It's Friday - what a day to visit jfoobar!

 

Joomla! Security, let's get started!

A server on a parashute

In the Joomla! Security and unsafe Sex article we promised to do a series of articles related to Joomla! Security, in this article we will start the series. During my presentation about security at the Swiss Joomla!Day I explained that you don't need a super hero like Iron Man to make your Joomla! site save, but just common sense and a bit of patience (yes you need to study this topic a bit).

As basic foundation for this series of articles we will use the Joomla! security check-list that is available on the Joomla! Documentation wiki. We will not only handle a the Joomla! security check-list, there where needed we will go into more detail to give a better understanding on the topics we want to cover.

At Jfoobar we try to create blogs that are not too long and easy to read. The security topic will be spread out of a number of blog posts that we will try to post on a very regular basis.

Disclaimer: following the hints in this series of articles will help you improve web security. There is no best way to approach this topic, as we will explain. Keep in mind that following the descriptions in this series of articles will surely improve the security of you website, but in now way we can be responsible for the content of the articles.

We don't know how many articles we will write, but let's just start with the first article. This will be a fairly simple description of things to start with, basically we strongly advise you to take at least 2 precautions when you start with a Joomla! site.

  • Backup Early and Often: For me personally a real open door...a backup is crucial for recovery. Not only when you site has been hacked, also when something gets broken or worst case, the server crashes and you have to recover. After making an initial set-up, test if you can recover. It is fairly easy to recover a full Joomla! installation, so perform this at least once but preferable on a regular basis. This one step ensures that you can always recover from any problem. As said, this sound like something very obvious, you will be surprised how many people still think that they can rely on their hoster. I cannot hammer this one out often enough, backup on a regular basis and test it. This also is an important criteria when you select a hoster, make sure that your hoster has descent backup and recovery tools!
  • Update Early and Often: Also something obvious, but certainly not something to forget. Update your server to the latest stable version of Joomla! and don't forget to update ANY installed third-party extensions. We often see reports of sites hacked, and 99% of the times this is due to outdated versions of extensions. In an upcoming blog about security we will explain the things to keep in mind when updating your site, for now get used to this statement: update, update, update! This one step ensures that your site is protected from all new vulnerabilities as soon as a fix is released, and from all new attacks methods as soon as a defence is developed.

As mentioned before, site security is a serious matter and takes some time and effort. If you're not familiar with web security, we suggest you make time to study it. Like said in the security check-list...there is no free lunch! In these blogs we only can give you limited information, a full training course would take at least 2 days for professional users to understand all steps. We advise you to read as much as you can on this topic, below you will find some links for additional information:

To end this blog...keep in mind that the security measurement described here also apply to other PHP web solutions, even when you have written your own website in PHP. The next security blog will follow the security check-list, so next on our list is "Hosting and Server set-up".

About the author Wilco Jansen

Wilco was born in 1967 in the Netherlands where he still lives. After years of being a programmer Wilco has worked as project manager and IT manager. Discovered Joomla! when he was creating his own content management system, and never lost focus after then. Joined core team as development coordinator in May 2006 just helping to make Joomla! even better then it is already. Wilco has been deeply involved in the Joomla project as Google summer of code program manager 2006, 2007 and 2008 editions, co-organizer of the Google Highly Participation contest in 2008, first ever development coordinator, creator of the Joomla bug squad, member of the board of Open source matters, regular speaker on world wide conference advocating Joomla and much, much more. Wilco has a bachelor degree in business and information engineering and studied Master of Science knowledge and information engineering at the Middlesex University in London.

More about Wilco Jansen

Like it? Share it!

There are 1 comments posted.

# 1 - Posted by: joe2owl on 2009-09-15 08:10:19

Try RS Firewall (http://www.rsjoomla.com/joomla-components/joomla-security.html) and Joomla Scanner (http://www.joomlascanner.com)

Help for creating beautiful comments.

Enter Your Details:
Enter Your Comments:
I'm finished with the form Your form will be checked and you'll get a preview.
moovur promo

Blogging team

We have a team that works on the blogs presented on this site. Below you will find all present members who are actively working on blogs on this site.


Please contact us if you are interested in helping us out with the creation of the blogs.

Post translations

jfoobar has readers from all over the world and in many languages. If you create a translation of one of our posts and link to it than please let us know so we can add a link back to the translation at the original post.

JFoobar friends on Twitter

Follow JFoobar on twitter

Sponsored Links

Latest Comments

Aaron wrote:
2009-12-23 13:19:22 - Genius! Thanks, Wilco. I've been dying to take .
Posted in How to downlo .
Amy Stephen wrote:
2009-12-22 18:39:37 - Happy Birthday to one of Joomla!'s most noble - .
Posted in Mister Joomla .
Antonie de Wilde wrote:
2009-12-22 09:30:26 - Congrats Robin. Have a good day and watch out w .
Posted in Mister Joomla .
Robert wrote:
2009-12-22 08:51:02 - Happy Birthday Robin .
Posted in Mister Joomla .
Arno wrote:
2009-12-22 08:43:28 - Happy Birthday Robin, love your suit, you wife .
Posted in Mister Joomla .
Brian Teeman wrote:
2009-12-22 00:17:41 - Happy Birthday Robin, Welcome to the big four oh .
Posted in Mister Joomla .