<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Phil Taylor - Joomla Expert &#38; PHP Developer &#187; Rants</title>
	<atom:link href="http://www.phil-taylor.com/tag/rants/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.phil-taylor.com</link>
	<description>The Joomla Expert!</description>
	<lastBuildDate>Sat, 12 Jan 2013 21:46:14 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.6-beta1-24067</generator>
		<item>
		<title>Joomla Sites Hacked &#8211; We help Repair them</title>
		<link>http://www.phil-taylor.com/2012/01/05/we-helped-fix-50-joomla-websites-that-were-hacked/</link>
		<comments>http://www.phil-taylor.com/2012/01/05/we-helped-fix-50-joomla-websites-that-were-hacked/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 00:00:57 +0000</pubDate>
		<dc:creator>Phil Taylor</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[Bug Fixes]]></category>
		<category><![CDATA[Fraud]]></category>
		<category><![CDATA[Joomla Components]]></category>
		<category><![CDATA[Joomla Core]]></category>
		<category><![CDATA[Mambo]]></category>
		<category><![CDATA[New Releases]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.phil-taylor.com/2006/07/18/we-helped-fix-50-joomla-websites-that-were-hacked/</guid>
		<description><![CDATA[Click here to get help with your hacked site → Many Many more Joomla based sites are being hacked daily at the moment &#8211; and ITS NOT JOOMLA&#8217;s fault! Firstly let me say the sites were NOT hacked through Joomla! They were all hacked through Joomla Custom Components! If you are running Joomla 1.0.10 then&#160; &#160;<a href="http://www.phil-taylor.com/2012/01/05/we-helped-fix-50-joomla-websites-that-were-hacked/">...Continue Reading</a>]]></description>
				<content:encoded><![CDATA[<p style="text-align: center;"><a class="btn btn-large btn-primary primary large" href="http://fix.myjoomla.com/">Click here to get help with your hacked site →</a></p>
<p>Many Many more Joomla based sites are being hacked daily at the moment &#8211; and ITS NOT JOOMLA&#8217;s fault!<br />
Firstly let me say the sites were NOT hacked through Joomla! They were all hacked through Joomla Custom Components!</p>
<p align="center"><strong>If you are running Joomla 1.0.10 then there are no known security holes in that version!</strong></p>
<div align="center">
<div align="left">HOWEVER here is a long list of custom components that have been used to hack Joomla sites, If you have any of these custom components you may get hacked!!:</div>
<p align="left">extCalender • OpenSEF • phpBB Forum (com_forum) • SimpleBoard Forum • VideoDB • Mambo-SMF Forum • LoudMouth • PollXT • HashCash • perForms • Google Page Rank Module  • BSQ SiteStats • MultiBanners • MiniBB • New Article Component • Advanced Poll • JomBok • ArtLinks • PCCookBook • Mambo/Joomla SiteMap (Custom Component) • Galleria • com_spray</p>
<p style="text-align: center;"><a class="btn btn-large btn-primary primary large" href="http://fix.myjoomla.com/">Click here to get help with your hacked site →</a></p>
<p>and <a href="http://forum.joomla.org/index.php?board=296.0">many other components</a>&#8230;</p>
<p align="left">I write this to inform you of thiese facts, and also to let you know, as our customer, that none of the components on www.phil-taylor.com have been hacked or used to hack Joomla websites! Yippee!</p>
<p align="left">You should really only install components from TRUSTED sources, from developers that you trust!</p>
<p align="left"><img src="http://images.scanalert.com/meter/www.phil-taylor.com/13.gif" alt="" align="right" />Again, ALL COMPONENTS ON PHIL-TAYLOR.com Have been HACKER SAFE certified! And have no known security issues (At this moment in time <img src='http://www.phil-taylor.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  ) As experts in Joomla development we take pride in checking our components with an industry standard (expensive!) scanning solution used by the big players worldwide!</p>
<p align="center"><strong><em>We have fixed over 50 hacked sites for new customers worldwide in the last 7 days!</em></strong></p>
<h1>Did your site get hacked? &#8211; we can help!</h1>
<p align="justify"><img src="http://www.phil-taylor.com/images/stories/dontpanic_large.jpg" alt="Dont Panic!" width="150" height="155" align="left" hspace="3" vspace="3" /><strong><br />
Fix My Site is a very unique service offered by Phil Taylor.<br />
</strong><strong> (This is a fee per incident based service, no contracts and no strings involved!) </strong></p>
