|
As mentioned earlier, it's impossible to create a 100% hack-proof website, but we can make a hacker's job significantly more difficult. If you're using Joomla 5.3.3 (or later), you can take basic steps to help protect your site from attackers. According to confirmed reports, over 30,000 websites are hacked daily—a significant number, enough to understand that everyone is at risk. There's no point in becoming part of this sad statistic.
Many people think this problem won't affect them, confidently claiming that hackers aren't interested in small online stores or blogs by unknown authors. In reality, hackers, in most cases, don't care about the specifics of a website, don't analyze its content, and will attack simply because they can: destroy or change content, add a hidden link, or set up a redirect.
Any doctor will tell you that prevention is better than cure. The tips below will help improve website security and prevent hacking.
1. Update Many will be surprised by how many websites are using an outdated version of the CMS. The reasons for not updating in a timely manner can vary, including lack of time or resources, but more often than not, users don't see the need, which is a serious misconception. Several times a year, security vulnerabilities are discovered, and the Joomla team, like other developers, release updates that fix these issues. Website owners don't follow these news, but attackers know exactly which older CMS versions have security issues and will undoubtedly take advantage of this opportunity to carry out their malicious plans.
Update your Joomla core, as well as components, plugins, modules, and templates, to the latest versions. Thousands of websites are hacked due to using outdated software, although a few simple steps are needed to remove them.
2. Check your website and create a backup Don't plan to improve your website's security unless you're certain it's already free of infection. If your website is functioning properly and doesn't give cause for concern, that doesn't mean it hasn't been attacked. First, you need to conduct a full analysis; there's a chance you can detect and remove malicious code, as detailed in a previous post. The second problem is that most Joomla site owners don't change the default configuration, such as renaming the htaccess.txt file to .htaccess, disabling user registration in the User Manager, enabling shortened URLs, and other recommended actions after a successful system installation.
Once you're confident the site is free of malware and the current settings are close to ideal, perform a full backup of your site files and database. Ideally, set up regular backups, such as automatically running them once a week. Having regular backups for different time periods will protect you from many surprises, such as easily restoring an accidentally deleted article or rolling back to a previous version after a failed update.
It's important to understand that the backup should be stored separately from the main site, as if an attacker gains access to the server, the backups could also be infected or simply deleted. You can copy backup files to your computer, but the best solution is to store them on a third-party hosting service, preferably multiple copies.
3. Is the hosting secure? For information: more than a quarter of hacks occur through server-side vulnerabilities. These typically involve outdated PHP versions, open file system folder permissions, insecure web server settings… many small details can lead to dire consequences. Many hosting providers host multiple websites on a shared server, and if one website is infected, all the others are at risk, regardless of the security measures taken by the owners.
Cheap hosting providers typically do not provide a built-in firewall, backup service, or other tools designed to protect the website. Remember, the first line of defense is not Joomla, but the hosting provider's equipment.
4. Conceal Yourself The first thing a hacker needs to know to carry out a successful attack is the type of CMS the website runs on. Of course, the owner won't tell anyone they're using Joomla, but there are many signs, both obvious and indirect, that can help identify the CMS. Automated bots, including search engines, regularly query the site and, based on the information they receive, can accurately determine not only that the site is running Joomla but also the core version.
