Skip to content
Joomla

Joomla! Under attack?

Team Host.it 3 min read

Content

These are hot days for the most used in the world (Joomla!), it's been several hours since the number of BRUTE FORCE towards the administrator page in the world has increased exponentially.

What is a BRUTE FORCE? These are attempts to access (brutally) the administrator page of our Joomla! site, the one accessible at www.dominio.it/administrator/index.php so to speak. Dozens of attempts per second with the sole aim of "getting the password right", sometimes very simple, and then installing malicious plugins to carry out SPAM, DDOS, or other attacks around the world.

There are real "crews", called CREWs, who come together around the world to destroy as many websites as possible, to create global attack resources. Science fiction? Everyday life... And those of us who work as hosts are faced with new types of attacks every day to defend ourselves from. Our natural inclination towards Joomla! it leads us to be much more dedicated and focused on security, so our customers can deal with site management and not emergencies.

My site is unknown why would they attack it? It doesn't matter whether your site has 1 visit or 100,000, if it's online, rest assured that it will be targeted.

First of all we ALWAYS recommend protecting the /administrator folder of your Joomla! site. to do this we recommend a free component that you can download at this link: http://extensions.joomla.org/extensions/access-a-security/site-security/login-protection/15711

Why is the choice of hosting important for security? Hosting services are not all the same and it is precisely in these days of "attacks" that the differences are visible.

Here are some numbers relating to brute forces towards Joomla! sites hosted by Joomlahost

01 Mar 411,000 02 Mar 372,000 03 Mar 354,000 04 Mar 330,000 05 Mar 168,000 06 Mar 576,000 07 Mar 239,000 08 Mar 2.6 MILLION 09 Mar 4.5 MILLION 10-Mar 4.4 MILLION

These are all brute force attempts correctly blocked by our traffic inspection systems, without which they would have been successful with the following causes:

unwanted traffic on the website

slowing down browsing for users

steal of login credentials (very high %)

probable disservice for users of the website

It goes without saying that an e-commerce site cannot afford to suffer slowdowns or malfunctions and just protecting your folder is not enough, because on a shared hosting service, you can never know how many other sites there are on the same server and how they are managed.

This is why at Joomlahost we apply upstream protections to protect ALL our customers, our aim is to let them live the WEB experience with Joomla! in the simplest way possible.

Joomlahost has a team of experts who analyze malicious activity towards Joomla! sites on a daily basis. and creates ad hoc protections. It's an invisible job that customers don't see but appreciate in the long run, when they realize that other sites they have with non-certified Joomla! they suffer many more attacks, disruptions and slowdowns.

To discover the world of Joomlahost.it, take a tour of our website www.joomlahost.it and discover our hosting services for Joomla! .

Joomla hosting

Joomla hosting in Italy

Plans with backups, SSL certificates and tools for developers and agencies.

From the blog

WordPress

WordPress 7.0 e l’AI

Cosa cambia per le web agency

Sicurezza

Patch a caldo, sito acceso

CVE kernel senza riavvii a raffica

From the archive

Joomla

Why Host.it chose Joomla 4 as its frontend

Joomla

Data Protection Day - The importance of Privacy and Security