This is a message i received from syskay on how to secure your joomla installation and prevent it from hackers and i think is wise to share it with you.
These are simple steps to secure your joomla installation and prevent it from getting hacked:
1. Change the Default Database Prefix (jos_)
While installation, change the default database prefix to something random. This will prevent most of the SQL injection attacks as hackers try to retrive superadmin details from jos_users table.a
2. Disable FTP Layer
While installation, dont enable the FTP layer as it opens up a potential security hole since your FTP details are stored in plain text under a Joomla! configuration file. FTP layer is not required if your hosting is secured and configured properly for Joomla.
3. Change superadministrator username
After installation, change the username for the super-administrator. By default, its admin. So change it something like your name or company name so that the username/password combination becomes difficult to guess or crack.
4. Strong password
Always use strong password for the administrator accounts. An example of strong password is E@^M!$<9@k. You can use sites like www.strongpasswordgenerator.
5. Enable SEF URLs
Most hackers use the Google inurl: command to search for a vulnerable exploit. So enable SEF urls from site configuration if you are using Joomla 1.5. You can also use extensions like SH404SEF for both Joomla 1.0 and Joomla 1.5. This will prevent hackers from finding the exploits as well as benefit you in SEO perspective.
6. Upgrade to latest release of Joomla
Always upgrade to the latest release of Joomla as soon as possible.
7. Always download Joomla! from official sites, such as the Joomla! Forge, and check the MD5 hash
8. Third party extensions
There are more than 4000 extensions available for Joomla many of which are non-commercial. But dont take this as an opportunity to install unnecessary extensions on your website. Remember that most hacking attempts occur due to vulnerability in these extensions. So, always use extensions which are popular, has strong community backing and development process.
9.Proper file/folder permissions
The proper file/folder permissions for your joomla website is:
* PHP files: 644
* Config files: 666
* Other folders: 755
You can CHMOD the files and folders using your FTP client.
10. Setup a backup and recovery process
Always rely on a strong backup and recovery protocol for your live website. Its not just hacking that may compromise your website but other factors like a faulty upgrade or extension install, hardware failure. You can use JoomlaPack, a non-commercial component native for both Joomla 1.0 and 1.5 for backup.
Best Regards
Nice one bro
ReplyDeletebut tha best way to keep your password safe from crackers is to make use of a traditional word cos the only kind of password crackers the world have ever known is for English words.
To make it fully undetectable(FUD) is to add numbers to it.
E.G
adaobi19,oluade32 or garuba98
with tha above you can only be afraid of script hacking and keylogging and not password crackers.
You can always check my blog for security update...........