[image: Joomla Feed logo]
(everything)
H1 Tags in Joomla Templates PDF Print E-mail
about joomla
Written by Alledia.com   
Monday, 27 October 2008
Are h1 tags any use? At last as far as SEO experts go, there's a lot of disagreement: Russ Jones: In my opinion, the second most important HTML tag available. Todd Malicoat: I can't imagine h1 tags having very much weight anymore - they're good practice for coding valid CSS, and seperating form from function. Good to use, but not a whole lot of value on their own. Jill Whalen: Keywords H tags in and of themselves don't seem to really matter as my tests have shown that positions don't seem to change whether the headline is wrapped in an H tag or not. http://www.seomoz.org/article/search-ranking-factors (http://www.seomoz.org/article/search-ranking-factors)
 
It's working. Thanks for your help. PDF Print E-mail
general news
Written by Brad Baker   
Wednesday, 22 October 2008

So.. I was checking the subscription stats for http://feeds.joomla.org/JoomlaSecurityNews as I usually do and noticed that finally things are on the improve. We're now starting to see 100's of people each day subscribing either via email or RSS. At this time we have 5145 people subscribed. I'll start to get even more excited when that figure gets into the 10's of thousands.

Obviously this is due to all the help the community is doing to share this link and encourage others to subscribe. We've also added this option directly to the Joomla download page as was suggested by a community member (well, something similar).

Thanks again everyone, and keep up the great support. Joomla wouldn't be as popular as it is without all of your help. 

 

PS Don't forget to subscribe other areas of the project, see: www.joomla.org/rss.html

 
Joomla 1.0 has nine months left PDF Print E-mail
commercial templates
Written by Joomlashack News   
Wednesday, 22 October 2008
As announced on the official Joomla Project Developers Blog a few weeks ago, Joomla 1.0 is headed into the sunset (http://community.joomla.org/team-blogs/developer-team/509-an-old-friend-comes-of-age.html) next July. Longtime Joomla volunteer Wilco Jansen (http://community.joomla.org/team-blogs/developer-team/509-an-old-friend-comes-of-age.html) writes: But now it's time to say our farewells to our old friend Joomla 1.0. As of July 22, 2009, the Joomla 1.0.x...
 
LETTERman 2.0 - A first look PDF Print E-mail
joomla advocates
Written by Blog - Joomlatools   
Wednesday, 22 October 2008
 
How to Write a Decent Blog Post PDF Print E-mail
about joomla
Written by Alledia.com   
Wednesday, 22 October 2008
Forget all that advice floating about good grammar, declarative sentences, keywords in the title and all the other advice you've been giving about blogging. That's just the icing on the cake. I reckon there's only one way to write a decent blog post .... go for a walk.
 
CMS Expo just six weeks away! PDF Print E-mail
commercial templates
Written by Joomlashack News   
Tuesday, 21 October 2008
UPDATED 10/23: Special deal for Joomlashack friends! $50 off the registration price through November 1st! (http://www.cmsexpo.net/joomlashack?utm_source=post102308 utm_medium=blog2 utm_campaign=jshack) CMS Winter Expo (http://www.cmsexpo.net/?utm_source=post102308 utm_medium=blog2 utm_campaign=jshack)! You're invited to the 2008 Winter CMS Expo (http://www.cmsexpo.net/?utm_source=post102308 utm_medium=blog2 utm_campaign=jshack), to be held at Denver's historic Brown Palace Hotel on December 4th and 5th. Joomla!...
 
CMS Expo just five weeks away! PDF Print E-mail
commercial templates
Written by Joomlashack News   
Tuesday, 21 October 2008
UPDATED 10/23: Special deal for Joomlashack friends! $50 off the registration price through November 1st! (http://www.cmsexpo.net/joomlashack?utm_source=post102308 utm_medium=blog2 utm_campaign=jshack) CMS Winter Expo (http://www.cmsexpo.net/?utm_source=post102308 utm_medium=blog2 utm_campaign=jshack)! You're invited to the 2008 Winter CMS Expo (http://www.cmsexpo.net/?utm_source=post102308 utm_medium=blog2 utm_campaign=jshack), to be held at Denver's historic Brown Palace Hotel on December 4th and 5th. Joomla!...
 
