What is Joomla and a WAF?
Joomla is a popular free program for building websites. Because so many sites use it, attackers often look for old or weak Joomla sites.
A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF reads every visit to your site and blocks the ones that look like attacks. It does this before they reach Joomla.
Before you start
Make a full backup of your Joomla files and database. A database is a digital filing cabinet where Joomla keeps your articles and users.
Steps
- Turn on the WAF. In cPanel, open Security, then ModSecurity. In Plesk, open Tools & Settings, then Web Application Firewall. Switch your domain to On.
- Make sure the server uses a rule set such as OWASP. Ask Hostvento support if you are not sure.
- Open your Joomla site and click around. Log in to the Administrator area. Save an article. Check that nothing breaks.
- If the WAF blocks a good action, read the WAF log. Note the rule ID. Ask support to add an exception for that rule on that page.
Add Joomla-specific protection
- Update Joomla. In the admin area, open System, then Update. Install new versions of Joomla, extensions and templates. An extension is an add-on, like a plugin.
- Remove extensions you do not use. Old add-ons are a common way in.
- Turn on two-factor login. Go to Users, then Manage, open your user, and set up multi-factor authentication. It asks for a code from your phone as well as the password.
- Use a strong password for each admin account.
- Rename or limit the admin user named
admin. - Turn on Force HTTPS in System, Global Configuration, Server. HTTPS encrypts traffic between visitors and your site. You need an SSL certificate first.
Limit access to the admin area
If only you log in to /administrator, you can allow only your own IP address in .htaccess. Add a rule in the administrator folder:
Require ip 203.0.113.5
This allows only that address. Replace it with your own IP address. If your IP changes often, do not use this rule.
.htaccess file first.Need help? Open a support ticket.
Quick recap
- A WAF blocks attacks before Joomla sees them.
- Turn ModSecurity on and test your site.
- Keep Joomla and all extensions updated.
- Use strong passwords and two-factor login.
- Back up before every change.