There is no excuse for this one. If you have a large website with dozens or hundreds of pages, give me an internal search box to find what I need.
We are all getting used to the search being a given feature, in fact Joomla sites come with this as standard.
Google and Yahoo! and many others will give you the tool - free - to put on your site.
Use it.
Online marketing blog by Stuart Gow aimed B2B for small to medium operators looking for a cost effective and measurable way to use their marketing funds!
Showing posts with label joomla. Show all posts
Showing posts with label joomla. Show all posts
4 Aug 2007
19 Jul 2007
Help! My site's CMS has been compromised. Now what?
Directions
- Change all relevant passwords
Assume your passwords have been harvested and immediately change all critical passwords, including shell access, FTP access, Joomla! Administrator accounts, and the database account. - Check raw logs
Identify when and how the attackers gained access to your site by carefully reviewing your raw server logs. Make careful note of the date/time and names of attacked files. Note that these logs may have been deleted or altered, so a lack of evidence does not prove a lack of activity. - List recently modified files
Before making any changes to your site, generate a list of recently modified files. Here's a php script that will list the files for you. Remove this script as soon as you have your list and don't publish a link to it! - Note suspicious newly-created files
Use this list to identify new files that don't belong. Pay particular attention to their creation and modification dates, and correlate them to the dates of attacks shown in your log files. - Note suspicious recently-modified files
Check the modified files list for any files that were recently changed. Pay particular attention to the modification, and correlate them to the dates of attacks shown in your log files. - Coordinate with your host
If you have identified how you were cracked, report the method to your host. If you are on a shared server, you may habe been attacked through another vulnerable site on your server. Report this to your host. A reputable host will appreciate your efforts in this area. - Delete the entire public_html directory
This is the best way to guarantee that every potential vulnerabililty in that site is removed. - Delete related database records
This step may only be possible if you have good backups. Simple script kiddies, who are only trying to mark your index page, may not attack your database, but professionals are usually very interested in confidential data, such as passwords. They may pose as script kiddies to avoid suspicion while repeatedly harvesting confidential information from your database. - Reinstall everything
Use pre-crack backups. If you don't have good backups, go on to step 10. - Reset critical passwords again
You must reset your passwards again now that your server is finally cleaned of any possible, hidden trojan horses. - Rebuild site: If you are unable to rebuild from clean backups, rebuild your entire site using original, pre-crack installs. Use only the latest stable versions of all software, and check the List of Vulnerable Extensions
- Review security processes
Follow standard security precautions for important settings in php.ini, globals.php, configuration.php, .htaccess, etc. - Review backup processes
If you don't already have one, add a dependable backup process to your site administration practices. - Stay watchful
Attackers often return repeatedly. Closely monitor your raw logs for suspicious activity.
24 Jun 2007
Top Ten SEO Joomla Tips
The Top Ten Joomla Search Engine Optimisation tricks you should perform once you have installed Joomla Content Management System! Learn what the Joomla Development Experts do to get Joomla SEO ready!
- Install the SEF Patch
- Install and configure JoomSEF or other SEF URL transalation component for use with Joomla. JoomSEF Latest Version
- Change the title of Joomla to use title alias - helps for Admin purposes
- Identify 30-40 keyword phrases using Google Adwords & Yahoo Overture.
- Optimise frontpage title for your top 3-5 keyword phrases
- Sprinkle these top keywords through meta tags and content on frontpage
- divide up the other keywords into 3-4 groups and optimise other pages for these keywords.
- Unique page titles, meta descriptions, meta keywords, page content.
- Divide up the page content with appropriate page headings using H1, H2, H3 etc tags
- Use appropriate page names in JoomSEF. ie: website-design.html & website-development.html
Subscribe to:
Posts (Atom)