From Joomla! Documentation
This security list has been compiled from several sources. Some of these sources are linked at the bottom of this article. As such you may find duplicate suggestions. DON'T skip anything because of this!
This list for the main part does not provide instructions. It is only a list for you to check off each item as you perform the tasks.
I know this list will generate MANY questions; please post to the joomla.org forum: http://forum.joomla.org/viewforum.php?f=432&sid=81c2aa9b5a4a88574ae79a6b176111cc
- Change username "admin" to anything else in Joomla, PhpBB, and anywhere else it used.
- Change database tables prefix from "jos_" to anything else.
- Change username or add password to username "root" in PhpMyAdmin. Default is NO password! This is not usually an issue on remote servers however if you have a local server it may be.
- It does not matter if your host does backups. Do it yourself too, and store them anywhere else other than the server.
- Backup up often! You would be amazed at how many site owners never perform regular backups. Don't be one of those persons.
- Test your backup. Verify that your backup procedure works.
- Remove unused templates, extensions and unneeded files from your site. This includes compressed archives.
- Check joomla.org Vulnerable Extensions List (VEL)
- Check regularly for updates for Joomla, PHP, SQL and EVERY extension you use.
- Avoid encrypted code in extensions.
- Use some form of intrusion detection either through a cron job or an extension (like Eyesite).
- Check your log files OFTEN for unusual activity.
- Test your site for weaknesses or hire someone to perform this for you. Make sure you tell your host first what you are doing or you may get your site removed from the server!!!
- Ask your server if they offer PHPsuExec, php_suexec or suPHP.
- Use php.ini files if your server allows. With this you can disable functions that are not needed or dangerous.
- Register_Globals = 0 (off) Many servers default this to ON.
- allow_url_fopen = 0 (off)
- expose_php = 0 (off)
- safe_mode = 0 (off)
- Use .htaccess to add extra protection to your administrator directory or use an extension (like kSecure).
- Move configuration.php outside of your public directory.
- Get an SSL certificate for financial transactions and other sensitive data exchange.
- Use open_basedir. It limits which files/folders can be opened.
- Change the paths (directories) where your log, temp (tmp) files are stored. Don't just move them, you have to change the setting in Global Config as well. You also have to ensure your new paths fall under the scope of open_basedir.
- If your administrator password is changed by hackers (or you forget it) follow this procedure to restore it: http://docs.joomla.org/How_do_you_recover_your_admin_password%3F
7 Great Tips from Marco Folio (Some with instructions): http://www.marcofolio.net/joomla/7_tips_to_optimize_joomla_security.html
How to prevent an SQL injection by Marco Folio: http://www.marcofolio.net/features/how_you_can_prevent_an_sql_injection.html
Joomla Security Primer by Tom Canavan: http://www.howtojoomla.net/how-tos/security/joomla-security-primer
Joomla.org Security Checklist Wiki: Security Checklist
Joomla.org Vulnerable Extensions List: Vulnerable Extensions List