An Irresponsible Post by a Third Party Developer PDF Print E-mail
general news
Written by Anthony Ferrara   
Monday, 20 October 2008

Earlier today, a rather prominent third party company (who have traditionally been involved with and supported Joomla) openly revealed details about a potential Joomla security vulnerability by posting it on their site.  I will not do the company justice by posting who they are or by publishing a link to their site.  It's incredibly disappointing, and disturbing that these developers (two of which had official positions) did not try follow the established procedure (or even a moral approach), but resorted to posting the vulnerability publicly and with an incorrect fix.

About the vulnerability

About two weeks ago, the aforementioned developers submitted a report to the Joomla! Security Strike Team detailing the potential vulnerability.  In accordance with our security response protocol, we engaged in discussion with the third-party developer, and determined that the issue was not of a critical nature, and did not warrant an accelerated release.  We were able to confirm the issue and determined that it would be fixed in 1.5.8 when it finished its normal cycle.  After consulting with the respective Joomla teams, we determined that since the "issue" is completely internal (a potential attacker must be an author or higher) it is not of a "critical" nature.

The post also mentions that they submitted the bug to the Joomla 1.5 bug tracker and that it was removed.  It is our policy that security issues are taken out of public view when they are published in the public tracker or on a public forum.  This is a responsible stance which is also followed by many other projects.  The company did in fact post to the tracker, and it was removed per our normal operating policy.  Disappointingly, the company had already publicized the vulnerability to their own mailing list prior to posting the issue on the tracker.  This was in direct contradiction of our belief in the need for discretion and professionalism when dealing with security issues, which cannot be overstressed.

About the "fix" they provide

First of all, applying third-party patches is never recommended.  It is always advised to either wait for either an official emergency patch or an official release that addresses the issue. 

In this case, the third-party developer removes a key feature that allows a site to protect itself from various malicious attacks.  This suggests a complete lack of understanding of why the feature was added in the first place.  Applying an unofficial patch could expose your site to unknown dangers.  If your site is subsequently hacked/defaced as a result of any third-party patch, we cannot help you. It's also important to keep in mind that these types of unauthorized patches circumvent the ability for the Joomla Project to properly support Joomla.

About their viewpoints

Despite their claims to the contrary, security is always optional. The simple existence of firewalls, file permissions, and configuration settings clearly show that the needs of users, administrators, and developers differ. Joomla is no different in this regard. Therefore, we also have different user groups and access levels that empower you to determine which security protocols to implement and when to implement them.

This feature is also well documented on the Documentation Site and via help screens.  It also has some very positive benefits, particularly in environments where copy-and-paste from popular rich-text editors is a problem for site administrators.

We have shown that features can, and will, be added to incremental releases.  We try to limit these features only to small changes unless the need is really warranted.  This one specific feature was added primarily to harden the ability to filter incoming content and judged to be of significant community value.  While we acknowledge that some take a very legalistic or purist stance on features, we will always judge similar issues on their merits, usually with common sense prevailing.

An irresponsible thing to do

Publicizing security vulnerabilities is nothing short of irresponsible. It is completely misguided to presume that publicizing any vulnerability forces the project to act. In this instance, the Joomla Project was aware of the issue and had determined the appropriate response with the best interest of the community in mind. Even a philosophical difference does not justify putting potentially millions of Web sites at risk. We have ZERO TOLERANCE for this kind of behavior.  The members in question have been removed from their respective Joomla positions.  It's saddening that it had to come to that, but we must take a firm stand against such irresponsible acts.

Generally speaking, people in the community are highly supportive of the Project. Unfortunately, this company isn't one of them (and on multiple occasions this has shown to be true). We'll probably never know what motivates people to act in such a manner.

In conclusion

While the reported vulnerability does exist, we do not change our initial assessment that the impact of the issue is minor enough to be included in the normal Joomla 1.5.8 release cycle (which is not far off anyway). We strongly recommend you DO NOT install their recommended fix and DO NOT support their actions in any way. Actions like this are damaging to the community and unless the community refuses to acknowledge this activity, these people will continue cause disturbances.

