<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rochen Host Blog &#187; Joomla Security</title>
	<atom:link href="http://blog.rochenhost.com/tag/joomla-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.rochenhost.com</link>
	<description>The latest hosting news and developments from the Rochen team.</description>
	<lastBuildDate>Tue, 06 Dec 2011 22:28:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>Introducing Joomla Utilities WHM Tool for Resellers</title>
		<link>http://blog.rochenhost.com/2011/06/introducing-joomla-utilities-whm-tool-for-resellers/</link>
		<comments>http://blog.rochenhost.com/2011/06/introducing-joomla-utilities-whm-tool-for-resellers/#comments</comments>
		<pubDate>Wed, 29 Jun 2011 16:31:09 +0000</pubDate>
		<dc:creator>Wendy Robinson</dc:creator>
				<category><![CDATA[Joomla]]></category>
		<category><![CDATA[Joomla Updates]]></category>
		<category><![CDATA[Joomla Utilities]]></category>
		<category><![CDATA[Reseller Web Hosting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Host Manager]]></category>
		<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[cPanel]]></category>
		<category><![CDATA[Backup Joomla]]></category>
		<category><![CDATA[fast joomla web hosting]]></category>
		<category><![CDATA[fast reseller web hosting]]></category>
		<category><![CDATA[Joomla Hosting]]></category>
		<category><![CDATA[Joomla Security]]></category>

		<guid isPermaLink="false">http://blog.rochenhost.com/?p=730</guid>
		<description><![CDATA[If you&#8217;re a regular reader of this blog then by now you&#8217;ve heard about our Joomla Utilities cPanel tool for easy upgrading, security fixes, permissions fixes and site migration among other features available for our Joomla Hosting customers. Recently we&#8217;ve taken all of the great cPanel plugin features and integrated them into WHM (Web Host [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-544" style="border: 2px solid #dddddd; padding: 3px; margin-left: 10px; margin-bottom: 10px;" title="wendy-rochen" src="http://img.rochenhost.com/rochen/images/team/wendy-grey.jpg" alt="Wendy Robinson" width="85" height="123" /></p>
<p>If you&#8217;re a regular reader of this blog then by now you&#8217;ve heard about our <a title="Joomla Utilities From Rochen" href="http://www.rochenhost.com/cms-utilities/joomla-utilities" target="_blank">Joomla Utilities cPanel tool</a> for easy upgrading, security fixes, permissions fixes and site migration among other features available for our <a title="Joomla Performance Hosting" href="http://www.rochenhost.com/joomla-hosting" target="_blank">Joomla Hosting</a> customers.</p>
<p>Recently we&#8217;ve taken all of the great cPanel plugin features and integrated them into WHM (Web Host Manager) as an extra convenience for our Rochen <a title="Reseller Hosting" href="http://www.rochenhost.com/reseller-hosting" target="_blank">Reseller Hosting</a> customers.</p>
<div class="wp-caption alignleft" style="width: 190px"><img class=" " style="margin-right: 10px; border: 1px solid black;" title="Joomla Utilities for WHM" src="http://img.rochenhost.com/rochen/images/whm-Jutilities5.png" alt="Joomla Utilities for WHM" width="180" height="218" /><p class="wp-caption-text">Joomla Utilties for WHM is in the plugin section of the left side menu</p></div>
<p>The WHM plugin will allow you to easily upgrade all core files for Joomla 1.5 or 1.6 installations that are hosted on your Reseller account right from WHM instead of having to do all manually from their individual cPanel accounts.   You can upgrade the installations individually or you can also choose to update them all at once!</p>
<p>In addition to the upgrading feature we&#8217;ve also added the ability to fix file permissions and apply security tweaks, again directly from WHM to your Joomla 1.5 and 1.6 installations and just like when upgrading, you can choose to apply the changes to individual installations or all at once.</p>
<p>You can find the WHM Joomla Utilities tool in the Plugins section at the bottom of the left side menu in your WHM account.</p>
<div class="wp-caption alignnone" style="width: 680px"><img class="  " style="border: 1px solid black;" title="Joomla Utilities Installation List" src="http://img.rochenhost.com/rochen/images/whm-Jutilities3.png" alt="Joomla Utilities Installation List" width="670" height="253" /><p class="wp-caption-text">Displays a list of all Joomla 1.5 and 1.6 Installations within your Reseller account</p></div>
<p><em>-Wendy</em></p>
<p><em>Wendy Robinson joined the Rochen team in June 2010 as a sales support staff member. She is also currently involved with the Joomla! project as a member of the Community Leadership Team.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rochenhost.com/2011/06/introducing-joomla-utilities-whm-tool-for-resellers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Introducing Rochen Alert</title>
		<link>http://blog.rochenhost.com/2011/01/introducing-rochen-alert/</link>
		<comments>http://blog.rochenhost.com/2011/01/introducing-rochen-alert/#comments</comments>
		<pubDate>Mon, 17 Jan 2011 16:50:37 +0000</pubDate>