First, enable short URLs. Second, remove the meta tags generated by Joomla. This can be done using the ByeByeGenerator or RSFirewall plugins. It's a good idea to remove all "Powered by Joomla" entries. Another effective method is to instruct the web server to block requests generated by bots or hacking applications. Below is a good example of code for the .htaccess file:
Apache configuration cod: <IfModule mod_rewrite.c> RewriteEngine On RewriteCond %{HTTP_USER_AGENT} ^warning [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^wget [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^linkwalker [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^cosmos [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^moget [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^hloader [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^humanlinks [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^linkextractorpro [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^offline [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^lexibot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^collector [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^intraformant [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^blowfish [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^jennybot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^builtbottough [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^propowerbot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^backdoorbot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^webenhancer [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^tighttwatbot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^suzuran [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^vci [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^webviewer [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^szukacz [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^zeus [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Abonti [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^aggregator [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^AhrefsBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^almaden [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Anarchie [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^ASPSeek [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^asterias [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^autoemailspider [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Bandit [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^BDCbot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^BackWeb [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^BatchFTP [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^BlackWidow [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^BLEXBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Bolt [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Buddy [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^BuiltBotTough [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Bullseye [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^bumblebee [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^BunnySlippers [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^ca\-crawler [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^CazoodleBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^CCBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Cegbfeieh [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^CheeseBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^CherryPicker [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^CherryPickerElite [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^CherryPickerSE [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^ChinaClaw [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^CICC [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Collector [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Copier [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^CopyRightCheck [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Crescent\ Internet\ ToolPak [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Crescent [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Custo [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^DIIbot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^discobot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^DittoSpyder [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^DOC [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^DotBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Download\ Ninja [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Drip [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^DSurf15a [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^EasouSpider [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^eCatch [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^ecxi [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^EmailCollector [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^EmailSiphon [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^EmailWolf [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^EroCrawler [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Exabot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^EirGrabber [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^ExtractorPro [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^EyeNetIE [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Fasterfox [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^FeedBooster [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^FlashGet [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Foobot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^FrontPage [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Genieo [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^GetRight [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^GetSmart [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^GetWeb\! [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^gigabaz [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Go\!Zilla [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Go\-Ahead\-Got\-It [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^gotit [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Grabber [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^GrabNet [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Grafula [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^grub\-client [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Harvest [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^heritrix [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^httplib [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^HMView [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^HTTrack [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^httpdown [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^IDBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^id\-search [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^ieautodiscovery [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^InfoNaviRobot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^InterGET [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^InternetLinkagent [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^IstellaBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^InternetSeer [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Iria [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^IRLbot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Java/1\. [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^JennyBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^JetCar [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^JustView [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^k2spider [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Kenjin\ Spider [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Keyword\ Density/0\.9 [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^larbin [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^LeechFTP [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^LexiBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^lftp [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^libWeb [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^libwww [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^libwww\-perl [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^likse [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Link\*Sleuth [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^LinkextractorPro [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^linko [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^LinkScan/8\.1a\ Unix [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^LinkWalker [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^LNSpiderguy [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^lwp\-trivial [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Mag\-Net [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^magpie [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Mata\ Hari [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Maxthon$ [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^MaxPointCrawler [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^MegaIndex [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Memo [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^MFC_Tear_Sample [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Microsoft\ URL\ Control [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^MIDown [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^MIIxpc [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Mippin [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Missigua\ Locator [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Mister\ PiX [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^MJ12bot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^MSIECrawler [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Navroad [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^NearSite [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^NetAnts [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^NetMechanic [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^NetSpider [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^NICErsPRO [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Niki\-Bot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Ninja [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^NPBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Nutch [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Octopus [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Offline\ Explorer [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Openfind\ data\ gathere [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Openfind [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^PageGrabber [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^panscient\.com [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^pavuk [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^pcBrowser [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^PeoplePal [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^PHP/5\.