<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: &#8220;e107 website system&#8221; &#8212; please die in a chemical fire</title>
	<atom:link href="http://strugglers.net/~andy/blog/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/</link>
	<description>I'll get there one day.</description>
	<pubDate>Sun, 12 Oct 2008 05:40:44 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.4-bleeding</generator>
		<item>
		<title>By: spam post</title>
		<link>http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-72979</link>
		<dc:creator>spam post</dc:creator>
		<pubDate>Wed, 20 Aug 2008 09:24:59 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-72979</guid>
		<description>I think that this little corner of the web should stop being so negative, i know we have issues with various web apps being less that awesome at times but yeah lets move on aye :)</description>
		<content:encoded><![CDATA[<p>I think that this little corner of the web should stop being so negative, i know we have issues with various web apps being less that awesome at times but yeah lets move on aye <img src='http://strugglers.net/~andy/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy</title>
		<link>http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-968</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Mon, 10 Jul 2006 02:13:07 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-968</guid>
		<description>digitalartist / teamcoltra,

As far as I can see his only point was that this incredibly ill-conceived feature can be disabled if only people read the documentation, which is not very reassuring to me.

Wordpress defaults to requiring moderation.  I don't know if it is even possible to make it as silly as the e107 setup I found being used to send out spam, and I have no desire to invest time in finding out.

I also have not had the same level of grief with Wordpress as I have with e107 thus far.  Nor many other types of software that my users install.  e107 has proven exceptional in this regard, so I will continue to recommend that people not touch it with a barge pole.

Rather than arguing back and forth on my blog about how e107 stacks up against Wordpress, how about you people spend the time making sure there are no more "features" like this email thing which will cause administrators like me to find old unmaintained installs of your software spewing out spam.  That might be more productive for you since as far as e107 goes I am a lost cause both as an advocate and a prospective user.</description>
		<content:encoded><![CDATA[<p>digitalartist / teamcoltra,</p>
<p>As far as I can see his only point was that this incredibly ill-conceived feature can be disabled if only people read the documentation, which is not very reassuring to me.</p>
<p>Wordpress defaults to requiring moderation.  I don&#8217;t know if it is even possible to make it as silly as the e107 setup I found being used to send out spam, and I have no desire to invest time in finding out.</p>
<p>I also have not had the same level of grief with Wordpress as I have with e107 thus far.  Nor many other types of software that my users install.  e107 has proven exceptional in this regard, so I will continue to recommend that people not touch it with a barge pole.</p>
<p>Rather than arguing back and forth on my blog about how e107 stacks up against Wordpress, how about you people spend the time making sure there are no more &#8220;features&#8221; like this email thing which will cause administrators like me to find old unmaintained installs of your software spewing out spam.  That might be more productive for you since as far as e107 goes I am a lost cause both as an advocate and a prospective user.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: digitalartist</title>
		<link>http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-967</link>
		<dc:creator>digitalartist</dc:creator>
		<pubDate>Mon, 10 Jul 2006 01:54:39 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-967</guid>
		<description>Andy,
   I think you missed the point of teamcoltra's post.  The email feature you disapprove of is something that can be easily disabled.  It is also an option not uncommon on the internet.  Many major news sites, among others, have the very same option and have for years, though I believe some require registration to use it.  

I assume (though I could be wrong) that the option to moderate comments on this type of blog is set by the person owning the blog (in this case you).  If I am correct and someone doesn't set it to moderate, does it then make it a stupid option because they can receive tons of spam  due to the input of arbitrary email address coupled with arbitrary text?

No it is not your responsibility to manage every single web app your users use, but it is also not up to you to recommend people stay away from a decent app because of options you don't like and a list of vulnerabilities found with a google search that were fixed before you made the first post of this topic.

