Joomla! Discussion Forums



It is currently Tue Nov 24, 2009 7:09 am (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 7 posts ] 
Author Message
Posted: Thu Nov 06, 2008 5:10 am 
Joomla! Intern
Joomla! Intern
Offline

Joined: Sat Apr 08, 2006 4:44 am
Posts: 51
What most frightened is "deface". How to make a joomla site avoid this kind of attack ? What are the check lists to do ?

Thanks for advice


Top
   
 
Posted: Thu Nov 06, 2008 5:15 am 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Wed Nov 21, 2007 7:31 pm
Posts: 51
Location: Pune
security checklist is good starting point http://docs.joomla.org/Joomla!_Administrators_Security_Checklist

_________________
Do Something. Prioritize and focus

Have you checked out my blog today?.... No, do it now http://amiworks.co.in/talk/category/joomla

Join Joomla User Group Pune discussion group http://groups.google.com/group/jugpune


Top
   
 
Posted: Thu Nov 06, 2008 9:08 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sat Apr 26, 2008 6:05 am
Posts: 275
Location: New Jersey
read the above list and/or pull the cable from your server's nic card. Dont look for specific answers. Everyone has a different opinion. Understand how script kidd0z work and how to counter them. Read books about web app security and server configuration to prevent sqli, rfi, xss etc. If i tell you to install modsecurity, mod_suphp, edit php.ini, run sef, edit robots.txt etc etc etc you will come with a whole lot more questions. There is no substitute for working experience. If you want to be secure 98% hire a pro. I personally know how this brainless losers work (script kidd0z) and I analyze most of their tools so I am not really worried. I am always learning though, Its impossible to know everything.


Top
  E-mail  
 
Posted: Wed Aug 26, 2009 4:40 am 
User avatar
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Fri Aug 21, 2009 5:18 pm
Posts: 31
Location: NY
from my personal experience :
this is a method which is already listed in security checklist but worked really well for me :
" just put all your critical files outside of public_html folder "
eg: you create a folder "secure" outside of public_html folder , then you place important files such as configuration.php etc in it , then by using require once you call these files from inside public_html folder , so what happens is that your main files wot get touched by outsiders be it hacker or someone else and still they will work they used to
hope it helps

_________________
http://www.travelresult.com
http://www.sql-server-hosting.org


Top
  E-mail  
 
Posted: Thu Aug 27, 2009 11:15 am 
User avatar
Joomla! Virtuoso
Joomla! Virtuoso
Online

Joined: Sat Oct 18, 2008 3:02 am
Posts: 4815
Location: In my Room
Other tips for increase security :
- http://docs.joomla.org/Category:Security_Checklist
- viewtopic.php?f=432&t=335090
- viewtopic.php?f=432&t=391251

:)

_________________
100% FREE Joomla CMS Templates / Themes >>> http://www.freejoomlatemplatez.com
Sort by Category & Update Daily... !!!


Top
  E-mail  
 
Posted: Thu Nov 12, 2009 4:18 am 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Sun Oct 18, 2009 8:41 am
Posts: 9
Also you may want to look at this as well.

http://www.modsecurity.org/index.html


Top
  E-mail  
 
Posted: Thu Nov 12, 2009 11:29 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Tue Aug 12, 2008 9:04 am
Posts: 253
Location: Sydney, Australia
airomic wrote:
Also you may want to look at this as well.

http://www.modsecurity.org/index.html


I use a captcha (captchaconnector) with a survey.

_________________
It's great to be here......in fact,.....it's great to be anywhere!


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

Quick reply

 



Who is online

Users browsing this forum: No registered users and 33 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group