When did you last update?
Joomla! is an actively developed open source content management system, which is constantly being improved and updated as bugs are identified, new technologies arise, and of course, people find ways to exploit new vulnerabilities.
As a result, there is usually an update on average every 6-8 weeks which fixes bugs, patches security holes, and generally keeps things running smoothly. Here at Virya Technologies we take security of Joomla! sites quite seriously, and we insist that people hosting on our servers either maintain their sites at the latest version or pay us to do this on their behalf. The reason we insist on this is simple. As soon as a vulnerability is publicised, it's 'out there'. People know about it, and they know what the vulnerability is, and how to exploit it.
Why does it matter?
If you knew that you lost your house key at the pub when there were some dodgy characters asking you where you lived, you wouldn't think twice about calling out a locksmith to change the locks. Why is the security of your website any less important?
As soon as hackers know about a vulnerability, if you don't patch that vulnerability, you're potentially open to attack - this applies both to Joomla! itself, and also to extensions (but there's enough content on that topic for an entire article in itself!). If you haven't taken certain basic security precautions, it's very easy to identify that you're running Joomla! - and this makes it even easier to attempt to exploit the vulnerability.
So, rather than waiting for someone to tell you your site is out of date - or even worse, find out the hard way by getting compromised - take matters into your own hands and take three simple steps towards securing your own site.
Three steps to basic Joomla! security
- Go to www.joomla.org/download and sign up for the security mailing list - you'll get a notification when a new version is released
- Log into your administrator portal and find out what version you're using - in 1.0.x (red stripe) this will be at the bottom; in 1.5.x (green stripe) this will be in the top right; in 1.7.x (blue stripe) this will be at the bottom - assuming you're not using an administrator template. Match this up against the versions at www.joomla.org/download - if you're out of date, update.
- Install Akeeba Admin Tools (it's free!) - it will tell you when your site is out of date (as well as let you run through several other basic security tasks), and gives you a one-click upgrade option (we also recommend installing Akeeba Backup so you can take a backup of your site before doing this!) - both available from www.akeebabackup.com
