• 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!

TOPIC: .htaccess protection?

.htaccess protection? 14 years 6 days ago #10389

  • wirecreative
  • wirecreative's Avatar
  • OFFLINE
  • Junior Boarder
  • Posts: 21
  • Thank you received: 2
Hi,

I have a site that gets attacked by hackers once every few months, specifically targeting Joomla files. Last week I installed RSfirewall and fixed a bunch of permissions problems.

However, it got hacked again today. Turns out this time instead of replacing various Joomla files like they usually do, they replaced the htaccess file.

Would it be possible for RSFirewall to also make note of changes to and permissions for the htaccess file, even though it's outside Joomla? It would be great if it could take a snapshot of the file and note changes. I probably would've have discovered the source of the problem a bit earlier if this was under its scope.

Installing RSFirewall last week probably saved some of the joomla files, however, as the pattern of this attack was similar to the previous ones and there was as usual a bogus "copyrights.php" file in the root. It would be nice to be able to keep hackers totally out of my root directory.
The administrator has disabled public write access.

Re:.htaccess protection? 14 years 6 days ago #10395

  • alexp
  • alexp's Avatar
  • OFFLINE
  • RSJoomla! Official Staff
  • Posts: 2253
  • Thank you received: 180
Hello,

Unfortunately there is no real way of keeping track of changes made on the htaccess file, since this is used to perform all kind of settings.

We currently have on our TO DO list a feature that will take into consideration the htaccess file also.

It would be best to also follow the security points stated on our blog:

http://www.rsjoomla.com/blog/joomla-website-hacked-what-s-next.html
Please note: my help is not official customer support. To receive your support, submit a ticket by clicking here
Regards,
RSJoomla! Development Team
The administrator has disabled public write access.

Re:.htaccess protection? 13 years 11 months ago #10551

  • jwhite47
  • jwhite47's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 7
What about changing the file from .htaccess to something else within httpd.conf file? That why it will trick or at least slow down the hackers.


I never tested this but I think its worth a shot.

Regards,
John.
The administrator has disabled public write access.

Re:.htaccess protection? 13 years 11 months ago #10602

  • hayatta
  • hayatta's Avatar
  • OFFLINE
  • Junior Boarder
  • Posts: 20
jwhite47 wrote:
What about changing the file from .htaccess to something else within httpd.conf file? That why it will trick or at least slow down the hackers.

That's a good idea, I also wonder how.

By the way, have you tried adding .htaccess to the "Monitor the following files for changes" list?
It might work.
The administrator has disabled public write access.

Re:.htaccess protection? 13 years 10 months ago #10675

I did set the userrights to 444 for .htaccess, so it is only readable. If you need to change it, you can put the userrights to 644 to change the content and set it back to 444.
The administrator has disabled public write access.
  • 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!