@Uvex Media
{SIGH} You sort of missed the point TBH, as Sunburn rightly says unless it is a closed network yes you still may have problems. I'm not saying that it will be any more secure, well I would love to see some 1 get round my filters especially with file uploads, or even try to crack my custom CMS security login, but that's not the point. The point, is if you create it your self you take yourself off the radar. If you know a site follows the crowd and you know how to hack via the search engines you can find all outpacthed versions of any software on the net, you then look them up for exploits and wella your in with very little trouble or even time wasted.
By creating it yourself 1 you are not in the list and 2 they don't have a detailed attack strategy they have to take an immense amount of time trying to crack it if your validation protocols are strong and with no point to start with they have to go through every possible attack or start with the most common. Now if you know your stuff you can quite easily protect against them, hell most are a 5 min job, bare in mind I actually hide my server conf, takes time to mask it as Ills when you are running Apache and yes granted could still be got by someone really knowing there stuff but the added time to their attack strategy is all it takes, 99.9% of the time, due to huge amount of easy targets that use custom solutions.
But the point being is because I created it myself attack routes are not documented and I don't appear in any attack carried out via a search engine. The point that I'm not an easy target then again means I am seriously safer due to the immense amount of easy targets out there.
I believe you have very little to gain from creating your own application
Really how many have you created or had created for you?
Are you one of those 'hate big brand types' with an axe to grind?
No, but if you know what you could do via that Ning exploit you would be scared. I don't even use that site now due to the potential that my personal security is at risk.
@chrismitchell
the question is .. is how sensitive is the data on the forum.. does it really matter?
Lets say you have 1000 threads on your DB and the software you use allows for an SQL injection attack, Kaspersky was done via a SQL injection attack I think, then all it would take is for me to add a few lines of special coding and I would delete your entire DB and all those 1000 threads.
Now if you relie on your threads to bring you ad revenue and you then find that you have an empty forum the answer is yes it does, the level of sensitivity is irrelevant as quite a few hackers just want to do it because they can, and for the recognition of doing it from other hackers, their peers if you like.
If you then allow for image uploads, for say O I don't know Avatars, and miss 1 section of validation, bare in mind file upload scripts are easy to create you need to spend time on getting them truly secure, then they can upload Malware or even possible take down the server.
Once Malware is detected you can say good by to all your ranking across board and thus most of your revenue.
If the server is hosted you will probably acquire a fine from the server company for downtime of every one on the server, lost income due to people coming to your site and getting a 500 error, and your rankings as they would move you to another server more than likely, which can effect your rankings in a negative way.
Now if I was a competitor there's reason to do it on it's own, data sensitivity is totally irrelevant 9 times out of 10 TBH.
Jaz
