<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://docs.sandbox.joomla.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=MLAbram</id>
	<title>Joomla! Documentation - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://docs.sandbox.joomla.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=MLAbram"/>
	<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/Special:Contributions/MLAbram"/>
	<updated>2026-10-11T13:28:17Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.0</generator>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Security_Checklist/Getting_Started&amp;diff=13191</id>
		<title>Security Checklist/Getting Started</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Security_Checklist/Getting_Started&amp;diff=13191"/>
		<updated>2009-02-13T00:50:43Z</updated>

		<summary type="html">&lt;p&gt;MLAbram: replaced http://forums.joomla.org with http://forum.joomla.org&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{RightTOC}}&lt;br /&gt;
== Read Me First==&lt;br /&gt;
&lt;br /&gt;
=== Security is always a concern ===&lt;br /&gt;
&lt;br /&gt;
:On the Internet, security is a fast evolving and ever present challenge. There is no one right way to secure a site, and all security methods are subject to improvement, revision, and obsolescence at any time. Luckily, there are many well-established principles that can help. The following checklist points you toward current best practices for Joomla security.&lt;br /&gt;
&lt;br /&gt;
=== The most important guidelines===&lt;br /&gt;
:This checklist is long because the full plot is thick and complex. But don&#039;t despair! Here are the essential guidelines for securing any Web site. Following these few pointers will protect your site from most catastrophes.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Backup Early and Often:&#039;&#039;&#039; Setup (and use and test!) a regular backup and recovery process. When done well, this one practice ensures that you can recover from almost any imaginable disaster.&lt;br /&gt;
# &#039;&#039;&#039;Update Early and Often:&#039;&#039;&#039; Promptly update to the latest &#039;&#039;stable&#039;&#039; version of Joomla! and any installed third-party extensions. This one step ensures that your site is protected from all new vulnerabilities as soon as a fix is released, and from all new attacks methods as soon as a defense is developed. &lt;br /&gt;
# &#039;&#039;&#039;Use a secure host&#039;&#039;&#039; Of course the above advise applies to your entire infrastructure. Proper Web security is largely a Web hosting issue. Therefore, if security matters to you, use a high-quality Web host. Consider hiring professional assistance if you have no experience or knowledge in this area. If you wish to ask questions of the community regarding security issues, please do so using the appropriate board (ex., Installation, Migration and Updating, Administration, etc) in the [http://forum.joomla.org Joomla! Forums].&lt;br /&gt;
&lt;br /&gt;
:There are many other important security considerations that you can learn about in this checklist and in the Security FAQ&#039;s.&lt;br /&gt;
&lt;br /&gt;
==There is no Web security!==&lt;br /&gt;
===There&#039;s no free lunch!=== &lt;br /&gt;
&lt;br /&gt;
: Don&#039;t be fooled by Joomla&#039;s award winning ease-of-use. Maintaining a secure Web site on the open Internet is not easy. Adequate security requires a ranging skills and knowledge, constant watchfulness, and a very solid backup and recovery process. &lt;br /&gt;
&lt;br /&gt;
===There&#039;s no one right way!===&lt;br /&gt;
&lt;br /&gt;
: Due to the variety and complexity of modern web systems, security issues can&#039;t be resolved with simple, one-size-fits-all solutions. You, or someone you trust, must learn enough about your server infrastructure to make valid security decisions. Strong security is a moving target. Today&#039;s expert might be tomorrow&#039;s victim. Welcome to the game...&lt;br /&gt;
&lt;br /&gt;
===There&#039;s no substitute for experience!=== &lt;br /&gt;
&lt;br /&gt;
: To secure your Web site, you must gain real experience (some of which will be bitter), or get experienced help from others. If you haven&#039;t invested the considerable time it takes to learn how to maintain a secure Web site, be sure you can consult with someone who has. Read this tongue-in-cheek description of the [[Top_10_Stupidest_Administrator_Tricks|Top 10 Stupidest Administrator Tricks]] which illustrates typical, blow-by-blow examples of how to learn Web security the hard way.&lt;br /&gt;
&lt;br /&gt;
==Encouragements==&lt;br /&gt;
&lt;br /&gt;
===Start at the head of the herd=== &lt;br /&gt;
&lt;br /&gt;
: The Security Forums are filled with &amp;quot;Help! I&#039;ve been hacked&amp;quot; posts by people who did NOT follow standard security practices. If you decided to study this checklist before your site is attacked, congratulation, you&#039;re already ahead of the herd.&lt;br /&gt;
