daily security run output and joomla3

Baptiste Daroussin bapt at FreeBSD.org
Sun Jan 28 18:35:23 UTC 2018


On Sun, Jan 28, 2018 at 07:31:00PM +0100, Baptiste Daroussin wrote:
> On Mon, Jan 29, 2018 at 03:27:22AM +0900, Yasuhiro KIMURA wrote:
> > From: Larry Rosenman <ler at lerctr.org>
> > Subject: Re: daily security run output and joomla3
> > Date: Sun, 28 Jan 2018 12:04:56 -0600
> > 
> > > But as the OP notes, the joomla3 instructions *REQUIRE*
> > > removal of the install directory for security reasons, so 
> > > I understand where he is coming from. 
> > 
> > Do you mean that all installed file must be removed? If so, what about
> > simply deinstalling joomla3 package after instructions are finished?
> > 
> 
> Does changing the owners of the directory to nobody helps? joomla (www users)
> might not be able to read it

Another way (still ugly) would be 2 packages: joomla and
joomla-installation-cruft and once setup is done the user should pkg delete
joomla-installation-cruft

Just thinking, can't find better ideas so far :)

Bapt
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.freebsd.org/pipermail/freebsd-ports/attachments/20180128/a93c8b3e/attachment.sig>


More information about the freebsd-ports mailing list