How to block Administrator Page from outsiders' access?

Discussion in 'Joomla' started by toototoo, Mar 29, 2010.

  1. #1
    Hello,

    I'd like to block outsiders/hackers to access to my joomla admin page (www.mywebsite.com/administrator). Currently I am using "Restric IP address" system. But as my internet IP address is changed oftentimes, it is painful to go and allow the new IP whenever there is change. And now I am looking for a different way of blocking the administrator page.

    please help.

    Many Thanks.
     
    toototoo, Mar 29, 2010 IP
  2. JoomlaDesigner

    JoomlaDesigner Active Member

    Messages:
    956
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    60
    #2
    You can password protect that directory.
     
    JoomlaDesigner, Mar 30, 2010 IP
  3. PalladiumHosting

    PalladiumHosting Peon

    Messages:
    29
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #3
    PalladiumHosting, Mar 30, 2010 IP
  4. sugank

    sugank Member

    Messages:
    202
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    28
    #4
    try to install JSecure Authentication module to your joomla site.
    you can see about it here:D
     
    sugank, Mar 31, 2010 IP
  5. TooMaxi

    TooMaxi Peon

    Messages:
    39
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    hey..
    you can also get it from ( joomlaserviceprovider.com/component/ambrasubs/file/view/5/7.html ). just register and download it. very good one. i tried and like it. Inside the zip file try to read Readme file so that you know how to setup. Don't also forget to oftentimes update your access keys which are to be made in your secret characters/numbers.
    Good Luck..
     
    TooMaxi, Apr 1, 2010 IP
  6. toototoo

    toototoo Peon

    Messages:
    49
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    thanks.. everyone.
     
    toototoo, Apr 8, 2010 IP
  7. freei

    freei Peon

    Messages:
    27
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    I recommend password protecting the directory. jSecure is also good, but a pain when you want to uninstall.
     
    freei, Apr 8, 2010 IP
  8. threads

    threads Peon

    Messages:
    36
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    cant you just uninstall jSecure /???? how hard can it be? cause i was about to buy that component , its only like 5 dollars. httaccess file password protect should work.
     
    threads, Apr 9, 2010 IP
  9. freei

    freei Peon

    Messages:
    27
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    not that simple, you may have to delete tables in your MySql db. I suggest reading a few forum posts on joomla's forum before buying or adding any extension. I agree about the htaccess pass protect. In addition, great unique passwords will probably work just fine. Unless you're getting serious traffic and dealing with large sums of money you should be fine, but if you're BIG TIME, who's dealing with development? All the best.
     
    freei, Apr 10, 2010 IP
  10. Blue Star Ent.

    Blue Star Ent. Well-Known Member

    Messages:
    1,989
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    160
    #10
    If you are concerned about someone breaking into your admin account at the joomla "back door", the strength of your password will make or break the event. Obfuscating can be used, but a simple creation of a powerful password is your first line of defense. Plus, did you know you do not have to use "admin" for the username ?
     
    Last edited: Apr 10, 2010
    Blue Star Ent., Apr 10, 2010 IP
  11. threads

    threads Peon

    Messages:
    36
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    yeah that is a good point. disable the admin account like you would do on your wireless router or computer. Make a new account that is super administrator and use that instead . Also perform all the other Joomla security suggestions on the site to make sure your secure. Also always keep your site updated.
     
    threads, Apr 12, 2010 IP
  12. xhmaker

    xhmaker Member

    Messages:
    80
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    41
    #12
    have you ever try to change Joomla admin folder And disable site/administrator ?. I think that's best way to solve this problem
     
    xhmaker, Apr 12, 2010 IP
  13. threads

    threads Peon

    Messages:
    36
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #13
    change the folder nope . I thought that would be too complicated to change . You would think quite a bit of joomla would be pointing to files in that folder . Sounds like something that should be made to move the directory around easier .
     
    threads, Apr 12, 2010 IP
  14. freei

    freei Peon

    Messages:
    27
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Blue Star nailed it. Change your admin username and create a powerful password. Simple.
     
    freei, Apr 13, 2010 IP
  15. prasxz

    prasxz Peon

    Messages:
    392
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #15
    you can rename administrator folder to whatever you want
     
    prasxz, Apr 13, 2010 IP
  16. threads

    threads Peon

    Messages:
    36
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #16
    ill have to test that out, at least on a site i can risk it on . I would think it would start something to stop working just by renaming it. Never heard of that trick before . I guess then rename it back when you upgrade .
     
    threads, Apr 13, 2010 IP
  17. whiteeaglet

    whiteeaglet Peon

    Messages:
    175
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #17
    My site was hacked long time ago.
     
    whiteeaglet, Apr 15, 2010 IP
  18. prasxz

    prasxz Peon

    Messages:
    392
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #18
    or you can find any security module from joomla extension
     
    prasxz, Apr 15, 2010 IP
  19. aka_le_Mulder

    aka_le_Mulder Member

    Messages:
    232
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    35
    #19
    What about .htaccess file? As far as I know you can make your admin panel available only from IP you want and all the rest will see 404 page.
     
    aka_le_Mulder, Apr 16, 2010 IP
  20. corinaw

    corinaw Not Banned

    Messages:
    486
    Likes Received:
    69
    Best Answers:
    0
    Trophy Points:
    0
    #20
    Install guardxt. http://extensions.joomla.org/extensions/access-a-security/site-security/7013
    It helps with protecting your site in many ways and has wizards to assist in security concerns:

    1. change "admin" login to another name- like your dp logon name "toototoo"
    2. password protect the admin directory via htaccess (guardxt wizard does this)
    3. change joomla db prefix from jos_ to another prefix_
    4. add "Options All -Indexes" to your htaccess if it is not there already

    Install jsecure such as TooMaxi suggested here: http://joomlaserviceprovider.com/component/ambrasubs/file/view/5/7.html then you have 2 passwords to secure your admin page. Anyone trying to access my admin page without the jsecure password is redirected to the main site.
     
    corinaw, Apr 16, 2010 IP