We always encourage contributions, but through the proper channels and with proper communication. Publicizing a security vulnerability does not do anybody any good, hurts the users they purport to represent, and should never be tolerated.

 
High level security vulnerability in Joomla 1.5.7 PDF Print E-mail
joomla advocates
Written by Blog - Joomlatools   
Monday, 20 October 2008
 
Are Your Joomla Confirmation Emails Getting Delivered? PDF Print E-mail
joomla advocates
Written by barrie@compassdesigns.net   
Sunday, 19 October 2008

I have mentioned before that its sometimes a challenge dealing with Joomla registrations issues. I have had particular problems with Joomla Confirmation emails to hotmail and aol, specifically, the emails get caught in spam filters and the users never get the confirmation email.


So I was especially interested to get a Jakob Nielsen's Alertbox about Transactional Email and Confirmation Messages, e.g. confirmation emails Joomla sends out.


Let's take a look at what he says and c [...]

 
Leadsure partners up with Joomlatools for new Bootcamps PDF Print E-mail
joomla advocates
Written by Blog - Joomlatools   
Thursday, 16 October 2008
 
Hosting Companies with Joomla Users: Listen up! PDF Print E-mail
general news
Written by Brad Baker   
Thursday, 16 October 2008

Not that long ago, I posted on this subject with my blog: Hosting providers - Isn't it time? It was nice to see in the comments that some providers actually took on board the free advice and took steps to better secure their servers.

However, by and large it seems still, far too many hosting providers just do not care about security. This is not the place to name and shame them, but I'm talking about huge hosting providers still running outdated installs of php4 for example. 

Further, one of the most common responses hosting companies give to the users when their site is hacked, is "It's Joomla's fault". How illogical it this for example, when the user is running Joomla 1.5.0 (an out of date version that was patched long ago)? If you are a host and one of your clients sites is hacked, think before you lay blame. Why do so many of you automatically blame Joomla and not the client who never kept their site updated?

If you want to make a difference, educate yourself with an hour or so of you time and find out how simple it is to keep up to date. Don't you want smarter users, who run more secure websites and thus reduce your support time cleaning up phishing scams, spam mailers and hacked websites?

Maybe publish our security feed somewhere on your site, do you know the link?: http://feeds.joomla.org/JoomlaSecurityNews Subscription via email is also available from that page.

As I recently posted in the Security Forum "Security is very important, but seriously it's not that hard." This applies both to Joomla as well as the hosting setups that people run.

 

So join me as we sing together:

- "php4 is no more, we don't run it at all!"

- "suphp is for me, especially when I want security!"

- "backups are my friend, we take them even on the weekend!"

- "we keep our software up to date, vulnerabilities are what we hate!"

 

Finally. You don't have to listen to me, afterall, what would I know, you may say, however, next time a user posts about their sites being compromised due to a poor hosting configuration you might lose a customer when someone points out that the blame may in fact lie with you, their host and not with Joomla at all.

 
Alledia's Bolt is the World's Fastest Joomla Template PDF Print E-mail
about joomla
Written by Alledia.com   
Thursday, 16 October 2008
(http://demo.alledia.com/bolt/) This Sunday will be the 1st birthday of the Joomla SEO Club! We're celebrating by releasing our first extension, an SEO-optimized (are you surprised?) template called Bolt. Bolt is named in honor of Usain Bolt, the world's fastest man, because this template loads so much faster than its rivals. We're not launching yet another template club, but staying based in Joomla SEO, aiming to offer you some optimized extensions. (http://demo.alledia.com/bolt/) The philisophy behind Bolt is to remove anything that stops the template from loading as quickly as possible. There are no heavy scripts, no conflicts with other extensions and we've even disabled Joomla's heavy Javascript file. Speed: So stripped down that it can make as few as 4 HTTP requests. Lean Code: Uses only 8 images and 15kb of files. Flexibility: 7 different background colors and 15 different module options. Menus: It comes with both a dropdown menu (http://demo.alledia.com/bolt/) and a split menu. (http://demo.alledia.com/bolt/split/)
 