<p>&nbsp;</p>
<p align="justify"><strong>Fix My Site puts a very experienced and knowledgeable Mambo and Joomla expert at your fingertips when things go wrong on your site. For a set fee, you can have Phil Taylor (Or one of our other experts) login and take a look at that problem that has causing problems on your site.</strong></p>
<p align="justify">See our site at <a href="http://www.phil-taylor.com/FixMySite">http://www.phil-taylor.com/FixMySite<br />
</a></p>
<p align="justify">ONLY TRUST THE EXPERTS! &#8211; Beware of some other help sites that simply repair your site without giving advice on how hackers gained access or how to prevent further attacks. We are not just Joomla experts, we have huge amounts of experience in this area and can draw on this experience to provide the very best solution for you.</p>
<p align="justify">You have been warned!</p>
</div>
<p>If you want to stop hackers and do information security as a career, consider <a href="http://www.regisdegrees.com/">information assurance training.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.phil-taylor.com/2012/01/05/we-helped-fix-50-joomla-websites-that-were-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Moving House</title>
		<link>http://www.phil-taylor.com/2009/05/19/moving-house/</link>
		<comments>http://www.phil-taylor.com/2009/05/19/moving-house/#comments</comments>
		<pubDate>Tue, 19 May 2009 20:52:22 +0000</pubDate>
		<dc:creator>Phil Taylor</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Rants]]></category>

		<guid isPermaLink="false">http://blog.phil-taylor.com/?p=753</guid>
		<description><![CDATA[PLEASE BE PATIENT if you have sent me and email &#8211; and refrain from sending me abusive messages&#8230;.. you know who you are&#8230; I am moving house at the moment, and only have mobile broadband access and my main PC is in a box! I dont have all the tools I need to do my&#160; &#160;<a href="http://www.phil-taylor.com/2009/05/19/moving-house/">...Continue Reading</a>]]></description>
				<content:encoded><![CDATA[<p>PLEASE BE PATIENT if you have sent me and email &#8211; and refrain from sending me abusive messages&#8230;.. you know who you are&#8230;</p>
<p>I am moving house at the moment, and only have mobile broadband access and my main PC is in a box! I dont have all the tools I need to do my job and so therefore I cant <img src='http://www.phil-taylor.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>I&#8217;ll be up to full speed by next Monday again.</p>
<p>Thanks to those who are being patient <img src='http://www.phil-taylor.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.phil-taylor.com/2009/05/19/moving-house/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The scale of the email problem</title>
		<link>http://www.phil-taylor.com/2009/01/26/the-scale-of-the-email-problem/</link>
		<comments>http://www.phil-taylor.com/2009/01/26/the-scale-of-the-email-problem/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 19:44:59 +0000</pubDate>
		<dc:creator>Phil Taylor</dc:creator>
				<category><![CDATA[Rants]]></category>

		<guid isPermaLink="false">http://blog.phil-taylor.com/?p=633</guid>
		<description><![CDATA[I blog quite often on the email over load I am under But this time here are some interesting statistics to put it in perspective. In February 2007 I set up a gmail account and I forward a single copy of all incoming email to that account, gmail filters the spam so whats left in&#160; &#160;<a href="http://www.phil-taylor.com/2009/01/26/the-scale-of-the-email-problem/">...Continue Reading</a>]]></description>
				<content:encoded><![CDATA[<p>I blog quite often on the email over load I am under <img src='http://www.phil-taylor.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>But this time here are some interesting statistics to put it in perspective.</p>
<p>In February 2007 I set up a gmail account and I forward a single copy of all incoming email to that account, gmail filters the spam so whats left in my inbox is all good mail.</p>
<p>So since 17 Feb 2007 I have received 159976 emails (recorded by gmail)  ! (Thats exact as of now.  the rest of these figures are slightly less as its not yet feb 2009)</p>
<p>Thats an average of:</p>
<ul>
<li>79988 emails per year</li>
<li>6665 emails per month</li>
<li>222 emails per day</li>
</ul>
<p>And I aim to reply to each and every one of these personally!!! Gulp</p>