		<dc:creator>Wendy Robinson</dc:creator>
				<category><![CDATA[Joomla]]></category>
		<category><![CDATA[Joomla Updates]]></category>
		<category><![CDATA[Reseller Web Hosting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Backup Joomla]]></category>
		<category><![CDATA[Drupal]]></category>
		<category><![CDATA[Joomla Extensions]]></category>
		<category><![CDATA[Joomla Security]]></category>
		<category><![CDATA[Secure Hosting]]></category>
		<category><![CDATA[upgrading]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blog.rochenhost.com/?p=677</guid>
		<description><![CDATA[With Rochen&#8217;s leading edge hosting infrastructure we provide the most secure and production ready environment for your Joomla!, Drupal and WordPress based websites, and our technical support team is there to assist 24/7 with any server related issues you might experience. However, the responsibility of maintaining and securing websites lies with the site owner (you). [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-544" title="wendy-rochen" src="http://blog.rochenhost.com/wp-content/uploads/2010/07/wendy-rochen.png" alt="Wendy Robinson" width="107" height="123" />With Rochen&#8217;s leading edge <a href="http://www.rochenhost.com/about/hosting-infrastructure">hosting infrastructure</a> we provide the most secure and production ready environment for your Joomla!, Drupal and WordPress based websites, and our technical support team is there to assist 24/7 with any server related issues you might experience.</p>
<p>However, the responsibility of maintaining and securing websites <a href="https://my.rochen.com/index.php?fuse=knowledgebase&amp;view=KB_viewArticle&amp;articleId=47" target="_blank">lies with the site owner (you)</a>.  This includes core upgrades, extension upgrades, file permissions and settings.  That can be a daunting task if you have multiple websites to manage, each functioning with a unique combination of addons and possibly using different content management systems.</p>
<p>Rochen has recently introduced a unique service that can help you keep your websites secure and avoid spending money and/or lengthy periods of time fixing your site in the event of a compromise.   This new service is <a href="http://www.rochenhost.com/other-services/rochen-alert">Rochen Alert</a>.</p>
<p>What is the best way to prevent an attack or compromise and be sure that your site is as secure as possible? By <a href="https://my.rochen.com/index.php?fuse=knowledgebase&amp;view=KB_viewArticle&amp;articleId=10">keeping yourself informed</a> about the software you use and making sure you are receiving every bit of critical security news that gets released.  The reality is that it can be rather tedious to comb through all the news you receive and it&#8217;s possible that the amount of spam and irrelevant information that lands in your inbox can keep you from getting the critical news when you need it.</p>
<p>The advantage of Rochen Alert is that it allows you to subscribe to a security notification service that will send you automatic emails any time a <strong>critical</strong> security vulnerability or upgrade is reported. This covers not only core but also extensions, modules and plugins that pertain to Joomla!, Drupal, and  WordPress.  The spam, junk and irrelevant news is filtered out ensuring that only the important information gets sent to you.</p>
<h3>How does it work?</h3>
<p>The system is powered by a proprietary engine built to discover, categorize and deliver security related information. It combs the internet continuously ingesting security related topics and rejecting everything else.</p>
<ul>
<li>Security notifications for scripts you choose. E.g. Joomla, Drupal, WordPress 	etc.</li>
<li>Security notifications for plug-ins or extensions. E.g. Joomla Extensions, 	WordPress plug-ins etc.</li>
<li>Clear instructions on resolving the issue contained within the security 	notification.</li>
<li>Alerts about threats provided within hours of release.</li>
</ul>
<p>With Rochen Alert you can carry on with your day, manage your business, and be sure that any critical security notifications will find their way to you before most people even know about them. As the alerts arrive within a timely manner you can take necessary steps to prepare your sites ahead of time, keeping your own site safe and allowing your clients to have full confidence that their websites are in good hands with you.</p>
<p>Our security optimized hosting infrastructure combined with the convenience and quality of Rochen Alert notifications will always keep you one step ahead of everyone else, including the hackers.</p>
<h3>Where Can I Sign Up?</h3>
<p>Rochen Alert is available <a href="http://www.rochenhost.com/other-services/rochen-alert">here</a> for a annual subscription fee. Upon sign up you can choose your own combination of alerts pertaining to each of the three big content management systems, Joomla!, Drupal and WordPress.  As soon as your order is processed you will be on the list to start receiving your critical alert notifications.</p>
<h3>Can I get a discount?</h3>