It would be the same as someone finding an old exploit on your site that was taken care of but them using it as a reason to advise everyone avoid your services with a barge pole.  Unprofessional at the very least.</description>
		<content:encoded><![CDATA[<p>Andy,<br />
   I think you missed the point of teamcoltra&#8217;s post.  The email feature you disapprove of is something that can be easily disabled.  It is also an option not uncommon on the internet.  Many major news sites, among others, have the very same option and have for years, though I believe some require registration to use it.  </p>
<p>I assume (though I could be wrong) that the option to moderate comments on this type of blog is set by the person owning the blog (in this case you).  If I am correct and someone doesn&#8217;t set it to moderate, does it then make it a stupid option because they can receive tons of spam  due to the input of arbitrary email address coupled with arbitrary text?</p>
<p>No it is not your responsibility to manage every single web app your users use, but it is also not up to you to recommend people stay away from a decent app because of options you don&#8217;t like and a list of vulnerabilities found with a google search that were fixed before you made the first post of this topic.</p>
<p>It would be the same as someone finding an old exploit on your site that was taken care of but them using it as a reason to advise everyone avoid your services with a barge pole.  Unprofessional at the very least.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy</title>
		<link>http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-965</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Mon, 10 Jul 2006 01:02:05 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-965</guid>
		<description>teamcoltra,

It isn't my responsiblity to have to learn how to manage every single web app my users may install just to prevent security breaches and spamming of third parties.  There are not enough hours in the day and if that is your best suggestion then I would only be forced to ban use of any non-vetted package.

If you want to argue that 100% of the e107 installations I have found so far have been managed by users with poor judgement who failed to keep their software up to date then that is a line of argument I would be more willing to accept.

However the email feature concerned is extremely silly and should never have even been contemplated.</description>
		<content:encoded><![CDATA[<p>teamcoltra,</p>
<p>It isn&#8217;t my responsiblity to have to learn how to manage every single web app my users may install just to prevent security breaches and spamming of third parties.  There are not enough hours in the day and if that is your best suggestion then I would only be forced to ban use of any non-vetted package.</p>
<p>If you want to argue that 100% of the e107 installations I have found so far have been managed by users with poor judgement who failed to keep their software up to date then that is a line of argument I would be more willing to accept.</p>
<p>However the email feature concerned is extremely silly and should never have even been contemplated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: teamcoltra</title>
		<link>http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-964</link>
		<dc:creator>teamcoltra</dc:creator>
		<pubDate>Mon, 10 Jul 2006 00:48:03 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-964</guid>
		<description>The mail feature can easly be removed, and if you dont know how to remove it there are alot of people at e107.org (a group of about 20 or so that are trusted users that are soly there to help people.. and are one of the best support teams in the CMS market -although my opinion is slightly biased-) Who will hlep you remove this and if you cant do it, they will do it for you in most cases.
So this point is null. If you dont like it take it off.
No website is safe and there is always somthing that someone can take advantage of.</description>
		<content:encoded><![CDATA[<p>The mail feature can easly be removed, and if you dont know how to remove it there are alot of people at e107.org (a group of about 20 or so that are trusted users that are soly there to help people.. and are one of the best support teams in the CMS market -although my opinion is slightly biased-) Who will hlep you remove this and if you cant do it, they will do it for you in most cases.<br />
So this point is null. If you dont like it take it off.<br />
No website is safe and there is always somthing that someone can take advantage of.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy</title>
		<link>http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-851</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Mon, 03 Jul 2006 15:22:35 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-851</guid>
		<description>Because you are a poster that I have approved.  I don't really see that these situations are comparable, sorry.</description>
		<content:encoded><![CDATA[<p>Because you are a poster that I have approved.  I don&#8217;t really see that these situations are comparable, sorry.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: digitalartist</title>
		<link>http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-850</link>
		<dc:creator>digitalartist</dc:creator>
		<pubDate>Mon, 03 Jul 2006 15:17:42 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-850</guid>
		<description>You might want to check the settings.  After my post above, I checked the page with a diffferent computer that has a completely different ip address and saw my message fine so it seems the messages are available for immediate viewing once posted even though you are moderating this blog.</description>
		<content:encoded><![CDATA[<p>You might want to check the settings.  After my post above, I checked the page with a diffferent computer that has a completely different ip address and saw my message fine so it seems the messages are available for immediate viewing once posted even though you are moderating this blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: digitalartist</title>
		<link>http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-849</link>
		<dc:creator>digitalartist</dc:creator>
		<pubDate>Mon, 03 Jul 2006 15:12:55 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-849</guid>
		<description>Ok so it wouldn't get to your email but by allowing unregistered postings you open yourself up to a situation similar to the comment spam you referred to.  While it is true that you approve all messages before others see them, it is also true that all messages waiting for approval are housed on the server.  Someone could use a bot to flood the server with posts waiting to be approved and if coupled with an ip randomizer would avoid being banned and could put such a huge load on the server that they would close down your blog.  (Please remove the comment about bot flooding after you read it since I have no desire to give people ideas)</description>
		<content:encoded><![CDATA[<p>Ok so it wouldn&#8217;t get to your email but by allowing unregistered postings you open yourself up to a situation similar to the comment spam you referred to.  While it is true that you approve all messages before others see them, it is also true that all messages waiting for approval are housed on the server.  Someone could use a bot to flood the server with posts waiting to be approved and if coupled with an ip randomizer would avoid being banned and could put such a huge load on the server that they would close down your blog.  (Please remove the comment about bot flooding after you read it since I have no desire to give people ideas)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy</title>
		<link>http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-846</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Mon, 03 Jul 2006 08:51:51 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-846</guid>
		<description>digitalartist,

