Security Checklist 7 PDF Print Email

We are sorry for any basic language used in this document. Before you post in the joomla security forum please read this checklist summary, then use it as a post template.

 

On Line Action List

  • Take your site offline temporarily to prevent others being infected

 

  • Ensure you have the latest version of Joomla
  • Notify your host and work with them to clean up the site, and to make sure there are no back doors to your site.
  • Review and action Security_Checklist to make sure you've gone through all of the steps (please note some steps are optional, but please review them all).
  • Change all passwords and if possible user names for the domains control panel, mysql, FTP, joomla Super Admin, and joomla Admin password; do change them often. Passwords should be at least 12 mixed alphanumeric characters and contain no common word phrases. Do not use the standard Admin user. Disable it. If you need to reset your admin password, see these instructions
  • Replace all templates and files with clean copies,
  • Check and/or replace all .pdf, image, photo files for exploits
  • Check you server logs for IP's calling suspicious files or attempting POST commands to non-form's
  • Use proper permissions on files and directories. They should be max permissions of 644 for files & 755 for folders with no exceptions.

IF you have permissions to access SSH (secure shell) via putty/sftp you can chmod the files and directories. You can use the following commands from within the public_html (or similar) directory. For files use:

 find -type f -exec chmod 644 {} \; 

and for directories use:

 find -type d -exec chmod 755 {} \; 
  • Request to be put on another server with php as cgi and suphp and up-to-date serverside software (apache, php etc) on your existing host or find another server host if necessary.


To check the recent file changes on your system use these commands or via a cron job

 find \public_html -ctime -1 

or

 find \public_html -mtime -1 

Please note the location of your files may be public_html or httpdocs or similar.

To protect directories that seemed to need 777 permissions to run or as a default in your images/media folder try this code within a .htaccess file within the open folder.

# secure directory by disabling script execution
AddHandler cgi-script .php .pl .py .jsp .asp .htm .shtml .sh .cgi
Options -ExecCGI

especially in your images folder

  • Make sure that is in a htaccess file in a directory that will not run any scripts or remove the extensions as required

Do check with your hosting provider to see if they have purposely secured the server your site is on; and that they or you perform regular (weekly) security updates to keep the server up to date. Check you have jail shell. A rule of thumb is the less you pay, the less they care

A Safe route for disaster relief

  • save the configuration.php file and your images and personal files one by one, (not the folder)?
  • wipe the entire joomla installation folder
  • upload a new clean version of joomla1.5.15 (minus the install folder)
  • reupload your configuration file & images, templates (even better is to use original clean copies to ensure that the hacker/defacer did not leave any shell script files in your site)
  • reinstall the latest versions of your extensions.

To do this will take your site off line for around 15 minutes. To track down your hacked/defaced html may take hours or even longer.

 

Local Security

  • Don't store user name/password in ftp program
    • Use a password manager such as the free keepass
  • Scan all machines with FTP, Joomla super admin, and Joomla admin access for malware, virus, trojans, spyware, etc.

Other Considerations

  • Do not use the standard jos_ table prefix and avoid one click installers where possible
  • Use sFTP instead of FTP where possible
  • Check for any added sub domains and/or added directories
  • Check cron for any cron jobs not set up by domain administrator
  • Download and Review raw access and error logs.
  • Deny any IP's that you got to the IP ban on your site but it may belong to a proxy site.
Was your site hacked in the past and proper site sanitation not used to remove actual
(and hidden) hack thus leaving a backdoor for reinfection.

Malicious Code or Odd Links appearing on your site

Check that the original template file does or does not insert the unwanted code or that you downloaded a paid for template from a non trusted source eg file sharing sites

Gumblar doesn’t use any particular script vulnerability. This script is injected into every web page ( I would imagine though not confirmed, if infected page is edited then saved it will also be in database) on a site. Script changes every time it is accessed. It has been seen on phpBB, SMF and vBulletin forums, on WordPress 2.7.1 blogs, on proprietary PHP sites. The script starts with (function( and has no name and is obfusticated. A common Gumblar version breaks sites due to a bug in script.

iFrames

In recent iframe exploits the malicious code was only injected into files with most common filenames (e.g. index.html, index.php, etc.). Related Forum Sticky

Contributors & Editing

mandville PhilD fw116 JeffChannell dynamicnet

 

New Joomla Templates

  1. Social ConnectedSocial ConnectedName: Social ConnectedDescription: Social Connected is a new professional, easy to use Joomla template released by the Joomladesigns team which includes custom CSS style layouts for the Jomsocial and K2 Extensions. The Social Connected template includes the following features Three Jooml ...Owner: JoomlaDesignsTags: Computers, Communications, Business, Architecture
  2. ExtendExtendName: ExtendDescription: Extend is a professional easy to use Joomla template released by the Joomladesigns Team. The new Extend template supports the following features Includes Four different Joomla Templates Built-in colour picker to customize the template colour scheme Bui ...Owner: JoomlaDesignsTags: Business, Beauty, Architecture
  3. NgineNgineName: NgineDescription: Ngine is a new professional Joomla template from Joomladesigns.co.uk which supports a wide range of features including Five built-in Joomla templates Slide show Slide pop up boxes K2 CSS styles RTL support Six built in font styles Lots of module posi ...Owner: JoomlaDesignsTags: Software, Portal, News, Games
  4. Simply City 2Simply City 2Name: Simply City 2Description: Simply City is a professional, fast loading Joomla template which is easy to use and includes a wide range of features. The web design also supports CSS styles for the popular K2 extension. The Joomla template includes the following features 3 multi col ...Owner: JoomlaDesignsTags: Computers, Communications, Business
  5. Simply CitySimply CityName: Simply CityDescription: Simply City is a professional, fast loading Joomla template which is easy to use and includes a wide range of features. The web design also supports CSS styles for the popular K2 extension. The Joomla template includes the following features 3 different ...Owner: JoomlaDesignsTags: Electronics, Computers, Communications, Business
  6. Show more...

Search Directory

Explore Directory

Top Joomla Design Teams