<p>Sure! For a limited time you can use the promotional code &#8220;alertpromo&#8221; and receive $10 off the annual subscription fee for the first year of your Rochen Alert service. The promotional code will expire January 31, 2011, so sign up soon in order to save!<br />
<em>-Wendy</em></p>
<p><em>Wendy Robinson joined the Rochen team in June 2010 as a sales support staff member. She is also currently involved with the Joomla! project as a member of the Community Leadership Team.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rochenhost.com/2011/01/introducing-rochen-alert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joomla and WordPress Hosting and Security Presentations from CMS Expo. Rochen Discount Code Extended.</title>
		<link>http://blog.rochenhost.com/2010/06/joomla-and-wordpress-hosting-and-security-presentations-cms-expo/</link>
		<comments>http://blog.rochenhost.com/2010/06/joomla-and-wordpress-hosting-and-security-presentations-cms-expo/#comments</comments>
		<pubDate>Thu, 03 Jun 2010 16:13:54 +0000</pubDate>
		<dc:creator>Chris Adams</dc:creator>
				<category><![CDATA[Joomla]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[CMS Expo]]></category>
		<category><![CDATA[Drupal Hosting]]></category>
		<category><![CDATA[Joomla Hosting]]></category>
		<category><![CDATA[Joomla Security]]></category>
		<category><![CDATA[WordPress Hosting]]></category>
		<category><![CDATA[WordPress Security]]></category>

		<guid isPermaLink="false">http://blog.rochenhost.com/?p=501</guid>
		<description><![CDATA[Last month Martin, Adam and I from the Rochen team attended CMS Expo in Chicago, IL as Diamond Marquee Sponsors. It was a fantastic event where we got to meet a lot of our existing customers, potential customers and connect with various people in the Joomla, Drupal and WordPress communities. We&#8217;re a technology services company [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" title="Chris Adams, Rochen's CEO" src="http://blog.rochen.com/images/staffpics/chris-adams-blog.png" alt="" width="150" height="150" />Last month Martin, Adam and I from the <a href="http://www.rochenhost.com" target="_blank">Rochen</a> team attended <a href="http://www.cmsexpo.net" target="_blank">CMS Expo</a> in Chicago, IL as Diamond Marquee Sponsors. It was a fantastic event where we got to meet a lot of our existing customers, potential customers and connect with various people in the <a href="http://www.joomla.org" target="_blank">Joomla</a>, <a href="http://www.drupal.org" target="_blank">Drupal</a> and <a href="http://www.wordpress.org" target="_blank">WordPress</a> communities. We&#8217;re a technology services company that primarily deals online but nothing beats meeting face-to-face.</p>
<p>While at CMS Expo Adam and I delivered two 90 minute presentations on &#8220;<strong>WordPress Hosting and Security</strong>&#8221; and &#8220;<strong>Joomla Hosting and Security</strong>&#8220;. I have linked both of these below in PDF format in case anyone wishes to review them. Rochen also had a fantastic 20 ft x 10 ft booth setup at CMS Expo which I have attached a picture of as well. Apologies for the poor quality &#8211; it was taken with an iPhone.</p>
<p><a href="http://blog.rochenhost.com/wp-content/uploads/2010/05/Rochen-WordPress-Hosting-and-Security-Presentation.pdf" target="_blank">Download &#8220;WordPress Hosting and Security&#8221; Presentation</a></p>
<p><a href="http://blog.rochenhost.com/wp-content/uploads/2010/05/Rochen-Joomla-Hosting-and-Security-Presentation.pdf" target="_blank">Download &#8220;Joomla Hosting and Security&#8221; Presentation</a></p>
<p>In the last slide of the &#8220;Joomla Hosting and Security&#8221; presentation you may notice we discuss a new Joomla Utilities plug-in for our control panel that we will be releasing in beta here at Rochen later today. This new tool will make managing and keeping your Joomla sites secure a lot easier. We plan to develop similar tools for both Drupal and WordPress as well. More details on this to come very soon.</p>
<p>(I would also advise reviewing my original blog post on <a href="http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/" target="_blank">Joomla Hosting Security</a> from September 2008.)</p>
<p><em>Disclaimer: Security advice and best practices change over time. The details posted in the above presentations are correct, to the best of our knowledge, at the time of posting. For the most up to date security information please consult with your web hosting provider and site developer directly. Please always seek expert advice.</em></p>
<div class="mceTemp mceIEcenter">
<dl id="attachment_504" class="wp-caption aligncenter" style="width: 614px;">
<dt class="wp-caption-dt"><a href="http://blog.rochenhost.com/wp-content/uploads/2010/05/rochen-booth-cmsx2010.jpg"><img class="size-full wp-image-504" title="Rochen Booth at CMS Expo 2010." src="http://blog.rochenhost.com/wp-content/uploads/2010/05/rochen-booth-cmsx2010.jpg" alt="" width="604" height="453" /></a></dt>
</dl>
</div>
