In the course of most months the focus is on creating interesting new features to add to Joomla web sites, building system automations to connect Joomla/Odoo/Telphony and other systems, and keeping an eye on the many web sites we manage. But the past few weeks have been completely different.
It all started in May...
A huge security vulnerability in a 3rd-party Joomla extension that is (or was) installed on a large majority of Joomla sites started the whole thing. Before that we might see one or two vulnerabilities reported each month. But after that first one, and several subsequent vulnerabilities reported for that same extension, the flood-gates were opened.
There have been times when there have been multiple vulnerabilities reported in the same day. Hardly a day went by for a while when we didn't have a new vulnerability reported.
Regular updating / patching
Most of the vulnerabilities were reported to the developers and they had patches released before the vulnerabilities led to active compromises of Joomla sites; however, this entire experience has made it very clear how many Joomla sites aren't regularly maintained. It's also becoming clear how many sites were set-up with Joomla 3 and never upgraded - even though Joomla 3 was end-of-life three years ago and is no longer receiving security updates.
Unfortunately, it is all too common for a business owner to pay someone to set-up their Joomla web site and then just expect it to be functional for years without any regular maintenance and updates. There have been many posts written trying to encourage those people to make it a priority to get their Joomla sites updated. Well many of those people now learning the hard way that they should have listened and followed that advice.
Don't do this yourself
If you are a business owner and have a Joomla (or any CMS*) web site that you manage yourself, I can honestly say it might be time to re-consider that decision. Although there are some tools out there that will help you with the process, the tools just make it easier to DO the process of updating. Blindly installing every update is not always the best solution for 3rd party extensions. You have to know what changes were made to ensure it doesn't break your site.
Also, some of these vulnerabilities of the latest compromises effect the web site's server in ways that can not be fixed by a simple script. And if you have multiple web sites that you host on the same server, one site can potentially effect others on that same server.
This can all require a LOT of time to get things back to where they were before. And if you don't know Joomla (and web server) best-practices AND follow them, you will be likely hit again in the not too distant future.
*This does NOT just effect Joomla web sites. The level of security issues on WordPress has historically been significantly higher in 3rd party extensions to that site, and most other CMSs have had their share of security issues increase since AI has been available to malicious parties.
Why are we effected ... didn't we protect our sites?
I mentioned that we were busy with updating and securing all the sites we manage; however, our time was not spent de-hacking our client sites**. It was spent with the ever-repeating process of upgrading extensions or completely removing ones that we considered a serious ongoing security risk.
**We did experience the hacking ourselves on a couple of our less-used internal sites, partly due to the speed at which one of the vulnerabilities was compromised, but mainly because we prioritized keeping client sites secured over our own.
With the exception of that, none of our client sites suffered the fate of so many sites that were not regularly maintained and updated.
As noted, some of the steps taken were not Joomla-specific but systems hardened at the server level. Because we manage all of our own servers, we have complete control of the entire security window. Although there are some good hosting companies out there, most have many thousands of clients, all of which may be asking for help during a large attack like some of these. We avoid that by just handling it ourselves.
How we have experience actually de-hacking
Although we have not had to 'de-hack' any of our client's web sites during this latest round, we have been busy with web sites that have been hacked. We regularly get new clients whose web site fell victim to one of these recent vulnerabilities. In fact, a good portion of our clients have come to us over the years because their site was hacked or had serious vulnerabilities and needed to be protected before it got hacked. This has kept us busy over the years, as well as quite busy over the past few weeks.
How we can help you avoid downtime
Because we actively monitor every aspect of each Joomla site we manage, down to the server itself, we not only get alerted to potential issues before they become a significant problem, we can actually take action immediately when needed. This has led to 99% up-time (excluding scheduled maintenance) for all of the sites we manage for many years.
We do this by offering a monthly service that covers all the regular maintenance of each web site. You don't have to wonder if any specific vulnerability could bring your web site down, and you don't have to wonder if you will wake up to a hacked web site some day. And if you do have a concern, you can drop us an email or pick up the phone and call.
There are other services that can de-hack your site, as well as provide you with some level of on-going base security automation; however, we aren't just an automation service. We directly work with you to not only provide you with a stable Joomla site that has 99% up-time, we are there to help you make changes to the web site so that it grows with your business and effectively adapts to the Internet changes to be a key asset for your business.
Set-up a time for us to talk about how we can help you secure your site now and into the future.
