Nuke Development Sites Offering Webmasters Better Security Alternatives
28/10/2005 Written by felosi
When you see phpnuke in the news now a days all you see is more and more vulnerablities and weaknesses discovered in all versions, especially 7.7 – 7.9. Most webmasters dont even consider phpnuke as a viable cms and most who have had nuke have either moved on to others or live in fear of being defaced or have been defaced.With working exploits so easily available to anyone, a phpnuke site may be the worst mistake a webmaster makes.
Well, there is an alternative, mainly being nuke development sites that are not affiliated with the author Francisco Burzi. These sites patch up all the holes that are found in the stock versions and offer some very effective security modules such as NukeSentinel by Bob Marion at www.NukeScripts.net, . It is a comprehensive nuke security module that blocks all known exploits and even ones that are not known as it block all dangerous queries such as union, join, bind, and others. It also has IP Tracking features as well as dos protection and scripting blockers.
The phpnuke patched series is by Chatserv at www.NukeResources.com, they have patches for all available versions even the vulnerable 7.7 – 7.9. When an exploit is discovered its not too far behind the patch comes out. The version that is most highly reccomended among the nuke development community is the 7.6 version patch level 3.1. They do patch and provide security modules for 7.7 – 7.9 although they advise you use those versions at your own risk as the core design is somewhat flawed.
Other groups such as www.Nuke-Evolution.com are offering a pre-patched install with NukeSentinel and many other useful mods and even html compliance.
I would advise any webmaster who uses nuke to patch their sites with the latest patch level and install NukeSentinel. Pre-patched installs are available at a number of sites, one being www.ravenphpscripts.com
which stays current on the latest patches in their installs. You can have a secure nuke site despite popular belief to the contrary but there is a small amount of work on your part. People may see recent exploits released for nuke 7.8 – 7.9 patch level 3.1 but keep in mind anyone who works with nuke will tell you that your best bet is to stick with the 7.6 version. Even though 7.7 – 7.9 is the latest versions it does not mean they are the most secure.
I wanted to point out to anyone who uses or is considering using phpnuke there is an alternative and you can have a secure nuke site, just not a stock one. Check out some of the links I have mentioned, do the work, and you will be able to enjoy your nuke site without fear of being hacked and have some sense of security.





