3aIT Blog

Prompted by the news that the latest version of Joomla will not run on the version of PHP that our hosting server is running, we have been busy testing a way of making the latest stable version of PHP available to our hosting clients, while not causing compatibility issues with older websites by performing a wholesale PHP version upgrade across the whole server.

Research has shown that a large number of servers are still vulnerable to the widely publicised "Heartbleed" bug.

The problem is probably even worse than that research indicates, as they only measured the largest websites in the world, which one would expect to be well maintained. There are probably many more smaller sites that aren't actively maintained that are still susceptible to this bug.

Joomla 1.5 is has now been out of support for some time. However, many sites are still running this version of the CMS. While it is tempting to just think "Well, the site is still working, so let's ignore this for now", there are now many known vulnerabilities in this version of Joomla. It is likely only a matter of time until a Joomla 1.5 site is compromised. Then the problem suddenly becomes urgent. We look at the process of upgrading.

Microsoft have recently warned that there is a critical bug in all versions of Internet Explorer. This bug allows a malicious website to be constructed that enables an attacker to take control of any machine that visits it - assuming that user is logged in as the machine admin. As this is often the default setup of a Windows machine, this places many users at risk.

Page 36 of 37