Basic Security Tips - Joomla! Forum - community, help and support
hello,
my site got hacked recently. in attempt secure, reduce risk have completed following , thought may useful other people.
i know followed basic steps should take wondered have missed anything.
1) took site offline
2) installed latest version of joomla_1.0.10
3) complete review off 3rd party components, modules , bots
a) visit relevant 3rd party developer sites , download latest releases.
b) uninstall components, modules or bots not need via joomla administrator area.
c) accessed site via ftp , removed component, module or bot files may have being left behind.
d) removed sql tables relating components, modules or bots have uninstalled.
e) install or upgrade latest released of 3rd party components, modules or bots.
4) chmod permissions
once happy latest version of joomla installed plus running date components, modules, bots did following.
a) set all directories chmod 755
b) set all files chmod 644
5) complete weekly backup of mysql database plus core files.
a) once above complete took backup off files on server.
b) every week take backup of mysql database.
thanks
mr bingo
my site got hacked recently. in attempt secure, reduce risk have completed following , thought may useful other people.
i know followed basic steps should take wondered have missed anything.
1) took site offline
2) installed latest version of joomla_1.0.10
3) complete review off 3rd party components, modules , bots
a) visit relevant 3rd party developer sites , download latest releases.
b) uninstall components, modules or bots not need via joomla administrator area.
c) accessed site via ftp , removed component, module or bot files may have being left behind.
d) removed sql tables relating components, modules or bots have uninstalled.
e) install or upgrade latest released of 3rd party components, modules or bots.
4) chmod permissions
once happy latest version of joomla installed plus running date components, modules, bots did following.
a) set all directories chmod 755
b) set all files chmod 644
5) complete weekly backup of mysql database plus core files.
a) once above complete took backup off files on server.
b) every week take backup of mysql database.
thanks
mr bingo
i add taking site offline , reinstall may not sufficient in cases.
to delete files in html folder before reinstalling.
one way know looking @ last saved date files.
also, advised change al passwords formerly used, as, depending on crack, db have been accessed.
to delete files in html folder before reinstalling.
one way know looking @ last saved date files.
also, advised change al passwords formerly used, as, depending on crack, db have been accessed.
Comments
Post a Comment