I don't believe that the scenario you described would be possible with this blog, as all the comments need to be moderated by myself before they are posted.

Thus, someone would have to add a comment with a fake email address, and then add the spam comments too (without akismet catching them), and I would need to approve all of them, or else they would all have to be submitted by registered users of this site.</description>
		<content:encoded><![CDATA[<p>digitalartist,</p>
<p>I don&#8217;t believe that the scenario you described would be possible with this blog, as all the comments need to be moderated by myself before they are posted.</p>
<p>Thus, someone would have to add a comment with a fake email address, and then add the spam comments too (without akismet catching them), and I would need to approve all of them, or else they would all have to be submitted by registered users of this site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: digitalartist</title>
		<link>http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-840</link>
		<dc:creator>digitalartist</dc:creator>
		<pubDate>Mon, 03 Jul 2006 01:49:14 +0000</pubDate>
		<guid isPermaLink="false">http://strugglers.net/~andy/blog/2006/06/24/e107-website-system-please-die-in-a-chemical-fire/#comment-840</guid>
		<description>Andy,
   I find it truly amazing that you would use the google search as part of your comment.  If you had actualy checked those links at google and then checked with the developement team at e107.org you would have found that 99.99% of those exploits had been taken care of (some before 070 came out and we're up to 075 now).  

Further, 
     The option to email a news item (to an arbitrary email address) with additional text is no more stupid than this blog where followup comments can be sent (to an arbitrary email address).  This too could be used to send spam.  Just imagine if someone found your email address, put it in the mail box above where the comments are entered, entered something like this blog sucks then subbmitted the same thing a hundred times, you would receive 100 emails telling you this blog sucks.  See my point?</description>
		<content:encoded><![CDATA[<p>Andy,<br />
   I find it truly amazing that you would use the google search as part of your comment.  If you had actualy checked those links at google and then checked with the developement team at e107.org you would have found that 99.99% of those exploits had been taken care of (some before 070 came out and we&#8217;re up to 075 now).  </p>
<p>Further,<br />
     The option to email a news item (to an arbitrary email address) with additional text is no more stupid than this blog where followup comments can be sent (to an arbitrary email address).  This too could be used to send spam.  Just imagine if someone found your email address, put it in the mail box above where the comments are entered, entered something like this blog sucks then subbmitted the same thing a hundred times, you would receive 100 emails telling you this blog sucks.  See my point?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