\{ [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^PHPCrawl [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^PingALink [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^PleaseCrawl [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Pockey [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^ProPowerBot/2\.14 [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^ProWebWalker [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^psbot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Pump [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Python\-urllib [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^QueryN\ Metasearch [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^QRVA [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Reaper [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Recorder [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^ReGet [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^RepoMonkey [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Rippers [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^RMA [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SBIder [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Scooter [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Seeker [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SeaMonkey$ [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SemrushBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SeznamBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Siphon [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SISTRIX [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^sitecheck\.Internetseer\.com [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SiteSnagger [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SlySearch [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SmartDownload [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Snake [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SnapPreviewBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SpaceBison [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Sogou [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SpankBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^spanner [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^spbot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Spinn3r [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^sproose [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Steeler [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Stripper [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Sucker [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SuperBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^SuperHTTP [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Szukacz/1\.4 [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^tAkeOut [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Teleport\ Pro/1\.29 [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Teleport [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^TeleportPro [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Telesoft [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^The\ Intraformant [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^TheNomad [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^TightTwatBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Titan [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^toCrawl/UrlDispatcher [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^True_Robot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^True_Robot/1\.0 [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^turingos [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^TurnitinBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^UbiCrawler [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^UnisterBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^URLSpiderPro [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^URLy\ Warning [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Vacuum [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^VCI\ WebViewer\ VCI\ WebViewer [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^VoidEYE [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^webalta [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebAuto [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Win32 [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^VCI [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WBSearchBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Web\ Downloader/6\.9 [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Web\ Image\ Collector [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebBandit [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebBandit/3\.50 [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebCollage [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebCopier\ v4\.0 [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebCopier [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebEMailExtrac [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebEnhancer [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebFetch [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebGo [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebHook [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebLeacher [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebmasterWorldForumBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebMiner [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebMirror [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebReaper [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebSauger [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Website\ Quester [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Webster\ Pro [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebStripper [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WebZip [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Whacker [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Widow [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Wotbox [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Wget [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^wsr\-agent [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WWW\-Collector\-E [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WWW\-Mechanize [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^WWWOFFLE [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^x\-Tractor [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Xaldon [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Xenu [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^yandex [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Zao [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^zermelo [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Zeus [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^ZyBORG [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^coccoc [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Incutio [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^lmspider [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^memoryBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^serf [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Unknown [NC] RewriteRule ^.* - [F] </IfModule>
5. Authorization Restrictions One common hacking method is password guessing. Bots and special programs use brute-force attacks until the correct access credentials are determined. Half the job is done if the attacker knows a login with administrator rights. Dictionary guessing or letter-by-letter guessing is possible, as is a hybrid method that can quickly guess passwords like "VaSyA100500." These types of hacking methods are often referred to as "brute-force." There are several basic ways to protect yourself from such attacks, setting additional restrictions on the login form address to prevent unauthorized access to the restricted portion of the Joomla admin section:
jSecure Lite - a component that requires an access key when logging into the admin section of the site. The extended version has some additional features, such as IP address or regional authorization. AdminExile is a successful plugin that, in addition to requiring an access key, can set restrictions for IP addresses or network ranges based on a specified URL, creating blacklists and whitelists. Brute-Force Stop is another good extension that records information about failed login attempts and, when a specified threshold is reached, blocks the IP address from which such attempts are made. RSFirewall blocks an IP address if it frequently makes unsuccessful authorization attempts. pFirewall recognizes bot requests and blocks them, while correctly identifying useful search engine queries without applying any actions to them. Web server settings: By combining instructions in .htaccess and .htpasswd files, you can protect the /administrator directory from unauthorized access attempts to the website's administrative section. If brute-force attacks occur regularly, it is useful to collect some information and conduct an analysis. Typically, such attempts involve guessing passwords like "qwerty." If the requests continue, the IP addresses can be blocked via the .htaccess file. An example is below:
Apache configuration cod: # bruteforce botnet list Order Allow,Deny Allow from all Deny from 79.141.167.19 Deny from 192.42.116.16 Deny from 63.141.226.34 Deny from 128.153.145.125 Deny from 64.61.155.42 Deny from 78.32.129.58 Deny from 79.39.183.124 Deny from 5.39.76.158 Deny from 52.59.254.232 Deny from 85.17.14.21 Deny from 37.48.80.101 Deny from 37.187.7.74 Deny from 77.247.181.165 Deny from 94.242.222.40 Deny from 109.237.1.139 Deny from 128.72.91.30 Deny from 176.115.124.21 Deny from 178.238.229.54 Deny from 185.61.138.125 Deny from 46.165.208.105 Deny from 149.202.47.181 Deny from 178.162.198.109 Deny from 93.120.140.200 Deny from 185.3.32.23 Deny from 42.118.62.213 Deny from 212.74.201.244 Deny from 80.35.16.63 Deny from 83.70.178.60 Deny from 90.182.73.81 Deny from 94.113.137.129 Deny from 145.253.122.66 Deny from 131.109.59.90 Deny from 151.8.12.213 Deny from 188.13.39.226 Deny from 188.219.193.186 Deny from 212.121.116.65 Deny from 212.183.165.15 Deny from 217.7.249.243 Deny from 217.111.161.229 Deny from 217.128.175.91
A similar approach can be used to block traffic from a specific country, for example, if there are no Chinese visitors, but bot requests are constantly coming from that country. Using online services, you can generate a list of IP addresses for countries or regions, which can then be added to .htaccess.
6. Remove unused extensions and templates It's important that your Joomla installation includes only the extensions and templates that are truly needed and used. Remove components that are no longer needed. It's not recommended to install templates, plugins, and components from untrusted sources or from dubious authors. Hackers may target specific extensions, so be vigilant and cautious when installing add-ons.
7. Install a firewall To prevent hacking and attacks, you can use plugins or components that provide additional security measures. There are several popular solutions that implement firewall functionality, available in both basic and advanced versions for commercial use:
Akeeba Admin Tools
RSFirewall
Securitycheck
DMC Firewall
In conclusion The tips above can really help and provide additional security measures for your website. Although these are purely advisory in nature, we strongly recommend using them in practice. Don't let them make easy money out of you!
Go back
|