Plone CMS: The FBI hack story, whether it's true or a hoax aimed at advertising a useless exploit, has piqued my curiosity. What is this CMS and what does it do? How is it different from the others?
Let's start from the beginning.
Because I already have a LAMP system installed (the initials of Linux, Apache, MySQL, PHP) I thought it wouldn't take me long. I was left out because it took me even less. The Web application installer is standalone, meaning it can set up the site on its own without even having LAMP, or better said AMP.
I ran the installer on Linux (you will also find it for Windows and VirtualBox).
I will describe the installation on Linux:
Open a terminal in the folder containing the installer and run the following commands:
tar -xf Plone-5.0.6-UnifiedInstaller-r1.tgz
cd Plone-5.0.6-UnifiedInstaller-r1
Let's start the installation with options:
sudo ./install.sh $OPTION

The last commands are for starting and stopping Plone CMS.
cd ~/Plone/zinstance/ bin/plonectl start
or

cd ~/Plone/zinstance bin/plonectl stop
You are ready, you can see the first page of Plone CMS at:

Then you can explore the setup at your leisure

and the first page

At a glance, I noticed that the application has unlimited possibilities and settings.
Take a look at a detail to understand why Plone CMS doesn't need AMP

Plone uses the ZODB database. ZODB stores Python objects with arbitrary attributes. This eliminates the need to write database schemas or table descriptions, as these are used in SQL systems. If the data models are described in some way, the descriptions are written in Python, usually using the zope.schema package.
This chapter is about the basics of ZODB, working with the ZODB database directly, such as configuring database settings.
More information about ZODB
Of course I will mention the company's claim that they want Plone to be the most secure CMS in the world. On their website they state:
"The Plone CMS is one of the most secure website systems available. It is rare to have Common Vulnerability Exposures (CVE) published about Plone. A review of CVEs in the last 3 years for popular CMSs showed the following results with Plone being a clear winner with significantly fewer CVEs:
- Plone: 40
- Drupal: 409
- WordPress: 596
Source: National Vulnerability Database, February 2015″
However, they forgot to mention the adoption-usage rates of each platform. WordPress, for example, may have had 596 vulnerabilities in 2015, but in how many installed CMSs?
The high usability of any CMS makes it more visible to hackers and security researchers. Let's see now with the latest media reports that the name Plone has become widely known how long it will be able to hold the title..
Due to the reports I write above, I decided to install the CMS, but only for educational purposes..

