<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Sat, 18 May 2013 12:18:40 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[The Bakery: Mambo, Layout Switching, SimplePie and Caching Elements]]></title>
      <guid>http://www.phpdeveloper.org/news/8328</guid>
      <link>http://www.phpdeveloper.org/news/8328</link>
      <description><![CDATA[<p>
The Bakery has four new articles/tutorials posted today covering things like Mambo's choice to go with CakePHP, a layout switcher, SimplePie and caching elements.
</p>
<ul>
<li><a href="http://bakery.cakephp.org/articles/view/mambo-licious">Mambo-licious</a> - Join us in welcoming Mambo to the CakePHP community.
<li><a href="http://bakery.cakephp.org/articles/view/automatic-layout-swticher">Automatic Layout Switcher</a> - This component allows you to have two layouts for one site and switches between them automatically based on the domain.
<li><a href="http://bakery.cakephp.org/articles/view/simplepie-cakephp-component">SimplePie CakePHP Component</a> - SimplePHP is a PHP class for retrieval and parsing of RSS feeds.
<li><a href="http://bakery.cakephp.org/articles/view/cache-elements-individually-for-each-user">Cache Elements Individually For Each User</a> - Caching elements in general has been discussed before on bakery and this article takes caching of an element to a higher level. This article explains how to cache elements individually for each user.
</ul>
<p>
Be sure to check out the rest of <a href="http://bakery.cakephp.org">The Bakery</a> for more great CakePHP-related content and news.
</p>]]></description>
      <pubDate>Wed, 25 Jul 2007 11:09:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Mambo Foundation Blog: Baking Mambo]]></title>
      <guid>http://www.phpdeveloper.org/news/8311</guid>
      <link>http://www.phpdeveloper.org/news/8311</link>
      <description><![CDATA[<p>
According to <a href="http://www.source.mambo-foundation.org/content/view/126/1/">this new post</a> on the Mambo Foundation's blog, they've made a decision on what to base the next version of their software on - the <a href="http://www.cakephp.org">CakePHP PHP framework</a>.
</p>
<blockquote>
After a great deal of research the Mambo team has decided to utilize the CakePHP framework for Mambo 5.  CakePHP is a rapidly evolving, mature, and feature rich PHP framework.  The project is backed by an official Foundation (<a href="http://cakefoundation.org/">http://cakefoundation.org/</a>) much like the Mambo project itself.  We believe this is an important criterion as it helps assure the project will remain active and community minded.
</blockquote>
<p>
They include an overview of some of the features of the framework they plan to use including their flexible license, the simplicity of the development process and several "hot features" like built-in validation, access control lists and flexible view caching.
</p>]]></description>
      <pubDate>Mon, 23 Jul 2007 16:22:58 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: Mambo Unspecified Bypass Vulnerabilities]]></title>
      <guid>http://www.phpdeveloper.org/news/7764</guid>
      <link>http://www.phpdeveloper.org/news/7764</link>
      <description><![CDATA[<p>
Secunia.com has <a href="http://secunia.com/advisories/25039/">posted a new advisory</a> today that Mambo users need to sit up and take notice of. There's a vulnerability that's been discovered that could allow the bypassing of security restrictions in the application.
</p>
<blockquote>
<p>
A vulnerability is caused due to insufficient privilege checks in includes/pdf.php. No further information is currently available.
</p>
<p>
A vulnerability is caused due to insufficient privilege checks in MOStlyDB Admin. Successful exploitation requires valid administrator credentials. No further information is currently available.
</p>
</blockquote>
<p>
If you're using Mambo version 4.6.1 or prior, it's recommended that you update as soon as possible to the <a href="http://www.mamboserver.com/">latest release</a>, version 4.6.2.
</p>]]></description>
      <pubDate>Thu, 03 May 2007 09:38:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Community News: Mambo Lead Developer Quits]]></title>
      <guid>http://www.phpdeveloper.org/news/5328</guid>
      <link>http://www.phpdeveloper.org/news/5328</link>
      <description><![CDATA[<p>
According to <a href="http://blog.mamboguru.com/index.php?blog=5&title=mambo_foundation_board_counterpoint_quit&more=1&c=1&tb=1&pb=1">this post</a> on his blog today, one of the board memebers from the Mambo project, <i>Martin N Brampton</i> is formally leaving his position.
</p>
<quote>
<i>
<p>
I now feel it necessary to resign from the Board of the Mambo Foundation with immediate effect. Since joining the Board, a number of minor irregularities have been evident, and not all of them have been rectified even though I have sought to raise them. It is apparent that early decisions were taken by exchange of email and no records were kept. Present banking arrangements breach the Foundation's rules.
</p>
<p>
In terms of fundamental principles, there is a considerable concern in my mind that the Board is not informing itself about the members wishes, and not making decisions that fully take account of their interests. I see this as a breach of trust.
</p>
</i>
</quote>
<p>
He <a href="http://blog.mamboguru.com/index.php?blog=5&title=mambo_foundation_board_counterpoint_quit&more=1&c=1&tb=1&pb=1">goes on</a> to talk about some of the ongoing issues that the Board faced, including misinformation about trademark issues and their change to allow the membership of the Foundation to suggest rule changes.
</p>
<quote>
<i>
As the majority decisions being made by the Board conflict with my understanding of those obligations, I cannot continue as a Board member any longer. As there was no resolution to appoint me to the Board, I am unsure how you will handle my resignation. I will remain a member of the Foundation and continue with my work in Mambo development.
