creator>
		<pubDate>Mon, 05 Jan 2009 23:10:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rochen.com/?p=3#comment-1236</guid>
		<description>[...] UK JoomlaDay - Sat 14th March - Sun 15th March 2009 Chris as well as Martin will be attending this event. This is only the second UK JoomlaDay, so I&#8217;d expect it to be a sold out event. Chris will also be speaking on Joomla security from a web hosting prospective. In the mean time you may wish to review his previous blog post on Joomla Security. [...]</description>
		<content:encoded><![CDATA[<p>[...] UK JoomlaDay &#8211; Sat 14th March &#8211; Sun 15th March 2009 Chris as well as Martin will be attending this event. This is only the second UK JoomlaDay, so I&#8217;d expect it to be a sold out event. Chris will also be speaking on Joomla security from a web hosting prospective. In the mean time you may wish to review his previous blog post on Joomla Security. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arnaldo Gallo</title>
		<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/comment-page-1/#comment-981</link>
		<dc:creator>Arnaldo Gallo</dc:creator>
		<pubDate>Thu, 18 Dec 2008 01:20:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rochen.com/?p=3#comment-981</guid>
		<description>Instructive for newcomers to open source like me, and written in a rather honest way. Guidance on the requirements for a secure installation of Joomla and other issues, useful when selecting a hosting provider. I may be wrong, but I believe potential subscribers like me increasingly rate a secure hosting environment as their #1 requirement. Anyway, I am not a potential subscriber anymore. I &#039;ve just subscribed to your Starter Plan.</description>
		<content:encoded><![CDATA[<p>Instructive for newcomers to open source like me, and written in a rather honest way. Guidance on the requirements for a secure installation of Joomla and other issues, useful when selecting a hosting provider. I may be wrong, but I believe potential subscribers like me increasingly rate a secure hosting environment as their #1 requirement. Anyway, I am not a potential subscriber anymore. I &#8216;ve just subscribed to your Starter Plan.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/comment-page-1/#comment-32</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Tue, 07 Oct 2008 10:17:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rochen.com/?p=3#comment-32</guid>
		<description>Interesting post. As a beginner to open source web development it seems that security is the big question people ask. As someone looking to take a global business down the open source route, i&#039;d be interested to know if a hosting provider / third party will look after these security issues for me? Do the custom template providers for instance offer security management as a service (and therefore take accountability for website attacks)?</description>
		<content:encoded><![CDATA[<p>Interesting post. As a beginner to open source web development it seems that security is the big question people ask. As someone looking to take a global business down the open source route, i&#8217;d be interested to know if a hosting provider / third party will look after these security issues for me? Do the custom template providers for instance offer security management as a service (and therefore take accountability for website attacks)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Adams</title>
		<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/comment-page-1/#comment-12</link>
		<dc:creator>Chris Adams</dc:creator>
		<pubDate>Thu, 02 Oct 2008 23:37:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rochen.com/?p=3#comment-12</guid>
		<description>The basic points noted above will apply to any script and not just Joomla. We started off with a Joomla blog as that&#039;s by far the most popular script we host, but we will certainly look into covering others in the future.

Thanks for your comment! :-)</description>
		<content:encoded><![CDATA[<p>The basic points noted above will apply to any script and not just Joomla. We started off with a Joomla blog as that&#8217;s by far the most popular script we host, but we will certainly look into covering others in the future.</p>
<p>Thanks for your comment! :-)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