&lt;br /&gt;
===It&#039;s not as hard as it looks===&lt;br /&gt;
&lt;br /&gt;
: If this is one of your first Web sites, security considerations may seem intimidating, but you don&#039;t have to deal with all of it at once. As you become familiar with tools of modern Open Source Web development, such as [http://www.gnu.org/ GNU/Linux], [http://www.apache.org Apache], [http://www.mysql.com MySQL], [http://en.wikipedia.org/wiki/SQL SQL], [http://www.php.net PHP], [http://en.wikipedia.org/wiki/HTTP HTTP], [http://en.wikipedia.org/wiki/CSS CSS], [http://en.wikipedia.org/wiki/XML XML], [http://en.wikipedia.org/wiki/RSS RSS], [http://en.wikipedia.org/wiki/TCP/IP TCP/IP], [http://en.wikipedia.org/wiki/FTP FTP], [http://subversion.tigris.org/ Subversion], [http://en.wikipedia.org/wiki/JavaScript JavaScript], [http://www.joomla.org Joomla!], you&#039;ll add refinements to your set of security tactics.&lt;br /&gt;
&lt;br /&gt;
=== How to get help ===&lt;br /&gt;
:If you believe your Web site was attacked, &#039;&#039;&#039;do not&#039;&#039;&#039; post in the Joomla! forums. If there is a vulnerability, publishing that information could put other Web sites at risk. Instead, report possible security vulnerabilities to the [http://developer.joomla.org/security/contact-the-team.html Joomla! Security Task Force].&lt;br /&gt;
&lt;br /&gt;
=== How to read these documents ===&lt;br /&gt;
#Not all techniques are appropriate for every level of user. Apply the techniques you understand and read up on the ones you don&#039;t.&lt;br /&gt;
#Not all techniques are appropriate for every server. If you use a shared server, you will need to depend on the settings established by your hosting provider. If you are using a virtual or dedicated server, you will be able to apply more creative and exotic techniques.&lt;br /&gt;
#Not all techniques are appropriate for all Joomla! versions. Where a technique applies to only one version, an image is added, such as [[Image:Compat_10.png]] or [[Image:Compat_15.png]].&lt;br /&gt;
&lt;br /&gt;
== Getting Started ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Are you ready?===&lt;br /&gt;
&lt;br /&gt;
# Can you administer a dynamic, 24x7, world-accessible, database-driven, interactive, user-authenticated web server? &lt;br /&gt;
# Do you have the time and resources to respond to the flow of emerging Internet security issues? The [[Top 10 Stupidest Administrator Tricks]] is a comic/tragic look at what can go wrong. Don&#039;t learn these tricks the hard way! Depending on your recent experience, reading the &#039;&#039;Stupidest Tricks&#039;&#039; will either make you laugh or cry.&lt;br /&gt;
&lt;br /&gt;
===Stay informed of security issues===&lt;br /&gt;
&lt;br /&gt;
: Given the complexity of web servers, new vulnerabilities and conflicts are discovered all the time. To receive all security announcements, just subscribe to Joomla Security News. There are several ways to subscribe: &lt;br /&gt;
# [http://feedburner.google.com/fb/a/mailverify?uri=JoomlaSecurityNews Automatic Email Notification]&lt;br /&gt;
# [http://feeds.joomla.org/JoomlaSecurityNews RSS feed].&lt;br /&gt;
&lt;br /&gt;
===Check the FAQs.===&lt;br /&gt;
&lt;br /&gt;
: The most helpful posts in the Joomla! Security Forum are converted into [[Security and Performance FAQs]]. Many of the items on this list are explained in much greater detail in the FAQs.&lt;br /&gt;
&lt;br /&gt;
===Learn from the pros===&lt;br /&gt;
&lt;br /&gt;
: Read the excellent [[Beginners|Absolute Beginners Guide to Joomla!]] It has wealth of tips and tricks presented in an easy to understand format. Even experienced Joomlaists find great ideas here.&lt;br /&gt;
&lt;br /&gt;
: Hunt down the many nuggets of wisdom found in the [http://forum.joomla.org Joomla! Forums], in particular the [http://forum.joomla.org/viewforum.php?f=432 Joomla! 1.5 Security Forum] and the [http://forum.joomla.org/viewforum.php?f=267 Joomla! 1.0 Security Forum].&lt;br /&gt;
&lt;br /&gt;
== Security Checklists Table of Contents==&lt;br /&gt;
# [[Security Checklist 1 - Getting Started|Getting Started]] &lt;br /&gt;
# [[Security Checklist 2 - Hosting and Server Setup|Hosting and Server Setup]]&lt;br /&gt;
# [[Security Checklist 3 - Testing and Development|Testing and Development]]&lt;br /&gt;
# [[Security Checklist 4 - Joomla Setup|Joomla Setup]]&lt;br /&gt;
# [[Security Checklist 5 - Site Administration|Site Administration]]&lt;br /&gt;
# [[Security Checklist 6 - Site Recovery|Site Recovery]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- KEEP THIS AT THE END OF THE PAGE --&amp;gt;&lt;br /&gt;
[[Category:Security Checklist]]&lt;/div&gt;</summary>
		<author><name>MLAbram</name></author>
	</entry>
</feed>