<p>Second to last, you may have noticed that we launched a new website at the start of May just before CMS Expo. We are still tweaking the design a little and also building out the pre-sales FAQ sections but we are very happy with it so far.</p>
<p>Finally, at CMS Expo we issued a promotional code for 20% off your first invoice with Rochen for any <a href="http://www.rochenhost.com/business-hosting">Business Hosting</a>, <a href="http://www.rochenhost.com/reseller-hosting">Reseller Hosting</a> or <a href="http://www.rochenhost.com/virtualization/managed-virtual-server">Managed Virtual Server (MVS)</a> solution. This promotional code has now expired however we have decided to re-activate it with this blog post through until midnight UTC on Monday, June 7th 2010. <strong>The promotional code is: CMSX</strong></p>
<p>Rochen&#8217;s hosting platform is purpose built to deliver the very best performance and tightest security for database driven dynamic scripts like Joomla and WordPress. If you would like to discuss your hosting needs then please contact us via <a href="mailto:sales@rochen.com">sales@rochen.com</a> and we will be happy to assist.</p>
<p>Thanks for reading.</p>
<p>- Chris</p>
<p><em>Chris Adams is the Founder and CEO of Rochen Ltd.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rochenhost.com/2010/06/joomla-and-wordpress-hosting-and-security-presentations-cms-expo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rochen Staff and more JoomlaDay Events</title>
		<link>http://blog.rochenhost.com/2009/10/rochen-staff-and-more-joomladay-events/</link>
		<comments>http://blog.rochenhost.com/2009/10/rochen-staff-and-more-joomladay-events/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 03:36:13 +0000</pubDate>
		<dc:creator>Brad Baker</dc:creator>
				<category><![CDATA[Joomla]]></category>
		<category><![CDATA[Joomla Events]]></category>
		<category><![CDATA[Joomla Hosting]]></category>
		<category><![CDATA[Joomla Security]]></category>
		<category><![CDATA[JoomlaDays]]></category>

		<guid isPermaLink="false">http://blog.rochen.com/?p=316</guid>
		<description><![CDATA[Rochen keep in touch with their customers and the wider Joomla Community through our support and attendance of JoomlaDays and Joomla Events around the world. We try to keep our clients informed via our Twitter stream: @rochenhost make sure you follow us. Recently on the list of events we attended and supported was the Sydney [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" title="Brad Baker" src="http://blog.rochen.com/images/staffpics/brad-baker-blog.png" alt="" width="150" height="150" />Rochen keep in touch with their customers and the wider Joomla Community through our support and attendance of JoomlaDays and Joomla Events around the world. We try to keep our clients informed via our Twitter stream: <a title="Rochenhost on Twitter" href="http://twitter.com/rochenhost" target="_blank">@rochenhost</a> make sure you follow us.</p>
<p>Recently on the list of events we attended and supported was the <a title="Sydney JoomlaDay 2009" href="http://sydney.joomladay.org.au/" target="_blank">Sydney JoomlaDay 2009</a>.<br />
Thanks to all the people behind this event, the day was both informative and enjoyable. I was able to meet up with a number of current customers (and hopefully future ones) and discuss with them their needs and plans for the future. Here&#8217;s a small picture I took at the end of the event: <a title="JoomlaDay Sydney 2009 Rochen" href="http://yfrog.com/0sdfqj" target="_blank">http://yfrog.com/0sdfqj</a> If you attended this event and missed the coupon code we shared, please get in touch with me.</p>
<p>Later in the year we&#8217;re proud to be providing support to the <a title="Joomla! Developer Conference" href="http://community.joomla.org/blogs/community/1038-joomla-developer-conference.html" target="_blank">Joomla! Developer Conference</a> in New York City on Dec 5 and 6 2009.</p>
<p>Other JoomlaDays currently being planned in 2010 that we will also attend include: <a title="Melbourne JoomlaDay 2010" href="http://melbourne.joomladay.org.au/" target="_blank">Melbourne JoomlaDay 2010</a> and <a title="CMS Expo" href="http://www.cmsexpo.net/" target="_blank">CMS Expo 2010</a>. We may be able to have more than one staff member present at some of these future events as we try to contribute to the Joomla Community by sharing our knowledge and services of Joomla Hosting, after all, we <em>know</em>how to host Joomla sites being the <a title="Rochen Joomla Hosting Partner" href="http://www.joomla.org/about-joomla/the-project/partners.html" target="_blank">Official Hosting Partner of the Joomla Project</a>.</p>
<p>In the nearer future, you can catch us in Vietnam at the <a title="JoomlaDay Ho Chi Minh City Vietnam" href="http://joomladay.joomlaviet.org/" target="_blank">JoomlaDay Ho Chi Minh City</a> on November 1 2009. We&#8217;re not only attending this event, but also providing sponsorship.</p>
<p>If you have any questions regarding your hosting needs (present and future) and you can attend any of these events, be sure to let us know and we&#8217;d be happy to arrange to spend some time with you.</p>