<p>Lets say I reply to 222 emails a day and each takes me 2 mins to research and type a reply to &#8211; thats 444mins = 7.4 hours&#8230;&#8230;</p>
<p>so after replying ot my emails everyday I have 0.1 hours to do other things &#8211; like go to the bathroom, eat and drink coffee &#8211; no wonder I struggle!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phil-taylor.com/2009/01/26/the-scale-of-the-email-problem/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>I&#039;m Declaring Email Bankruptcy!</title>
		<link>http://www.phil-taylor.com/2008/12/15/im-declaring-email-bankruptcy/</link>
		<comments>http://www.phil-taylor.com/2008/12/15/im-declaring-email-bankruptcy/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 22:22:11 +0000</pubDate>
		<dc:creator>Phil Taylor</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Rants]]></category>

		<guid isPermaLink="false">http://blog.phil-taylor.com/?p=577</guid>
		<description><![CDATA[I have been toying with this idea to make me more productive for some time now, and then today I found out that I was not alone and that the term &#8220;Email Bankruptcy&#8221; is in fact something that has been done by many others over the years&#8230; So as of today &#8211; I have Zero&#160; &#160;<a href="http://www.phil-taylor.com/2008/12/15/im-declaring-email-bankruptcy/">...Continue Reading</a>]]></description>
				<content:encoded><![CDATA[<p><img title="inbox" src="http://www.phil-taylor.com/wp-content/uploads/2008/12/inbox1.jpg" alt="inbox" width="137" height="133" align="right" />I have been toying with this idea to make me more productive for some time now, and then today I found out that I was not alone and that the term &#8220;<a href="http://valleywag.com/tech/trends/declaring-e+mail-bankruptcy-254608.php">Email Bankruptcy</a>&#8221; is in fact something that has been done by many others over the years&#8230;</p>
<p>So as of today &#8211; I have <strong>Zero Emails</strong> in my Inbox. (I just deleted over 500!)</p>
<p><strong>Question:</strong> Whoah there you might say&#8230; Why have you done that?<br />
<strong>Answer: </strong>Well because the last 10 emails I replied to all replied back to me saying the problem was resolved or they don&#8217;t need assistance any more! &#8211; a waste of my time &#8211; some of these emails have built up over time as I have been out of the office, some of these emails can be answered by READING THE FAQ and some are just plain stupid.</p>
<p><strong>Question:</strong> Does this mean you are not answering emails?<br />
<strong>Answer: No it doesn&#8217;t &#8211; I will still answer any email sent me from now on, </strong>even if its a resend of an earlier email, by you resending it I know that its important and needs my attention rather than being one email in a big sea of emails&#8230;</p>
<p><strong>Question:</strong> I sent you an email last week, am I going to get a reply?<br />
<strong>Answer: </strong>Not unless you resend it !!!</p>
<p><strong>Question:</strong> Why are you doing this!!!!<br />
<strong>Answer: </strong>Simple &#8211; there are just not enough hours in a work week to reply to all the new emails and the historic ones built up over the last few weeks (months!) and why should I waste time researching, composing and replying to emails where my replies are no longer required&#8230;</p>
<p><strong>Question: </strong>Ok then, so where else can I find help<strong> </strong>to save me emailing you?<br />
<strong>Answer:</strong> to be honest I use a lot of quick replies to FAQ posts and Blog posts where 80% of all my email queries have already been answered, please try searching the blog, or visiting the products FAQ page (Especially Forms for Joomla, there are some articles in there I email people about all the time!!)</p>
<p><strong>Question: </strong>So how long will it take for you to reply to my next email?<br />
<strong>Answer: </strong>Don&#8217;t Know <img src='http://www.phil-taylor.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  but a hell of a lot sooner than before I declared email bankruptcy!</p>
<p>(Ok I lied, I am keeping about 10 emails from the last few hours in my inbox as they are current and require my input <img src='http://www.phil-taylor.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  )</p>
