Welcome, Guest
  • Page:
  • 1

TOPIC: Securing Your Joomla

Securing Your Joomla 2 years, 1 month ago #23474

Over the past few months I have been on a mission looking for and test driving different Joomla security applications. Below is a list of the different programs I have found to be very useful and best of all... they are free (or near free).

jSecure Authentication: (* small annual fee)
www.joomlaserviceprovider.com/component/...s/file/view/5/8.html

jFireWall Lite:
extensions.joomla.org/extensions/access-...y/site-security/4065

Site Scan:
extensions.joomla.org/extensions/tools/s...nagement-tools/12152

Change Database Prefix:
extensions.joomla.org/extensions/tools/database-tools/12150

Secure admin: (*)
extensions.joomla.org/extensions/access-...access-control/12142

The ones with an (*) after their names are recommended. I almost put Change Database Prefix on this list but did not because it requires a far amount of planning/logic on your behalf with no documentation to assist you. The 'Secure admin' is a brand new Joomla extension offering and shows a lot of promise. For those of you working behind strange or odd hosting servers I would strongly suggest looking at 'Site Scan'. This external application will scan your entire folder/file structure and set the proper permissions of your folders/directories to 755 and files to 644.

Even after using any or all of these applications, there are NO GUARANTEES that your Joomla site will be 100% safe and secure. Since Joomla is an Open Source CMS application interacting with MySQL another Open Source application, a lot of 'bad guys' know ways around almost all security software. The best prevention you can do for your site is having a daily MySQL dump sent to you via email. I would highly recommend,

JBackup System Plugin:
extensions.joomla.org/extensions/access-a-security/backup/5762

With a daily MySQL backup you are just one day behind a complete rebuild of your crashed or hacked Joomla site.

Ed

p.s. If you have tried or use something different with success, pass it along... PLEASE!
  • Ed
  • ( Moderator )
  • OFFLINE
  • LIfetime Developer - Big Bamboo
  • the Fewer the Less®
  • Posts: 1532
  • Karma: 55

Re:Securing Your Joomla 2 years, 1 month ago #23493

Thanks very much Ed,
I must admit I'm a lazy bugger when it comes to this stuff. I think you might have just gave me my belated new years resolution.

Hope your Well Ed, look forward to seeing you around JB!

Ben.
  • Ben Carter
  • ( User )
  • OFFLINE
  • Previous Member
  • Posts: 160
  • Karma: 6

Re:Securing Your Joomla 2 years, 1 month ago #23524

Wow thanks Ed - plenty of reading and playing to be done now

Cheers Anthony
  • Anthony Olsen
  • ( Admin )
  • NOW ONLINE
  • Moderator
  • Posts: 17255
  • Karma: 317
Creative Unique Minimal Joomla Templates

Re: Securing Your Joomla 1 year, 6 months ago #36737

Hi Ed, most of the links are now broken in this article, I guess the landscape changes quickly in the JED. I do have a comment, I downloaded EasySQL, based on the desire to change table jos_ prefixes, and it only works on some sites, of course as with all these measures it seems so easy to break the site when changing parameters (which I did to one of my sites, while trying to figure out the addon, and Anthony helped me fix it) There is a current question in the Joomla forum on EasySQL with the same issue I had about file being unwritable, I will keep an eye on it and update my own post.
  • handsun
  • ( User )
  • OFFLINE
  • 12 Month Developer
  • Posts: 288
  • Karma: 1

Re: Securing Your Joomla 1 year, 6 months ago #36744

Akeeba Admin Tools Pro would be my recommendation, it does *everything* Ed lists above (with the exception of DB prefix changing) and (lots) more. At Eur 20 it seems like a no-brainer. Combine that with Akeeba backup Pro, with the lazybackup plugin it now includes and you are totally covered.

DB prefix is something I always change at install time, when it's easy. I have never tried to cahnge it post install, as there is a potential to breal a lot of stuff!
  • Seth
  • ( Moderator )
  • OFFLINE
  • Moderator
  • Posts: 7583
  • Karma: 176
Internet Inspired! - Creative Websites (and freelance websmithing!)

Re: Securing Your Joomla 1 year, 6 months ago #36759

Wow... I had no idea how much the 'landscape' had changed. Thanks for posting and letting us all know this. Here is a current list that have some of my original listed but as with life, things have changed slightly. In closing... don't rely on just this list. Do your homework and ask questions along the way.

extensions.joomla.org/extensions/access-...rity/site-protection
extensions.joomla.org/extensions/access-...site-security/backup

Applications I use on production sites include;

jHackGuard (Non-Commercial)
extensions.joomla.org/extensions/access-...ite-protection/13233

Admin Tools (Commercial)
extensions.joomla.org/extensions/access-...ite-protection/14087

JDefender (Non-Commercial - Joomla 1.0 ONLY)
extensions.joomla.org/extensions/access-...ite-protection/11359

Marco's SQL Injection (Non-Commercial)
extensions.joomla.org/extensions/access-...ite-protection/12731

jSecure Authentication (Commercial)
www.joomlaserviceprovider.com/component/...s/file/view/5/8.html

Akeeba Backup (Non-Commercial & Commercial versions)
extensions.joomla.org/extensions/access-...security/backup/1606

Finally, for excellent reading regarding securing your Joomla install, give this link a go;
docs.joomla.org/Category:Security_Checklist

Also, know what you are installing into your Joomla. Bookmark this link and keep up-to-date of extensions that present potential harm to your installation. If you can, stay clear of these extensions. If you are currently using any one or more that are listed. Contact the developer and see where they are in fixing their product. Remember... it may be their application but it is YOUR site! Oddly, the majority of extensions listed are of the 'Commercial' type. This alone just angers me to no end. You and I PAY for these applications and for me, I'd expect nothing but 100% compliance.
docs.joomla.org/Vulnerable_Extensions_List

Ed
  • Ed
  • ( Moderator )
  • OFFLINE
  • LIfetime Developer - Big Bamboo
  • the Fewer the Less®
  • Posts: 1532
  • Karma: 55

Re: Securing Your Joomla 1 year, 6 months ago #36824

Thank you Ed, for your continuing support on the security topic, still waiting on an answer from the Joomla forum on Easysql For the sites I have already built, am making sure I have a current backup of each of my sites, on my computer and backed up on a flash drive as well, Akeeba is the Best! take care, Carin
  • handsun
  • ( User )
  • OFFLINE
  • 12 Month Developer
  • Posts: 288
  • Karma: 1

Re: Securing Your Joomla 1 year, 6 months ago #36827

Carin,

No problem... I'm no expert on the subject just trying to say one step ahead.

Akeeba is the Best!

I only wish it would do my laundry also!

Something to consider, if you do not already have either WAMP (Windows) or MAMP (Mac) on your local computer... strongly consider it. It makes doing adjustments to core code and MySQL a whole lot saver then on a production server. Tie this in with Akeeba and you'll have the best of all worlds!

Ed
  • Ed
  • ( Moderator )
  • OFFLINE
  • LIfetime Developer - Big Bamboo
  • the Fewer the Less®
  • Posts: 1532
  • Karma: 55
Last Edit: 1 year, 6 months ago by Ed.
  • Page:
  • 1
Time to create page: 1.08 seconds