<p style="margin: 0px 0px 0.8em; padding: 0px; outline-width: 0px; font-size: 1em; vertical-align: baseline; background-color: transparent; line-height: 20px;">
<p style="margin: 0px 0px 0.8em; padding: 0px; outline-width: 0px; font-size: 1em; vertical-align: baseline; background-color: transparent; line-height: 20px;">- Brad</p>
<p style="margin: 0px 0px 0.8em; padding: 0px; outline-width: 0px; font-size: 1em; vertical-align: baseline; background-color: transparent; line-height: 20px;">
<p style="margin: 0px 0px 0.8em; padding: 0px; outline-width: 0px; font-size: 1em; vertical-align: baseline; background-color: transparent; line-height: 20px;"><em>Brad Baker has been a member of the Rochen team since early 2003 and is a founding member of the Joomla! Open Source Project. He currently is part of the Joomla LeadershipTeam, and also blogs <a title="Joomla Tutorials" href="http://joomlatutorials.com/blog.html">here</a>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rochenhost.com/2009/10/rochen-staff-and-more-joomladay-events/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reminder: Keep Your Joomla Sites Updated and Secure!</title>
		<link>http://blog.rochenhost.com/2009/09/reminder-keep-your-joomla-sites-updated-and-secure/</link>
		<comments>http://blog.rochenhost.com/2009/09/reminder-keep-your-joomla-sites-updated-and-secure/#comments</comments>
		<pubDate>Fri, 11 Sep 2009 01:36:44 +0000</pubDate>
		<dc:creator>Brad Baker</dc:creator>
				<category><![CDATA[Joomla]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Joomla Hosting]]></category>
		<category><![CDATA[Joomla Security]]></category>
		<category><![CDATA[Rochen Vault]]></category>
		<category><![CDATA[Secure Hosting]]></category>
		<category><![CDATA[UK Hosting]]></category>

		<guid isPermaLink="false">http://blog.rochen.com/?p=311</guid>
		<description><![CDATA[I can&#8217;t hold back any more, I&#8217;m seeing still, so many people who do not keep their Joomla sites up to date, and then end up being exploited/compromised and cause more stress to themselves.. so.. again.. please Keep Your Joomla Sites Updated and Secure! A simply way to do this, and with minimal effort is [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" title="Brad Baker" src="http://blog.rochen.com/images/staffpics/brad-baker-blog.png" alt="Brad Baker" width="150" height="150" /></p>
<p>I can&#8217;t hold back any more, I&#8217;m seeing still, so many people who do not keep their Joomla sites up to date, and then end up being exploited/compromised and cause more stress to themselves.. so.. again.. please <strong>Keep Your Joomla Sites Updated and Secure!</strong></p>
<p>A simply way to do this, and with minimal effort is to use this great free component: <a href="http://extensions.joomla.org/extensions/core-enhancements/installers/9332">Update Manager for Joomla! &#8211; Joomla! Extensions Directory</a> &#8211; it will enable you to update your site, all from your Joomla backend. What could be easier?</p>
<p>BTW It&#8217;s not just Joomla that needs to be kept up to date, but any scripts you run. Joomla, along with scripts like WordPress are very popular and as a result attract the &#8216;script kiddies&#8217; and others who once a patch is released, work out how to scan for compromised sites and exploit &#8230; YOU.</p>
<p>So, avoid being blacklisted by Google, avoid the downtime and pain involved with recovering from a site compromise, and simply <strong>Keep Your Joomla Sites Updated and Secure!</strong></p>
<p>If you are in the unfortunate situation where you&#8217;ve been &#8216;driving a racing car without a helmet or seat belt&#8217; aka not bothering to Keep Your Joomla Sites Updated and Secure and your site has been compromised, please see the following articles: <a href="https://my.rochen.com/index.php?fuse=knowledgebase&amp;view=KB_viewArticle&amp;articleId=125&amp;public=1">How do I use Rochen Vault?</a> and <a href="https://my.rochen.com/index.php?fuse=knowledgebase&amp;view=KB_viewArticle&amp;articleId=24&amp;public=1">My site has been compromised, help!</a></p>
<p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0.8em; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-size: 1em; vertical-align: baseline; background-image: initial; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: transparent; line-height: 20px; background-position: initial initial; padding: 0px; border: 0px initial initial;">- Brad</p>
<p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0.8em; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-size: 1em; vertical-align: baseline; background-image: initial; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: transparent; line-height: 20px; background-position: initial initial; padding: 0px; border: 0px initial initial;"><em>Brad Baker has been a member of the Rochen team since early 2003 and is a founding member of the Joomla! Open Source Project. He currently is part of the Joomla LeadershipTeam, and also blogs <a title="Joomla Tutorials" href="http://joomlatutorials.com/blog.html">here</a>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rochenhost.com/2009/09/reminder-keep-your-joomla-sites-updated-and-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joomla! Events Rochen are Attending and Sponsoring. Joomla Hosting and Security.</title>