<p><strong>The Future: </strong>Well its easy to &#8220;keep up&#8221; when I&#8217;m in the office, also this frees up more time for development, its been far tooooooo long since my latest releases and we have some exciting new features to roll out, including some bug fixes <img src='http://www.phil-taylor.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>So Thanks for your patience <img src='http://www.phil-taylor.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  email me if you really need to <img src='http://www.phil-taylor.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.phil-taylor.com/2008/12/15/im-declaring-email-bankruptcy/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Back From Holiday &#8211; Playing Catchup!</title>
		<link>http://www.phil-taylor.com/2008/03/12/back-from-holiday-playing-catchup/</link>
		<comments>http://www.phil-taylor.com/2008/03/12/back-from-holiday-playing-catchup/#comments</comments>
		<pubDate>Wed, 12 Mar 2008 19:42:44 +0000</pubDate>
		<dc:creator>Phil Taylor</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Rants]]></category>

		<guid isPermaLink="false">http://blog.phil-taylor.com/2008/03/12/back-from-holiday-playing-catchup/</guid>
		<description><![CDATA[We are now back from our holiday and returning to work &#8211; over a thousand emails to filter through, plus more forum posts and other incoming communications&#8230; Please be patient Our trip was a good break away &#8211; however VENICE IS A DUMP, we were highly disappointed with Venice.  The place is nothing like the&#160; &#160;<a href="http://www.phil-taylor.com/2008/03/12/back-from-holiday-playing-catchup/">...Continue Reading</a>]]></description>
				<content:encoded><![CDATA[<p>We are now back from our holiday and returning to work &#8211; over a thousand emails to filter through, plus more forum posts and other incoming communications&#8230; Please be patient <img src='http://www.phil-taylor.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Our trip was a good break away &#8211; however VENICE IS A DUMP, we were highly disappointed with Venice.  The place is nothing like the TV or Books portray and is infact nothing more than a graffiti plastered, rubbish strewn, smelling island in the middle of a lagoon with a massive industrial plant on one side and water on the other.  I would never recommend you go to Venice, unless you are a real lover of history and art &#8211; and never take a baby or wheelchair, see those lovely little bridges? well each one is actually a stepladder up and down again! steps, steps and more steps!!!</p>
<p>The hotel was the only thing that stopped us returning after a few days! The hotel room was a mini-suite and was simply amazing! (As was the local internet cafe!)</p>
<p>So back to work now &#8211; all systems go &#8211; but we ask for your patience if you have contacted us over the last week &#8211; we will get to your emails &#8211; promise!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phil-taylor.com/2008/03/12/back-from-holiday-playing-catchup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joomla Still Doesn’t Get it on Migrating</title>
		<link>http://www.phil-taylor.com/2008/01/29/joomla-still-doesn%e2%80%99t-get-it-on-migrating/</link>
		<comments>http://www.phil-taylor.com/2008/01/29/joomla-still-doesn%e2%80%99t-get-it-on-migrating/#comments</comments>
		<pubDate>Tue, 29 Jan 2008 10:33:24 +0000</pubDate>
		<dc:creator>Phil Taylor</dc:creator>
				<category><![CDATA[Rants]]></category>

		<guid isPermaLink="false">http://blog.phil-taylor.com/2008/01/29/joomla-still-doesn%e2%80%99t-get-it-on-migrating/</guid>
		<description><![CDATA[I was out on the web today when I came across an article from someone who doesn&#8217;t normally blog ablout Joomla, but about Macs. I advise you to read the full article, but to pad out my own blog post here is a short except: However, I continue to believe that, the largest difference will&#160; &#160;<a href="http://www.phil-taylor.com/2008/01/29/joomla-still-doesn%e2%80%99t-get-it-on-migrating/">...Continue Reading</a>]]></description>
				<content:encoded><![CDATA[<p>I was out on the web today when I came across <a href="http://www.christopherprice.net/joomla-still-doesnt-get-it-on-migrating-216.html">an article</a> from someone who doesn&#8217;t normally blog ablout Joomla, but about Macs.</p>
<p>I advise you to read <a href="http://www.christopherprice.net/joomla-still-doesnt-get-it-on-migrating-216.html">the full article</a>, but to pad out my own blog post here is a short except:</p>
<pre>However, I continue to believe that, the largest difference will be that Joomla will fail
because of their migration, whereas Apple executed a perfect migration.

