From owner-freebsd-ports@freebsd.org Sun Jan 28 18:53:59 2018 Return-Path: Delivered-To: freebsd-ports@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 7B7C1ED930A for ; Sun, 28 Jan 2018 18:53:59 +0000 (UTC) (envelope-from peo@nethead.se) Received: from ns1.nethead.se (ns1.nethead.se [5.150.237.139]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "ns1.nethead.se", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 10AA96A140 for ; Sun, 28 Jan 2018 18:53:58 +0000 (UTC) (envelope-from peo@nethead.se) X-Virus-Scanned: amavisd-new at Nethead AB DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=nethead.se; s=NETHEADSE; t=1517165302; bh=ntmgT/+E/+5gufExEEX7UbNJte2N/OJ6llrySUr0z9c=; h=Subject:To:References:From:Date:In-Reply-To; b=f+XQy0W3LSe0KjAdWFXe+9D72fhWzQTsR2GZYyWtD3Hcltbe5w9UEZN8tP7lKKBrW L6irbMat25l1e84p/68tTDawF2871d1t1JtL7TaFPyVT87FgRxu+9peLMYGNFmeKOb ddT6lC1i45pp/yl0Se8xpz+II9ZEGuADRCXqxwL4= Subject: Re: daily security run output and joomla3 To: freebsd-ports@freebsd.org References: <20180129.025651.1943739201262226813.yasu@utahime.org> <20180128180456.wle3ydeqhshspq6y@ler-imac.local> <20180129.032722.1649622669605796083.yasu@utahime.org> <20180128183100.itrn2rpc3edsmhfw@ivaldir.net> From: Per olof Ljungmark Message-ID: Date: Sun, 28 Jan 2018 19:48:20 +0100 User-Agent: Mozilla/5.0 (X11; FreeBSD amd64; rv:52.0) Gecko/20100101 Thunderbird/52.5.2 MIME-Version: 1.0 In-Reply-To: <20180128183100.itrn2rpc3edsmhfw@ivaldir.net> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 28 Jan 2018 18:53:59 -0000 On 01/28/18 19:31, Baptiste Daroussin wrote: > On Mon, Jan 29, 2018 at 03:27:22AM +0900, Yasuhiro KIMURA wrote: >> From: Larry Rosenman >> Subject: Re: daily security run output and joomla3 >> Date: Sun, 28 Jan 2018 12:04:56 -0600 >> >>> But as the OP notes, the joomla3 instructions *REQUIRE* >>> removal of the install directory for security reasons, so >>> I understand where he is coming from. >> >> Do you mean that all installed file must be removed? If so, what about >> simply deinstalling joomla3 package after instructions are finished? >> > > Does changing the owners of the directory to nobody helps? joomla (www users) > might not be able to read it The trick we use here is to keep the original www/joomla3 directory from the ports install untouched, copy its contents to vhosts/ and serve the sites(s) from there. Then one can use other means/software to keep track of possible altered files. //per