		<link>http://blog.rochenhost.com/2009/01/joomla-events-rochen-are-attending-and-sponsoring-joomla-hosting-and-security/</link>
		<comments>http://blog.rochenhost.com/2009/01/joomla-events-rochen-are-attending-and-sponsoring-joomla-hosting-and-security/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 23:02:57 +0000</pubDate>
		<dc:creator>Brad Baker</dc:creator>
				<category><![CDATA[Joomla]]></category>
		<category><![CDATA[Joomla Events]]></category>
		<category><![CDATA[Joomla Hosting]]></category>
		<category><![CDATA[Joomla Security]]></category>
		<category><![CDATA[JoomlaDays]]></category>

		<guid isPermaLink="false">http://blog.rochen.com/?p=104</guid>
		<description><![CDATA[This year is shaping up to be an even busier year than last year at Rochen. Our recently launched Managed Virtual Server (MVS) platform continues to be one of our most successful products from 2008 and we hope that to continue this year as well. Still in the pipeline for the near future is our [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" title="Brad Baker" src="http://blog.rochen.com/images/staffpics/brad-baker-blog.png" alt="" width="150" height="150" />This year is shaping up to be an even busier year than last year at Rochen. Our recently launched <a href="http://www.rochenhost.com/managed/virtual/" target="_blank">Managed Virtual Server (MVS)</a> platform continues to be one of our most successful products from 2008 and we hope that to continue this year as well. Still in the pipeline for the near future is our Rochen &#8216;Exclusive&#8217; Affiliate program that will be only open to selected applicants. Look out for more information on that soon.</p>
<p><strong>Joomla Events where you can meet some of the Rochen team</strong>:</p>
<p><a title="Melbourne JoomlaDay" href="http://melbourne.joomladay.org.au" target="_blank">Melbourne JoomlaDay</a> &#8211; Sat 7th February &#8211; Sun 8th February 2009<br />
I&#8217;ll be attending this event, along with some other Joomla Core Team and Workgroup members. Look out for my presentation on Joomla Hosting, as well as others on the day regarding Joomla Security.</p>
<p><a title="UK JoomlaDay" href="http://joomladay.org.uk/" target="_blank">UK JoomlaDay</a> &#8211; Sat 14th March &#8211; Sun 15th March 2009<br />
Chris as well as Martin will be attending this event. This is only the second UK JoomlaDay, so I&#8217;d expect it to be a sold out event. Chris will also be speaking on Joomla security from a web hosting prospective. In the mean time you may wish to review his <a href="http://blog.rochen.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/" target="_blank">previous blog post on Joomla Security</a>.</p>
<p><a title="Las Vegas JoomlaDay" href="http://lasvegas.joomladayusa.org/" target="_blank">Las Vegas JoomlaDay</a> &#8211; Sat 4th April 2009<br />
Chris will be attending this event, and it&#8217;s shaping up to be one of the biggest Joomla Events of the year. Some of the presenters include: Steve Burge, Vic Drover, Andrew Eddie, Anthony Ferrara, Louis Landry, Toni Marie, Jennifer Marriott, Wendy Robinson, Rob Schley and Elin Waring.</p>
<p>Rochen do more than just <a title="Joomla!" href="http://www.rochenhost.com" target="_blank">Joomla hosting</a>. We try to support Joomla as much as we can by not only our <a href="http://www.joomla.org/about-joomla/the-project/partners.html" target="_blank">sponsorship of the project</a>, but also of JoomlaDays.</p>
<p>Which events will you be attending this year? We be happy to catch up with any current or potential customers while we attend these events.</p>
<p>We&#8217;re looking forward to seeing some of you there!</p>
<p>- Brad</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rochenhost.com/2009/01/joomla-events-rochen-are-attending-and-sponsoring-joomla-hosting-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Joomla! Security &#8211; Ever been hacked? Sorting fact from fiction. Useful security tips for Joomla! users.</title>
		<link>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/</link>
		<comments>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/#comments</comments>
		<pubDate>Fri, 19 Sep 2008 22:51:27 +0000</pubDate>
		<dc:creator>Chris Adams</dc:creator>
				<category><![CDATA[Joomla]]></category>
		<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Joomla Hosting]]></category>
		<category><![CDATA[Joomla Security]]></category>
		<category><![CDATA[Secure Joomla Host]]></category>

		<guid isPermaLink="false">http://blog.rochen.com/?p=3</guid>
