SlideShare a Scribd company logo
1 of 12
Tips To Secure Your Joomla Site

                   Enukesoftware.com
About Joomla
 A Joomla Web Development framework
  is one of the key contestants in the open
  source market for supple CMS.
 Joomla framework aids to put up the
  most resourceful websites packed with
  oodles of features that is swaddled in all
  categories of populace.
 Joomla has a collection of built-in
  features. It also has a large choice of
  extra modules and propels that it will
  amplify the meriting of the designed
  website
Merits of Joomla web
development framework:
 Variety of plug-ins
 Unstrained to utilize drop down menu
  features
 Freely reachable template themes
 Easiness of update
 Simplicity of other module assimilation
 Ease of customization
 Make over of Joomla community to
  respond for any query
Tips1:
Proper Hosting Environment
   A properly configured server for your joomla website.
   Host your site on a server that runs PHP in CGI mode with
    su_php.
   PHP runs under your own account user instead of the global
    Apache user
   Don't need to set insecure global permissions like CHMOD of
    777.

a. Set register_globals OFF
b. Disable allow_url_fopen
c. Adjust the magic_quotes_gpc directive as needed for your
site. The recommended setting for Joomla! 1.0.x is ON to protect
against poorly-written extensions. Joomla! 1.5 ignores this
setting and works fine either way.
d. Don't use PHP safe_mode
Tips 2: Change the Default Database Prefix
(jos_)
     While installation, change the default
      database prefix to something random.
      This will prevent most of the SQL
      injection attacks as hackers try to
      retrive superadmin details from
      jos_users table.
Tips 3: Disable FTP Layer
 While installation, dont enable the FTP
  layer as it opens up a potential
  security hole since your FTP details
  are stored in plain text under a
  Joomla! configuration file.
 FTP layer is not required if
  your hosting is secured and
  configured properly for Joomla.
Tips 4: Change
superadministrator username
 After installation, change the
  username for the super-administrator.
  By default, its admin.
 So change it something like
  ravi.chamria so that the
  username/password combination
  becomes difficult to guess or crack.
Tips 5: Strong Password
 Always use strong password like
  E@^M!$<9@k.
 In apache web server, you can do this
  htaccess file or in cpanel.
Tips 6: Enable SEF URLs
 Most hackers use the Google inurl:
  command to search for a vulnerable
  exploit.
 So enable SEF urls from site
  configuration if you are using Joomla
  1.5.
 Use extensions like SH404SEF for
  both Joomla 1.0 and Joomla 1.5.
Tips 7: Proper file/folder
permissions
     The proper file/folder permissions for
      your joomla website is:
      * PHP files: 644
      * Config files: 666
      * Other folders: 755You can CHMOD
      the files and folders using your FTP
      client.
Tips 8: Setup a Backup and
Recovery Process
   Always rely on a strong backup and
    recovery protocol for your live website.
   Its not just hacking that may
    compromise your website but other
    factors like a faulty upgrade or
    extension install, hardware
    failure, hosting provider issues.
   You can use JoomlaPack, a non-
    commercial component native for both
    Joomla 1.0 and 1.5 for backup.
REFERNCE WEBSITE




http://www.articlesbase.com/programming-
articles/10-tips-to-secure-your-joomla-site-
987902.html

More Related Content

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Recently uploaded (20)

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 

Featured

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Featured (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

Tips to secure your joomla site

  • 1. Tips To Secure Your Joomla Site Enukesoftware.com
  • 2. About Joomla  A Joomla Web Development framework is one of the key contestants in the open source market for supple CMS.  Joomla framework aids to put up the most resourceful websites packed with oodles of features that is swaddled in all categories of populace.  Joomla has a collection of built-in features. It also has a large choice of extra modules and propels that it will amplify the meriting of the designed website
  • 3. Merits of Joomla web development framework:  Variety of plug-ins  Unstrained to utilize drop down menu features  Freely reachable template themes  Easiness of update  Simplicity of other module assimilation  Ease of customization  Make over of Joomla community to respond for any query
  • 4. Tips1: Proper Hosting Environment  A properly configured server for your joomla website.  Host your site on a server that runs PHP in CGI mode with su_php.  PHP runs under your own account user instead of the global Apache user  Don't need to set insecure global permissions like CHMOD of 777. a. Set register_globals OFF b. Disable allow_url_fopen c. Adjust the magic_quotes_gpc directive as needed for your site. The recommended setting for Joomla! 1.0.x is ON to protect against poorly-written extensions. Joomla! 1.5 ignores this setting and works fine either way. d. Don't use PHP safe_mode
  • 5. Tips 2: Change the Default Database Prefix (jos_)  While installation, change the default database prefix to something random. This will prevent most of the SQL injection attacks as hackers try to retrive superadmin details from jos_users table.
  • 6. Tips 3: Disable FTP Layer  While installation, dont enable the FTP layer as it opens up a potential security hole since your FTP details are stored in plain text under a Joomla! configuration file.  FTP layer is not required if your hosting is secured and configured properly for Joomla.
  • 7. Tips 4: Change superadministrator username  After installation, change the username for the super-administrator. By default, its admin.  So change it something like ravi.chamria so that the username/password combination becomes difficult to guess or crack.
  • 8. Tips 5: Strong Password  Always use strong password like E@^M!$<9@k.  In apache web server, you can do this htaccess file or in cpanel.
  • 9. Tips 6: Enable SEF URLs  Most hackers use the Google inurl: command to search for a vulnerable exploit.  So enable SEF urls from site configuration if you are using Joomla 1.5.  Use extensions like SH404SEF for both Joomla 1.0 and Joomla 1.5.
  • 10. Tips 7: Proper file/folder permissions  The proper file/folder permissions for your joomla website is: * PHP files: 644 * Config files: 666 * Other folders: 755You can CHMOD the files and folders using your FTP client.
  • 11. Tips 8: Setup a Backup and Recovery Process  Always rely on a strong backup and recovery protocol for your live website.  Its not just hacking that may compromise your website but other factors like a faulty upgrade or extension install, hardware failure, hosting provider issues.  You can use JoomlaPack, a non- commercial component native for both Joomla 1.0 and 1.5 for backup.