Virya Technologies Blogs

Blogs from Virya Technologies staff

Posted by Ruth Cheesley
Ruth Cheesley
I am the owner and Director of Virya Technologies, with the responsibility for l
User is currently offline
on Saturday, 26 June 2010
in Joomla! Content Management System

Tips to secure your Joomla! site and prevent hacking

serverbugWe are often approached, as are many Joomla! developers, by those unfortunate enough to have their websites exploited for one reason or another, asking us to fix the immediate problem and also secure their site against future attacks.  Needless to say this can be quite costly, not ownly in our fees but also in terms of business downtime and potential loss of clients visiting your sites, and loss of confidence (particularly with Ecommerce sites).  Here are some basic tips to help you secure your site and prevent this happening in the first place.
  1. The most important factor in preventing sites being hacked is always to ensure you are up to date with all the latest releases, not only of Joomla! itself but also all the components, modules and plugins you may be using - you may find it useful to maintain a spreadsheet which contains these details.  We always recommend using a local test-server before rolling out upgrades on your live sites.
  2. Sign up to the Joomla Mailing List to hear when new releases come out and other important security announcements.  If you prefer RSS feeds, it's here.
  3. Choose a secure hosting provider - the cheapest is not generally the best - and make sure their settings and available features are as recommended by Joomla!
  4. Ensure you take basic precautions including
  • Rename your default administrator account (admin) to something harder to guess
  • If you're setting up an FTP account for the ftp layer, grant it permission only to the folder it needs (where your Joomla! installation is) and not to your entire site root
  • Use JSecure's plugin to "hide" your administrator back-end - this plugin only allows access if you know the "keyword" to append to the site URL
  • Only give out Super Administrator rights to people who definitely need it - if you have to give it out to a developer to faultfind ensure you're around to watch and be sure you're aware what is being done - and disable it as soon as the work is done!
  • Regularly back up your files & database - Lazybackup emails you an SQL dump of your site which can be quite useful, but don't forget if you use other applications outside of Joomla! which you've bridged in (such as forums, helpdesk etc) you'll need to back them up too!
We would strongly advise all Joomla! users to read the abundance of informative articles on the Security Checklist at Joomla's Site which goes into much more depth - if you have any specific questions please get in touch.
Rate this blog entry
0 votes
I am the owner and Director of Virya Technologies, with the responsibility for leading the website design team.

I am primarily involved with the day to day management of our website projects, ongoing support contracts and liaising with our clients from across the world.
Trackback URL for this blog entry

Comments

Guest
jahirul islam mamun Saturday, 07 January 2012

wowoo..First of all i wanna to thank you from my core of heart... what a outstanding article.. sir i have a site (

http://www.ebanglanewspaper.com
) which is build by the wordpress. How can i Prevent my site from hacking.. Please mail me..

thanks again

Leave your comment

Guest
Guest Sunday, 05 February 2012

Looking for our open source software?

viryasoftwarelogo

We release and support our open source software at Virya Software

Find us on

facebook    linkedin    twitter     youtube    vimeo    ViryaTechnologiesJoomlaResources    ViryaTechnologiesonTechnorati    rss

Virya Technologies Newsletter

Receive all the latest tips, news and reviews from Virya Technologies.

Come and meet us!

FEB
09

09.02.2012 19:30 - 22:00
Joomla! User Group Suffolk Meeting

MAR
02

02.03.2012 07:30 - 09:30
Ipswich Connected Business Breakfast

MAR
08

08.03.2012 19:30 - 22:00
Joomla! User Group Suffolk Meeting

MAR
22

22.03.2012 09:00 - 11:20
ISSBA Meet the Members

APR
06

06.04.2012 07:30 - 09:30
Ipswich Connected Business Breakfast

The latest from Virya Technologies

Virya Technologies We are delighted to announce that Ben Tasker will be joining us on a full-time basis as of Monday - Ben has been... http://t.co/Iw0JOWVN
ABOUT 8 HOURS AGO
Virya Technologies A slightly tongue-in-cheek guide to using social media! http://t.co/e1mD9xEr
Thursday, 02 February 2012 10:36
twitter Follow Viryatech on Twitter