		<description><![CDATA[Firstly, welcome to the Rochen Blog and our inaugural post. I am not sure where this blog is going to take us or what topics we will cover, but pretty much everything is on the table. With this first blog I thought it would be a good idea to cover a topic on the minds [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" src="http://blog.rochen.com/images/staffpics/chris-adams-blog.png" alt="" width="150" height="150" />Firstly, welcome to the <a href="http://blog.rochen.com">Rochen Blog</a> and our inaugural post. I am not sure where this blog is going to take us or what topics we will cover, but pretty much everything is on the table. With this first blog I thought it would be a good idea to cover a topic on the minds of many people – <a href="http://developer.joomla.org/security.html" target="_blank">Joomla! security</a>.</p>
<p>I think it is fair to say that Joomla! has received a lot of unjustified and misinformed criticism from many in the web hosting community. In my opinion the main reason for this is that when a Joomla! powered website is hacked on a host’s server then the vast majority of providers automatically assume the problem lies with Joomla! itself (because that’s what the site is running) and immediately tag it as a script with a lot of security problems without any proper research. Some hosts have even gone as far as banning Joomla! from their servers.</p>
<p>From our own experiences here at Rochen we have found that the vast majority of security issues that come up with Joomla! sites are nothing to do with the core code released by Joomla! themselves but due to poorly coded, insecure or out of date third-party extensions that are installed under Joomla. Even if your Joomla install is kept fully updated but you have a single insecure extension installed then this will allow your entire site to be compromised. <strong>Vulnerable extensions are lethal to your site security.</strong></p>
<p>As you might be aware Rochen know a thing or two about <a href="http://www.rochenhost.com/hosting/" target="_blank">Joomla hosting</a>. We host thousands of Joomla! powered websites but <a href="http://www.joomla.org/about-joomla/the-project/partners.html" target="_blank">we also host all of the Joomla! official sites</a> at <a href="http://www.joomla.org/" target="_blank">www.joomla.org</a> as well. <span> </span>We hosted the very first install of Joomla before any other provider. So I have put together a few recommendations based on things we have seen at Rochen that will hopefully help you keep your Joomla site more secure. Hosting with Rochen never hurts, but these tips are not specific to us.</p>
<p>1. Host your site on a server that runs PHP in CGI mode with su_php. This means that PHP runs under your own account user instead of the global Apache user and you don’t need to set insecure global permissions like CHMOD of 777. Not having PHP configured in this way opens you up to cross-account attacks from other users on the shared server since you will need to CHMOD to 777 any directories Joomla! need to be able to write to. It also makes installing and managing extensions a real nightmare for the webmaster. A shameless plug, but in case you were wondering, yes, Rochen meets this requirement and we also performance tune all of our PHP installs as well for good measure.</p>
<p>2. Providing you are hosted on a server that runs PHP as directed above then you should ensure all of your files are CHMOD to 644 and directories to 755. One exception is to ensure your Joomla configuration.php file is CHMOD to 640. You should never CHMOD any files or directories to 777, especially your <strong>configuration.php</strong> file.</p>
<p>3. The <a href="http://help.joomla.org/content/view/1941/302/1/2/" target="_blank">Joomla! FTP Layer</a> was developed as a work around solution in case a user was hosting a site on a server that did not run PHP under the account user. It allows for extensions to be installed under Joomla without running into file ownership issues. Unfortunately, it also opens up a potential security hole since your FTP details are stored in plain text under a Joomla! configuration file. <span> </span>If you are hosting in a secured and tuned environment, like we have here at Rochen, then you don’t actually need the FTP layer to be enabled as extensions will install out of the box without any hassle and you can manage them without running into file ownership issues. <strong>You should disable the Joomla FTP Layer and ensure it has not stored your login details.</strong></p>
<p>4. There was <a href="http://developer.joomla.org/security/news/241-20080801-core-password-remind-functionality.html" target="_blank">a security issue with Joomla reported around a month ago</a> that allowed an attacker to reset the Joomla administrator password for a site. Although it is not a complete solution a really simple thing you can do to help protect yourself if an issue like this comes up again is to change your Joomla! administrator username. Change it from the default “admin” to something <span> </span>else like “chris.admin”. Make it that bit harder for an attacker to compromise your site.</p>
<p>5. Although it might be tempting to <a href="http://extensions.joomla.org/" target="_blank">install every extension under the sun</a> (there are a lot of wonderful ones out there and some not so great!) only install the ones you need. The more you install under Joomla! then the more likely your site is to be compromised. <strong>You should also ensure you remove any components (including the files themselves via FTP) for any extensions you are not using.</strong></p>
