Jump to content

Recommended Posts

Posted

I know this has probably cropped up a million times before but what measures do you put in place to protect your Joomla / Moodle sites? Specifically if the webserver is onsite & a flavour of Ubuntu?

 

Do you just keep everything up to date or do you use additional tools?

 

We went through a phase of being constantly hacked. Long story, the short version being we didn't update Ubuntu/Joomla/Moodle for a long time and suffered because of it. Since we've started managing things better we haven't had any issues. On top of that we use brute force - we ban traffic to and from a group of countries. I know this isn't great but we are a small secondary school in a small area - we don't have worldwide appeal! Apache Logs Viewer (freeware : Apache Logs Viewer | Analyze & View Apache/IIS Log Files) to make nice reports to frighten people with & 'OSE Anti-Hacker for Joomla' which is an inexpensive Joomla module that *should* detect & stop most SQL injection / PHP attacks (I say *should* not because it doesn't but because I'm not expert enough to give it a glowing endorsement or not.... looking at it's log files, it certainly seems to be stopping a lot of stuff)

 

Despite all of this, I still don't feel 100% confident of how secure our sites are...

Posted

I think you've answered your own question - keep it up to date.

Any CMS system will be a nice target for hacking if it's not kept up to date.

 

Additional things you can do are:

Sign up for the security mailing lists for Joomla and Moodle make sure you check your sites when major security flaws are announced

We have our Ubuntu servers set to auto update for security patches

Install logwatch - this will send you an email daily with a breakdown of what's happening on the server so you can spot anything dodgy

Backup lots so if there is an issue you can roll

if you're very paranoid consider how smaller a footprint a virtual ubuntu server is and have one for moodle and one for joomla

Posted
Any web-facing system, whether a CMS or not, whether a website of any type, or an email server, etc. should be firewalled, audited and kept up-to-date.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...