TikiWiki administrators are reminded to check their PHP errors settings in admin->general (possible path disclosure)
- TikiWiki Security Articles
- TikiWIki Security Dcoumentation
System administrators might find the following general security advice useful in improving the security of their server:
- consider using an egress firewall on Internet-facing sites, to protect your OS against connect-back backdoor exploits
- make sure that every partition with a directory that unprivileged users such as apache can write to, is protected with the noexec mount option