Hungarian Joomladay 2008 : Impressions PDF Print E-mail
joomla advocates
Written by Blog - Joomlatools   
Thursday, 16 October 2008
 
Joomla Code Commits vs Drupal and Wordpress PDF Print E-mail
about joomla
Written by Alledia.com   
Wednesday, 15 October 2008
Someone mentioned to me this week that they were worried about Joomla because not much work was being done on the project's code. To reassure them I headed over to Ohloh.net (http://Ohloh.net) which keeps useful data on the amount of work done on open source projects. What I found was that work on Joomla proceeds very differently from both Drupal and Wordpress: Where as those projects are built incrementally with small changes, Joomla has great bursts of energy followed by relatively quiet periods. We're just on of those plateaus now as the project gets ready for Joomla 1.6. Joomla has had over four times more code contributions than it's rivals, in a much shorter period of time. Joomla page on Ohloh (http://www.ohloh.net/projects/joomla) Drupal page on Ohloh (http://www.ohloh.net/projects/drupal) Wordpress page on Ohloh (http://www.ohloh.net/projects/wordpress)
 
MetaMorph v2 - October 08 Bonus Joomla Templates PDF Print E-mail
commercial templates
Written by Andy Miller   
Wednesday, 15 October 2008
The all new MetaMorph v2 template features a clean and lightweight design based on the original MetaMorph template. Sites needing that extra graphical touch, but with a simpler approach, can take advantage of MetaMorph v2's beautiful design, as well as it's adaptability and built-in power. MetaMorph v2 offers the same flexibility and powerful features found in the original MetaMorph including the RokContentRotator content presentation module, Animated RokMooMenu menu system, and 28 module positions perfect for providing maximum control over your site's content presentation.
 
The Joomla Event Season - part 2 PDF Print E-mail
joomla advocates
Written by Blog - Joomlatools   
Tuesday, 14 October 2008
 
Official Support Will End for Joomla 1.0 PDF Print E-mail
about joomla
Written by Alledia.com   
Tuesday, 14 October 2008
Official support for Joomla 1.0 will end in 281 days. That announcement was made by Wilco Jansen on joomla.org (http://community.joomla.org/contributor-blogs/64-developer-team-blog/509-an-old-friend-comes-of-age.html). July 22, 2009 will be the two year anniversary of the first Joomla 1.5 release, and it seems an appropriate day to move forward. I'm sure this is a popular decision within the Joomla team and also with third-party devs who can concentrate on developing for just one version. Mathias from JoomlaTools was one person pushing for this to happen (http://blog.joomlatools.org/2008/10/more-about-joomla-10s-end-of-life.html). It's probably less popular with the thousands of people who still use Joomla 1.0. However, there's no reason to get worried. Personally I've made so many hacks and modifications to Alledia.com that we'll probably never upgrade. We build all our new websites with 1.5, but see no reason to upgrade existing installations. You can expect several Joomla developers to fill the gap of providing 1.0 support while the core team keeps pushing ahead.
 
The Joomla Event Season has begun! PDF Print E-mail
joomla advocates
Written by Blog - Joomlatools   
Tuesday, 14 October 2008
 
9 Months Left for Joomla 1.0 PDF Print E-mail
joomla advocates
Written by barrie@compassdesigns.net   
Monday, 13 October 2008

Some time ago, I posted my answer to the eternal question, Should I use Joomla 1.0 or 1.5? Now there is another factor to consider, Wilco Jansen recently posted on the Developer Team Blog the actual date when Joomla 1.0 would stop being supported with updates, July 22nd 2009.

"As of July 22, 2009, the Joomla 1.0.x series will no longer be supported."

Although that seems a long way into the future, its actually only 9 months.

You can read more about the post at [...]

 
<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>

Results 41 - 60 of 7970
Home arrow (everything)
actions
read comments
the joomlasphere by email

subscribe to our email newsletter and get updates on all the latest news from the joomlasphere!