</i>
</quote>
<p>
For the complete story, check out <a href="http://www.phpdeveloper.org/mambo_pr.php">this official release</a>...
</p>]]></description>
      <pubDate>Mon, 08 May 2006 09:42:39 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Community News: Mambo Foundation Podcasts]]></title>
      <guid>http://www.phpdeveloper.org/news/4470</guid>
      <link>http://www.phpdeveloper.org/news/4470</link>
      <description><![CDATA[The Mambo Foundation has released a <a href="http://mambo-foundation.org/content/blogsection/5/54/">series of podcasts</a> lately covering all sorts of different subjects.
<p>
<ul>
<li><a href="http://mambo-foundation.org/podcast/audio/mambo-2005-09-28-39582.mp3">Episode 1</a> - Mambo love, new team members, Mamboday in Italy, and the current state of development.
<li><a href="http://mambo-foundation.org/podcast/audio/mambo-2005-10-20-32033.mp3">Episode 2</a> - a Q&A session, Mastering Mambo, phpfreelancer.org, and  an interview with two developers from mambohub.com
<li><a href="http://mambo-foundation.org/podcast/audio/mambo-2005-11-20-64624.mp3">Episode 3</a> - an interview with <i>Christian Wenz</i>, a template design contest, users survey, and the "Component Corner"
</ul>
<p>
If you haven't gotten a chance to <a href="http://mambo-foundation.org/content/blogsection/5/54/">check them out yet</a>, grab one and give it a listen. You can also <a href="http://www.mambo-foundation.org/podcast/podcast.php">subscribe to their feed</a> to catch the latest...]]></description>
      <pubDate>Thu, 08 Dec 2005 08:42:30 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[Christian Wenz's Blog: Mastering Mambo Published!]]></title>
      <guid>http://www.phpdeveloper.org/news/4463</guid>
      <link>http://www.phpdeveloper.org/news/4463</link>
      <description><![CDATA[On <i>Christian Wenz</i>'s blog today, there's an announcement about one of the latest books from Packt - <a href="http://www.hauser-wenz.de/s9y/index.php?/archives/148-Mastering-Mambo-Published!.html">Mastering Mambo</a> which he was a co-author on.
<p>
<quote>
<i>
When Tobias and I created the CMS book series for German publisher <a href="http://www.hanser.de/">Hanser</a>, we also wrote the <a href="http://www.hauser-wenz.de/s9y/index.php?/archives/141-Mambo-bei-Hanser.html">first series title</a> on <a href="http://www.mamboserver.com/">Mambo</a>/<a href="http://www.joomla.org/">Joomla</a>!. We afterwards sold the translation rights to <a href="http://www.packtpub.com/">Packt Publishing</a>. They already had a Mambo book, but liked our material so they took the last two thirds of the book, translated it and thereby created "<a href="http://www.packtpub.com/mastering_mambo/book">Mastering Mambo</a>". 
</i>
</quote>
<p>
<a href="http://www.hauser-wenz.de/s9y/index.php?/archives/148-Mastering-Mambo-Published!.html">The book</a> covers topics like creating custom layouts, builing multilingual sites, using a forum, using the Mambo extensions, and how to develop your own modules...]]></description>
      <pubDate>Thu, 08 Dec 2005 08:00:59 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[Christopher Kunz's Blog: Mambo worm in the wild]]></title>
      <guid>http://www.phpdeveloper.org/news/4441</guid>
      <link>http://www.phpdeveloper.org/news/4441</link>
      <description><![CDATA[According to <a href="http://www.christopher-kunz.de/serendipity/archives/76-Mambo-worm-in-the-wild.html">this post</a> on <i>Christopher Kunz</i> today, there's a Mambo-targeted worm out "in the wild" called <a href="http://www.christopher-kunz.de/serendipity/exit.php?url_id=382&entry_id=76">Elxbot</a>.
<p>
<quote>
<i>
Well, it wasn't totally unexpected, I guess. The recently discovered remote code execution hole in Mambo has spawned a nifty little worm, called "<a href="http://www.christopher-kunz.de/serendipity/exit.php?url_id=382&entry_id=76">Elxbot</a>". I actually referred to the (then still fairly unknown) vulnerability and to the possibility that it might be abused by worm writers in my talk at the last PHP Conference.
<p>
I am already expecting a similar outbreak for the PHPKIT holes I recently reported. It has all of the features that I outlined above, although the install base is probably somewhat limited to german users (and there, mainly to gaming clans). Seeing this, I didn't actually publish a PoC for the remote code execution hole, but it is somewhat trivial to find and exploit anyway.
</i>
</quote>
<p>
<a href="http://www.outpost24.com/ops/delta/FrameIndex.jsp?page=/ops/delta/news/News.jsp%3FXID%3D1157%26XVCLANGUAGEID%3D">The worm</a> itself searches Google for available targets, infects the system, and connects to an IRC server where the controlling party is waiting. From there things like arbitrary command execution, TCP floods, HTTP floods, and Portscans can be made. For complete information, check out <a href="http://www.outpost24.com/ops/delta/FrameIndex.jsp?page=/ops/delta/news/News.jsp%3FXID%3D1157%26XVCLANGUAGEID%3D">this page</a> on the Outpost24.com site...]]></description>
      <pubDate>Tue, 06 Dec 2005 06:50:24 -0600</pubDate>
    </item>
  </channel>
</rss>
