Sections
Services
Our Blogs
« May 2008 »
Su Mo Tu We Th Fr Sa
1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
2008-05-09 00:00
16:51-16:51 A Sneak Peek at GloWorm
2008-05-13 00:00
15:02-15:02 vmstat and tail Make a Great Sandwich
2008-05-14 00:00
15:16-15:16 New Certificate on weblion.psu.edu
Recent entries:
New Certificate on weblion.psu.edu
vmstat and tail Make a Great Sandwich
A Sneak Peek at GloWorm
Last Registration Day! -- Plone Symposium East
Social Networking and Plone Symposium East
More...
Categories:
Plone (25)
Podcasts (1)
Presentations (2)
Screencasts (1)
Usability (2)
WebLion (19)
Zope (1)
 
Document Actions

WebLion/Plone Security: We're Solid

In cooperation with the ITS Security Operations and Services and WebLion partner College of Information Sciences and Technology, a comprehensive scan of security vulnerabilities shows that when properly installed, WebLion/Plone/Zope is a secure Web platform.

Security Operations and Services (SOS) is using AppScan, a sophisticated scanning and reporting application, to check Web-based applications in the psu.edu domain for security vulnerabilities. Typical vulnerabilities that are tested include SQL injection, cross-site scripting, cookie hijacking and other nefarious attack stratagies.

The results demonstrate that a properly installed instance of WebLion does not expose any known security vulnerabilities. The qualification that the site be properly installed is crucial. Without Penn State's authorization infrastructure in place (a crucial piece of WebLion), and without careful configuration of the server and associated applications like apache, you will in fact undermine the security of a WebLion site deployment and expose your network to great risk.

The WebLion team will continue to work with SOS to scan on a regular basis the WebLion-based Web sites, new functional enhancements, Plone updates and third party add-on applications for Plone. Our goal is to maintain the high level of security that Plone and WebLion developers have built into their products.

We encourage everyone who manages dynamic Web sites at Penn State to  request a security scan.

By Christian Vinten-Johansen on Wednesday, August 22, 2007
In PloneWebLion

WebLion Core Developer Blogs

Mike Halm
Darryl Noye
Rob Porter
Erik Rose
Eric Steele
Christian Vinten-Johansen
Catherine Williams

WebLion Partner Blogs

Jamie Oberdick
Brian Panulla
Rose Pruyne

WebLion Technical Writer Blogs

Dave Renn