<p>6. It might seem like an obvious one but ensure your web hosting provider is keeping up with their responsibilities. Ensure they are keeping PHP and other software on the server updated (nobody should be running PHP4 anymore as it is now “End of Life” and potentially open to security issues), ensure they are running their operations in a secure way (PHP in CGI mode with su_php as noted above) and ensure they are taking steps to help ward off attackers by running modules like <a href="http://www.modsecurity.org/" target="_blank">mod_security</a> under Apache and open_basedir under PHP. Having mod_security on your server can help to stop a lot of XSS attacks against your Joomla! install getting through, but it can’t stop them all so you still need to ensure you keep up with your Joomla! security updates.</p>
<p>7. Ensure you are setting secure passwords for both your Joomla! administrator user but also your web hosting account control panel and FTP logins. It would be a real shame to have spent lots of time securing your Joomla! install to then let an attacker in through a weak password. I recommend a password that is at least 8 characters in length and containers letters (both upper and lower case), numbers and at least one symbol. Also ensure your passwords do not contain dictionary words. Using a <a href="https://www.grc.com/passwords.htm" target="_blank">password generator</a> is a good idea.</p>
<p>8. Another useful tip I can share with you is to <strong>password protect your Joomla! /administrator directory</strong>. You can do this under an Apache web server using a .htaccess file and if you are a Rochen customer this can be easily configured using the &#8220;Password Protection&#8221; option within your control panel. By password protecting the /administror directory you will have to enter a username and password prior to reaching the Joomla! administrator login page. It means that even if your Joomla! admin password is stolen then your site is still largely protected since the attacker will not be able to reach your administrator login page. Remember, it is important to use a diffrent password on the /administrator directory than you do for your Joomla! admin password or it defeats the purpose of doing this.</p>
<p>9. Last but not least, and probably most important, you need to ensure you keep your Joomla install itself fully updated with the latest security patches from Joomla. You also need to ensure you keep all of your extension installs updated too. <strong>Remember, even if your Joomla install is updated having even one insecure extension can allow your site to be compromised.</strong> You should subscribe to the <a href="http://feeds.joomla.org/JoomlaSecurityNews" target="_blank">Joomla Security Mailing List</a> as well as the mailing lists maintained by the developers of third-party extensions you have installed. If you are using an extension from a developer that doesn&#8217;t maintain a security mailing list, then question them why. It is something all developers should be doing.</p>
<p>So, if you have read this far down the blog post, then you might be happy you did because I am pleased to provide you with a Rochen promotional code: joomlasecurity. Simply enter this during the Rochen ordering process and you will receive 15% off your first month’s hosting for any of our plans. This coupon is good through to the end of October 2008. We don&#8217;t issue many coupons, but when we do they will be in sneaky places like this. Who ever said reading blogs while you should be working wasted money?</p>
<p>One other thing worth mentioning. If your Joomla! site hosted at Rochen is hacked then you can easily roll your account back within a few minutes to points in time over the past 30 days using our <a href="https://vault.rochen.com/" target="_blank">Rochen Vault recovery system</a>. Simply login, select the files you want to restore and boom – your site is rolled back to an unhacked state. You do of course then need to secure the site otherwise it will simply be hacked again, but if you follow what I have outlined in this post then your Joomla! powered sites being hacked should be a thing of the past.</p>
<p>If you have any comments, questions or better yet security tips of your own then please leave a comment under this blog. Thanks for reading and I hope you have found some of the tips useful.</p>
<p><span> </span>- Chris</p>
<p><em>Chris Adams is the Founder and CEO of Rochen, a web hosting provider specializing in providing a performance tuned hosting platform for dynamic database driven scripts like Joomla! Rochen has hosted all of the official Joomla! websites since the project began in August 2005.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rochenhost.com/2008/09/joomla-security-ever-been-hacked-sorting-fact-from-fiction-some-useful-joomla-hosting-tips-including-some-you-might-now-know/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
	</channel>
</rss>

