Should I upgrade considering the custom work we have done?

Discussion regarding Joomla! 2.5 security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Locked
Austin1988
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 139
Joined: Thu Oct 07, 2010 2:24 am

Should I upgrade considering the custom work we have done?

Post by Austin1988 » Thu Sep 04, 2014 2:06 pm

Hi,

I am just after a little bit of advise please.

We have a website in Joomla 2.5 that we have spent several thousand pounds on and it is only just being released because of so many different custom components that we have had built.

Ideally we would release the website in Joomla 2.5 but I am aware of security and hacking risks that could occur from out of date software.

My question is, is it likely that I'll be able to keep my Joomla 2.5 site running without it getting hacked? If not, what sort of components are there to keep the site as secure as possible?

Many thanks!

User avatar
Bernard T
Joomla! Guru
Joomla! Guru
Posts: 782
Joined: Thu Jun 29, 2006 11:44 am
Location: Hrvatska
Contact:

Re: Should I upgrade considering the custom work we have don

Post by Bernard T » Sat Sep 06, 2014 3:58 pm

From my years of experience with pro development and hosting of Joomla sites, I would boil it down to this general advice and considerations:

  • find a decent, secure and responsive hosting provider, choose wisely. Without secure and up-to-date hosting environment - nothing else matters
  • check your hosting provider's policies regarding security - do they scan the websites for malware for you, what else they do to insure your websites security?
  • check your hosting provider's policies regarding critical situations protocols , and do they just lock you website down when you have the problem and leave you "dead in the water"
  • user-isolated hosting enviroments, like VPS or dedicated servers are preferred
  • mod_security and other proven app firewalls are advisable
  • read (and learn) security articles and advisories: http://docs.joomla.org/Security
  • update Joomla regularly and on time, subscribe to security announcements http://developer.joomla.org/security.html
  • regularly check VEL - Vulnerable Extension List - http://vel.joomla.org/ and subscribe to notifications about new/resolved VE
  • (re)check where you are getting any of the extensions or templates from. If it is not the original author's website or directly from JED, then make sure you download the original version again and replace all the files with original ones. That's especially valid if you downloaded from "warez" websites
Since you state that you have had several custom extensions developed
  • ensure constant developers care of all custom extensions - not maintained extensions are mostly used "backdoors" for hackers
  • (if your budget allows) order an PHP code audit for your custom code, provided by 3rd-pty PHP security professionals
VEL Team || Security Forum || PHP/Web Security Specialist || OWASP member
JAMSS author http://forum.joomla.org/viewtopic.php?f=621&t=777957
Twitter: @toplak

Austin1988
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 139
Joined: Thu Oct 07, 2010 2:24 am

Re: Should I upgrade considering the custom work we have don

Post by Austin1988 » Sat Sep 06, 2014 4:07 pm

Thank you. I'll have a look at your points when I get chance to go through them. Thanks again

User avatar
Bernard T
Joomla! Guru
Joomla! Guru
Posts: 782
Joined: Thu Jun 29, 2006 11:44 am
Location: Hrvatska
Contact:

Re: Should I upgrade considering the custom work we have don

Post by Bernard T » Sat Sep 06, 2014 4:26 pm

No problem, anytime.

Btw. if it's not too late, and budget allows, upgrading to Joomla 3 would ensure longer core code (security) upgrades from Joomla developers team .
VEL Team || Security Forum || PHP/Web Security Specialist || OWASP member
JAMSS author http://forum.joomla.org/viewtopic.php?f=621&t=777957
Twitter: @toplak


Locked

Return to “Security in Joomla! 2.5”