First, <em>“for</em><em> those interested in migrating”</em>… a product management failure right off the bat.
Joomla should be thinking that every site should upgrade, and they should be evangelizing

Joomla admins to start looking to making that transaction.
Second, saying that the migration process has issues completely ignores the fact that
migration should have been a paramount priority.</pre>
<p>An interesting opinion from a regular Joomla user!&#8230;.</p>
<p>Edit: I note that the <a href="http://www.joomla.org/component/option,com_jd-wp/Itemid,105/p,473/">Joomla Dev Blog now has a post on the migration</a> procedure as well &#8211; I really should have a coffee before blog posting <img src='http://www.phil-taylor.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.phil-taylor.com/2008/01/29/joomla-still-doesn%e2%80%99t-get-it-on-migrating/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joomla 1.0.13 contains a CSRF vulnerbility</title>
		<link>http://www.phil-taylor.com/2008/01/02/joomla-1013-contains-a-csrf-vulnerbility/</link>
		<comments>http://www.phil-taylor.com/2008/01/02/joomla-1013-contains-a-csrf-vulnerbility/#comments</comments>
		<pubDate>Wed, 02 Jan 2008 14:39:24 +0000</pubDate>
		<dc:creator>Phil Taylor</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.phil-taylor.com/2008/01/02/joomla-1013-contains-a-csrf-vulnerbility/</guid>
		<description><![CDATA[We write this blog post with sadness. On the 4th December 2007 a nice white hat hacker notified the Joomla Core Development team of a CSRF Vulnerability in Joomla 1.0.13 and Joomla 1.5 RC3.There have been many reports of these vulnerabilities around the web since then. The nature of the vulnerability means that your site&#160; &#160;<a href="http://www.phil-taylor.com/2008/01/02/joomla-1013-contains-a-csrf-vulnerbility/">...Continue Reading</a>]]></description>
				<content:encoded><![CDATA[<p>We write this blog post with sadness.  On the <strong>4th December 2007</strong> a nice white hat hacker notified the Joomla Core Development team of a <strong>CSRF Vulnerability in Joomla 1.0.13 and Joomla 1.5 RC3</strong>.There have been many reports of these vulnerabilities around the web since then.</p>
<p><strong>The nature of the vulnerability means that your site cannot be hacked while you sleep</strong> (like many of the other types of 3rd party component issues), but requires you (the sites Super Admin) to be logged into Joomla Admin while at the same time surfing sites (maybe even your own) that contain links to [THINGS] that send [NAUGHTY] requests back to your Joomla Admin Console without you knowing. This can lead to complete disaster and even complete server compromise.</p>
<p>The Joomla Developers took only 4 days to fix this in Joomla 1.5 SVN and then shortly after released Joomla 1.5 RC4 stating they had fixed this category A5 Security [High] Vulnerability.</p>
<p><strong><strike>To date, no changes and no attempts by the core development team have been made to the Joomla 1.0.13+ SVN tree to fix this vulnerability in Joomla 1.0.13</strike> Update: Changes are now in SVN for the next version of Joomla 1.0.x &#8211; about time! </strong></p>
<p>In an effort to assist them we spent a few hours and backported code from Joomla 1.5 RC4 to Joomla 1.0.13 and made all the changes required to fix Joomla 1.0.13 and make it secure from this type of vulnerability.</p>
<p>Details of this can be found in the following forum thread:</p>
<p><a href="http://forum.joomla.org/index.php/topic,248109.msg1136076.html#msg1136076">http://forum.joomla.org/index.php/topic,248109.msg1136076.html#msg1136076 </a></p>
<p>I personally emailed all three lead developers with the same information as I published there, including providing the diff/patch files to Joomla 1.0.13. I have been assured that once Joomla 1.5 stable is released time will be spent on fixing this issue in Joomla 1.0.13 <em><strong>(I object to this &#8211; why take 4 days to fix unreleased software and over 4 weeks to fix software running on millions of sites already?!?) </strong></em></p>
<p>Here is my professional advice to help you stay safe from the known and publish vulnerability until the next version of Joomla 1.0.x is released.</p>
