Joomla! Discussion Forums



It is currently Tue Feb 09, 2010 9:45 pm (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 4 posts ] 
Author Message
Posted: Sat Aug 09, 2008 8:35 am 
User avatar
Joomla! Ace
Joomla! Ace
Online

Joined: Tue Sep 06, 2005 11:18 am
Posts: 1171
Location: Germany
(orginal Post from rliskey)

10. Go with the cheapest hosting provider you can find, preferably a shared server that hosts hundreds of other sites, some of which are high-traffic porn sites. Don't check the list of recommended hosting providers.

9. Don't waste time with regular backups. Maybe the hosting provider will help you.

8. Don't waste time adjusting PHP and Joomla! settings for increased security. Hey, the install was brain-dead easy. How bad could the rest be? Worry about those details only if there's a problem.

7. Use the same username and password for your on-line bank account, Joomla! administrator account, Amazon account, Yahoo account, etc. Hey, who has time to keep track of so many passwords? And anyway, since you don't change passwords, it's easier to just use the same one all the time, everywhere.

6. Install your brand new beautiful Joomla!-powered site, celebrate a job well done, and don't worry about it again. After all, if you don't make any more changes, what can go wrong?

5. Do all upgrades and extension installations right there on the live site. Who needs a development and testing server anyway? If an installation fails, you'll just uninstall it again. That will hopefully also undo any damage the installation caused.

4. Trust all third-party extensions, and install all the cool-looking stuff you can find. Anyone smart enough to write a Joomla! extension will provide perfect code that blocks every known exploit attempt, now and forever. After all, almost all this stuff is provided for free by well-meaning, good-hearted people who know what they are doing.

3. Don't worry about updating to the latest version of Joomla!. Hey, nothing's gone wrong so far! Same plan for the third-party extensions. Too much work anyway.

2. When your site gets cracked, panic your way on over to the Joomla! Forums and start a new post with a very familiar title: "Help! My Site's Been Hacked!" Be sure not to leave relevant information, such as which obsolete versions of Joomla! and third party extensions were installed.

1. Once your site's been cracked, fix the defaced file and then assume all is well. Don't check raw logs, change your passwords, remove the entire directory and rebuild from clean backups, or take any other overly paranoid-seeming actions. When the attackers return the next day, scream loudly that you've been "hacked again," and it's all Joomla!'s fault. Ignore the fact that removing a defaced file is not even step one in the difficult process of fully recovering a cracked site.

_________________
MCITP - Microsoft Certified IT Professional | CCNA - Cisco Certfied Network Administrator
LPI - Linux Professional | PN for Online Transcript ID Check
http://www.mindset.de


Top
  E-mail  
 
Posted: Tue Aug 12, 2008 10:23 am 
User avatar
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Tue Jan 29, 2008 9:05 am
Posts: 22
Great tips on security and I wanted to add another one to the list:
- Don't stay abreast of the latest joomla extensions and updates which are being released. If something is not broken, than why fix it.

Hriday Biyani

_________________
Diadem Technologies Pvt. Ltd.
http://www.diadem.in
Custom Open Source Web Development


Top
  E-mail  
 
Posted: Wed Aug 20, 2008 5:51 pm 
User avatar
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Tue May 27, 2008 11:48 am
Posts: 35
Location: Hampshire, UK
nice list - good stuff for a joomla noob like me to know

about point 8, where could a noob find appropriate information on setting up PHP/my server (and Joomla) for best security? There's so much information out there and its very difficult to know what's relevant. I got my first dedicated server this week, with the intention of using it for Joomla sites, so at least I passed point 10 :D


Top
  E-mail  
 
Posted: Wed Aug 20, 2008 6:49 pm 
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Sat Nov 11, 2006 9:34 pm
Posts: 3783
Location: Hungary
This list can be also found in the Security and Performance FAQs:
http://docs.joomla.org/Security_and_Per ... _tricks.3F


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

Quick reply

 



Who is online

Users browsing this forum: aranock-online, dynamicnet, fnaqvi, fw116, jeffslough, weblapozo and 44 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group