0
Welcome Guest! Login
0 items Join Now

ROCKETTHEME IS CLOSING ON JUNE 30, 2025. As a thank-you to our community, enjoy 50% off all themes with the promo code THANKYOU before we shut down. Read our Farewell Blog Post for more details.

Hackers scanning websites for logins

    • Tyndie's Avatar
    • Tyndie
    • Preeminent Rocketeer
    • Posts: 8804
    • Thanks: 5

    Hackers scanning websites for logins

    Posted 15 years 3 months ago
    • Hi,

      I have picked up a few failed attempts from a hacker trying to access my admin section using a login and password that I changed a few weeks ago, is there a way of preventing someone from scanning posted form variables for logins?
  • Re: Hackers scanning websites for logins

    Posted 15 years 3 months ago
    • What is a "posted form variable"? Sorry, don't know the web lingo much.
    • drsawbones's Avatar
    • drsawbones
    • Sr. Rocketeer
    • Posts: 154
    • Thanks: 0
    • Joomla Adict

    Re: Hackers scanning websites for logins

    Posted 15 years 3 months ago
    • Hello,
      I use a couple techniques for hiding joomla's admin.
      The first thing I install on a live site is this one:
      extensions.joomla.org/extensions/5809/details

      it's a tiny joomla! plug-in that adds ?WoRDxXx to the end of your admin path.
      joomla/administrator/index.php?WoRDxXx
      for example - if you don't enter the exact path it kicks you back to say - home page of site.
      Make sure you read the documentation before enabling it so you don't lock yourself out. (and if you do, you can change the path-word via phpmyadmin mysql edit.

      I also install SSL and use https for admins accessing the ACP.

      If you have money to invest in security - RS Firewall is pretty slick component
      extensions.joomla.org/extensions/access-...y/site-security/8968

      Regards,
      Doc
    • Tyndie's Avatar
    • Tyndie
    • Preeminent Rocketeer
    • Posts: 8804
    • Thanks: 5

    Re: Hackers scanning websites for logins

    Posted 15 years 3 months ago
    • Thanks, I have RS Firewall, but what concerned me was that they managed to get a user and password that i only changed not long ago. I think i will invest in ssl thanks :)
    • Terp's Avatar
    • Terp
    • Elite Rocketeer
    • Posts: 1720
    • Thanks: 23

    Re: Hackers scanning websites for logins

    Posted 15 years 3 months ago
    • drsawbones wrote:
      The first thing I install on a live site is this one:
      extensions.joomla.org/extensions/5809/details

      I second this one...great extension to use to redirect anyone not using the ?key when trying to access the administration screen. :)
    • JEM's Avatar
    • JEM
    • Preeminent Rocketeer
    • Posts: 17917
    • Thanks: 4

    Re: Hackers scanning websites for logins

    Posted 15 years 3 months ago
    • Tyndie's Avatar
    • Tyndie
    • Preeminent Rocketeer
    • Posts: 8804
    • Thanks: 5

    Re: Hackers scanning websites for logins

    Posted 15 years 3 months ago
    • ok thanks :)

Time to create page: 0.060 seconds