<p><strong><span style="color: red">The number one bit of advice I can give all site admins at the moment is to &#8211; LOGOUT OF YOUR JOOMLA ADMIN as soon as you finish using it, and do not surf around the internet in other tabs/browser windows while administrating your Joomla site, and if you allow users to modify your site&#8217;s frontend, be careful not to surf your frontend as well while logged in.</span></strong></p>
<p><strong>Do not install any 3rd party components/mambots/modules/AND TEMPLATES!!! from untrusted sources, if these components choose they can use this vulnerability to do[BAD] things&#8230;</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.phil-taylor.com/2008/01/02/joomla-1013-contains-a-csrf-vulnerbility/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joomla 1.0.13 New Password Hashing Method Means NO Compatibilty</title>
		<link>http://www.phil-taylor.com/2007/07/23/joomla-1013-new-password-hashing-method-means-no-compatibilty/</link>
		<comments>http://www.phil-taylor.com/2007/07/23/joomla-1013-new-password-hashing-method-means-no-compatibilty/#comments</comments>
		<pubDate>Mon, 23 Jul 2007 20:00:32 +0000</pubDate>
		<dc:creator>Phil Taylor</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.phil-taylor.com/2007/07/23/joomla-1013-new-password-hashing-method-means-no-compatibilty/</guid>
		<description><![CDATA[Ever since the conception of Mambo/Joomla the passwords for admins and users have been converted into a md5 hash string and stored to the database. In Joomla 1.0.13 (About time too!) this has changed.  The password is now &#8220;salted&#8221; and then md5 hashed with the salt, the salt and the password are both stored in&#160; &#160;<a href="http://www.phil-taylor.com/2007/07/23/joomla-1013-new-password-hashing-method-means-no-compatibilty/">...Continue Reading</a>]]></description>
				<content:encoded><![CDATA[<p>Ever since the conception of Mambo/Joomla the passwords for admins and users have been converted into a md5 hash string and stored to the database.</p>
<p>In Joomla 1.0.13 (About time too!) this has changed.  The password is now &#8220;salted&#8221; and then md5 hashed with the salt, the salt and the password are both stored in the database.</p>
<p>This means that Joomla 1.0.13 breaks backwards compatibility with itself (you can&#8217;t downgrade to anything before joomla 1.0.13), and with some extensions like Community Builder and Forum bridges!!</p>
<p>Basically any 3rd Party Component that reads/writes/validates the password of an admin or user will now FAIL in Joomla 1.0.13 unless it is updated to know about the new changes.</p>
<p>The salting of passwords is a good security step &#8211; we praise the core team for doing it &#8211; HOWEVER no announcement has been made about this, no blog post has been made and users are now in the dark &#8211; remember, this means you can NEVER DOWNGRADE your site if you have problems so make sure you MAKE A BACKUP before upgrading to Joomla 1.0.13 &#8211; you have now been warned!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phil-taylor.com/2007/07/23/joomla-1013-new-password-hashing-method-means-no-compatibilty/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Extensions Site Voting Rigged By The Faceless</title>
		<link>http://www.phil-taylor.com/2007/05/18/extensions-site-voting-rigged-by-the-faceless/</link>
		<comments>http://www.phil-taylor.com/2007/05/18/extensions-site-voting-rigged-by-the-faceless/#comments</comments>
		<pubDate>Fri, 18 May 2007 12:08:45 +0000</pubDate>
		<dc:creator>Phil Taylor</dc:creator>
				<category><![CDATA[Joomla Extensions]]></category>
		<category><![CDATA[Rants]]></category>

		<guid isPermaLink="false">http://blog.phil-taylor.com/2007/05/18/extensions-site-voting-rigged-by-the-faceless/</guid>
		<description><![CDATA[Here is a new listing (Joomla Tags) on the Joomla Extensions Directory (JED) Site It has 13 anonymous votes &#8211; giving it 3stars out of 5 It has 5 (great) reviews all 5 star ratings. Should the JED allow anonymous voting?! I dont believe so &#8211; I (any visitor) could quite happily vote down ANY&#160; &#160;<a href="http://www.phil-taylor.com/2007/05/18/extensions-site-voting-rigged-by-the-faceless/">...Continue Reading</a>]]></description>
