Thursday 25 July 2013

Joomla 2.5 Installation Security Check List

After many years of installing & customising Joomla websites I thought it might be useful to share some tips on Security:

  • When installing make sure you don't use the default jos_ table prefix for your joomla database, rename this via phpMyAdmin if necessary .
  • Never use the default Super Admin username of "admin" always change this to something else less predictable.
  • Never use the user ID: 42, either change the user ID via phpMyAdmin, or demote this user to registered and then select "block this user" via Joomla user manager.
  • Redirect the admin url to something other than /administrator/, you can do this via a .htaccess redirect, although their are plenty of great extensions out there that will aid in securing the url of your admin panel from potential hack attempts.  Jsecure Authentication is one I highly recommend, this component with allow you to choose the new admin panel address
    • i.e. /administrator/?whateveryouwant!
  • Check and change your chmod settings to:
    • directories should be 755
    • files should be 644
    • configuration.php file should be 444
    • use an ftp client like filezilla or your hosting panel file manager to change the settings
    • I prefer to install and use akeeba admin tools (lots of other great security features including WAF)
  • Avoid using ftp in Global Configuration via Joomla admin panel.
  • Set show Joomla version to "No" in Global Configuration via Joomla admin panel.
  • Ensure that all sensitive files are outside the web root.
I will add to this list as I think of others, most of them are second nature to me.  Please feel free to make comments or add suggestions to this list!

4 comments:

  1. thanks for share
    joomla is always the best CMS all platform, so friendly, so advantage
    i also want to share 7 free templates for joomla 3.0 so best for everyone

    free download templates joomla 3.0

    May be help something to you
    thanks so much

    ReplyDelete
    Replies
    1. Hi, Great work, thanks for sharing the free Jooma 3.0 templates and also providing links to their demos, I am sure other Joomla users will find this helpful, thanks.

      Delete
    2. thanks for share
      i love joomla so much, joomla is the best platform cms to make website so easily.
      I've also to share all people some templates premium joomla free to download
      free premium joomla templates
      thanks so much

      Delete
  2. hey,

    thank you sharing joomla security check list its import, i enjoy with joomla CMS

    Cheers !!!
    www.kintech.com.np

    ReplyDelete