Answer the question
In order to leave comments, you need to log in
How to secure your website from freelancers?
Periodically, the site goes through the hands of freelancers and there was doubt about the "purity" of their thoughts.
How not to pick up shells and other "backdoors" that are usually not scanned by antiviruses?
Staging and version control are not very suitable. area of work on almost the entire core of the CMS and modules + new weighty developments. In different places, you can stick references and then make your way.
How can such risks be reduced (if this can be solved at all with reasonable labor costs)?
Answer the question
In order to leave comments, you need to log in
Staging and version control are not very suitable. area of work on almost the entire core of the CMS and modules + new weighty developments.
Renat, be polite, before you say, count to 42.
Do not throw a kid in a purely criminal concept. Solve all problems by negotiation.
Freelancers, in general, don’t care about you, you are the customer and pay for the banquet, harming you and setting yourself up for so-so entertainment. Well, I have a lot of passwords. What should I drop the base? I'd rather take a second round from you when the students screw up with you, the more I will know what's going on with you.
I have a long-term project, we completed it 4 times, about 17 teams worked on it. We already know each other by name.
There are only two exits. Either do everything yourself, or find one person who will do everything himself.
at a minimum, you must have an agreement with each freelancer and similar clauses in this agreement. (just related to all sorts of shells, backdoors, viruses, etc., you can also add about the losses that happened because of all this). well, all of them must work in the version control system in order to find out exactly whose code and when it was added.
and then if suddenly, someday you find a similar thing - to the court.
Judging by the description, staging and version control in the Gita is ideal.
It’s just that the percentage hit in the Git was made specifically for this
Allow coding in separate blocks and limit validation to only the list of functions you need.
PS: There is a lot of information: if you are interested, I can drop the article on my blog.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question