				<content:encoded><![CDATA[<p>Here is a <a href="http://extensions.joomla.org/component/option,com_mtree/task,viewlink/link_id,2270/Itemid,35/">new listing (Joomla Tags)</a> on the <a href="http://extensions.joomla.org">Joomla Extensions Directory</a> (JED) Site<a href="http://extensions.joomla.org/component/option,com_mtree/task,viewlink/link_id,2270/Itemid,35/" target="_blank"></a></p>
<p>It has 13 anonymous votes &#8211; giving it 3stars out of 5</p>
<p>It has 5 (great) reviews all 5 star ratings.</p>
<p>Should the JED allow anonymous voting?!  I dont believe so &#8211; I (any visitor) could quite happily vote down ANY extension on the JED without reason.</p>
<p>Maybe the votes should be linked to the reviews and not anonymous clicks?  At least with good and bad reviews you can understand the reason for the current number of stars.</p>
<p>Surely a component such as our Joomla Tags, which has received 5 positive, 5 star reviews from real people (with joomla accounts &#8211; easily identified and traced if needed) should not have a 3star rating swayed by faceless anonymous people, who may or may not even used the component !?!?!?!?</p>
<p>This is not a commercial rant &#8211; but it can happen on any free component listing too.</p>
<p>Why allow the faceless to sway the rating?</p>
<p><a href="http://forum.joomla.org/index.php/topic,171406.msg821253.html">DISCUSS in the Joomla Forum</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.phil-taylor.com/2007/05/18/extensions-site-voting-rigged-by-the-faceless/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Keep up to date with Joomla Related News</title>
		<link>http://www.phil-taylor.com/2007/02/08/keep-up-to-date-with-joomla-related-news/</link>
		<comments>http://www.phil-taylor.com/2007/02/08/keep-up-to-date-with-joomla-related-news/#comments</comments>
		<pubDate>Thu, 08 Feb 2007 20:30:57 +0000</pubDate>
		<dc:creator>Phil Taylor</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Free]]></category>
		<category><![CDATA[Fun]]></category>
		<category><![CDATA[Rants]]></category>

		<guid isPermaLink="false">http://blog.phil-taylor.com/2007/02/08/keep-up-to-date-with-joomla-related-news/</guid>
		<description><![CDATA[I was asked today how I manage to keep up with the huge amount of new news about Joomla from the official source and other peoples blogs about Joomla &#8211; simple &#8211; RSS Feeds and Google Alerts! Google Alerts: The google alerts system allows anyone to subscribe to alerts for any keyword, We have several&#160; &#160;<a href="http://www.phil-taylor.com/2007/02/08/keep-up-to-date-with-joomla-related-news/">...Continue Reading</a>]]></description>
				<content:encoded><![CDATA[<p>I was asked today how I manage to keep up with the huge amount of new news about Joomla from the official source and other peoples blogs about Joomla &#8211; simple &#8211; RSS Feeds and Google Alerts!</p>
<p><strong>Google Alerts:</strong></p>
<p>The <a href="http://www.google.com/alerts">google alerts system</a> allows anyone to subscribe to alerts for any keyword, We have several alerts set up with them, keywords for &#8220;Joomla&#8221;, all our product names and all our competitors names, along with some terms relevant to hacking and security in Joomla.  When Google spots a blog post, news item or new web page containing these terms Google emails an update direct to my mailbox. Useful for finding new blogs too!</p>
<p><strong>RSS</strong>:</p>
<p>I think most people know what RSS is by now, I&#8217;m not going to go too much into it, infact this blog post was more about Google than RSS &#8211; just know this, RSS is useful for looking for changes on a small number of websites, I have over 250 RSS feeds and I find filtering out the noise and finding keywords relavant to me and my company very difficult.  (We use the <a href="http://sage.mozdev.org/">sage</a> plugin for firefox since we left behind our windows days and became 100% <a href="http://www.ubuntu.com">linux</a> based. On windows we recommend <a href="http://www.newsgator.com/NGOLProduct.aspx?ProdID=FeedDemon">FeedDemon</a>)</p>
<p>No affiliate links in this post &#8211; just wanted to help you find relevant information about Joomla.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phil-taylor.com/2007/02/08/keep-up-to-date-with-joomla-related-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
