The Joomla! Extensions Directory ™


jHackGuard Plugin

Editor's Note
  • This extension requires registration to download.
  • Includes visible backlink
jHackGuard is designed by SiteGround to protect Joomla websites from hacking attacks. Just add it to your Joomla and it will be safe against SQL Injections, Remote URL/File Inclusions, Remote Code Executions and XSS Based Attacks!

This plugin has been successfully used by SiteGround customers during the past few years. Now we make its latest version public, so that you can easily protect your Joomla site. All you need to do is to install jHackGuard and enable it – no additional configuration needed!

Report

2011-12-31
Reviews: 51
Very well written plugin. I had issues removing the watermark (Link Back to SiteGround) in the previous version, however that has been taken care in the latest release. There is now an option under the configuration of the plugin "Link back to SiteGround" which can be set to On or Off which makes it easy to manage the link back shown in the home page without having the need to touch the code.

Thanks SiteGround. You Guys Rock.

Regards
Syed
2011-11-25
Reviews: 9
Been using this on J1.5 and it was great, but now that i have moved over to 1.7 its a complete mess.

As brian mention, it filters out extremely common words, i have tried the latest 1.2.1 version and it has not sovlved the problem, we have a social network with public bloggers and no matter where you want to use the word union, front-end or back, user level irrespective it removes the work or that part of any word containing it.

Even tried posting it as my status in JomSocial and as a super admin it would not let the post succeed. They are completely delusional if they believe they have solved the problem.
Owner's reply

Hello,

We have tested the plugin and we can confirm that the version for Joomla 1.7 no longer filters in any way content added by users that have access to the administrative area. To make sure that the latest version of jHackGuard is used please completely remove your current instance of jHackGuard, download it anew from our website and install it.

As to the JomSocial component, it allows users without access to the administrative area to create and publish content to your website. This behavior triggers the jHackGuard security checks and if anything suspicious is found it will be blocked. Our plugin utilizes the same logic in both Joomla 1.5 and Joomla 1.7 versions. This means that posting "union" through a JomSocial component will be filtered in all Joomla versions. Note that the majority of the MySQL injections work using precisely this command to execute unwanted queries to your database. For example, if someone posts 'and1=1 UNION select * from jos_users' and your comment extension is not written securely, this will return everything in your jos_users table. Through this command if an attacker find such security hole he/she can execute literally every query he/she wants.

We also plan to develop further the plugin and converting it to a component that utilizes the new Joomla ACL system. This will allow each user better control over the security checks to be applied on his/her website.

1 of 1 people found this review helpful
2011-11-17
Reviews: 13
I've seen some bad extensions but this one really takes the biscuit.

The extension is so badly coded that it tests for things without checking without checking the context

For example it is impossible to write an article about a trade union as the extension removes the word union

Or to write the word concatenate as it removes the characters concat

Or to write a basic tutorial about joomla as it removes common terms such as jos_users.

Removing any of these from your content is just plain stupid!!!!
Owner's reply

Thank you for reporting these issues with jHackGuard in Twitter last week. We have tested and found that there was really a flaw in the jHackGuard version for Joomla 1.6 and 1.7, which was fixed and the new version of the plugin was uploaded yesterday.

Our plugin is originally designed to check whether the user submitting information to the site has admin privileges or not. By default only if the user has NO admin privileges we look for patterns for SQL injections and other hacking techniques and block posts containing such patterns in order to prevent the site from being hacked. Unfortunately, due to a slight modifications in the latest Joomla versions, the check whether an user has admin rights or not wasn't working correctly. This is why you were unable to post articles containing content that you've mentioned as your posts were block by mistake.

You can download the plugin again from our site and give it another try. I believe that you will find it useful and working as expecting to protect your site from hacking attempts. Of course any bug reporting or improvement suggestions are more than welcome!

2011-09-22
Reviews: 1
I have made many Joomla website over the years. About 1 year ago some of the many sites I designed started getting hacked from the outside. I did some research and found the "jHackGuard" plug-in.

I have installed it now on 5 websites I have created and they are all secure. (or seem to be)

On my personal Joomla website I have tried several other Admin tools, so that in the future (If one of my clients get hacked) I have other things I can do to help them out. Thanks to all the programmers who make these Extensions for Joomla! (Non-Commercial)
2011-09-20
Reviews: 3
I have installed this extension on site that requires great and full protection. Now, after 6 months after installation, I can make full review of this excellent extension. First, it WORKS. Second, it works PERFECTLY. It stops hackers completely. And logs are great help too, btw. Thank you. Thank you from the bottom of my heart. This is a MUST HAVE on every joomla installation.
2011-07-26
Reviews: 1
this plug in makes my site out of reach even in joomla administrator!!!! so I could not uninstall it. so I was obligated to remove plug in from directory!!!
2011-07-02
Reviews: 2
Okay, I know that unless my site gets hacked I really don't know how well this works. However, with that understanding, it installed well, that is, after I disabled my "register global" in my php.ini file. I use Hostgator and they require it turned off thru the php.ini file. They tell you in the forums that you should have register globals disabled because, really, without it - any security add on is really useless. I believe them so mine is disabled! Anyway, thanks for the plugin, I'm trusting it will help keep my client's site safe (especially since it is going to be hosted on Siteground's server - the guys who wrote the plugin)
As far as the footer, just take it out of the plugin file. I didnt mess with the php code, just the html section that puts it in there.
2011-06-26
Reviews: 6
Can't really rate this except to say that it caused my site to go offline with errors. I guess I'm not allowed to post the error message here but I did see that's it's a common problem in their forum. Apparently it's incompatible with something on my site. Too bad, I would have like to use it. Linkbacks is not something that would prevent me from not using an extension, they are too easy to remove. Some of you really should take some online HTML, CSS, and PHP courses, many of them are free and you'd never have to complain about linkbacks...just remove them!
2011-02-21
Reviews: 3
The thing that i find with these type of plug ins, is that you never really know if it is installed correctly, but i guess it did. the only thing is that i see people have commented about the backlink, but i'm not seeing any back links at all?? other than that, the installation and setup was really easy with only one section to set up to your specific requirements. i think it was great :)
2011-02-16
Reviews: 2
It takes what the title says to install it. Just download the plugin, upload and enable it. Well, another 5 seconds (as already said) to remove the footer.

The worst thing fo this plugins are that you don't notice if they are beeing useful, as the block the own problems that make you need them! :P

Thanks for publishing the plugin guys!
2010-10-16
Reviews: 4
just enable and that's it!!

as for removing the "joombla extension by siteground" water mark at the bottom of the front page..


as stated by CarlG (a few post below)...

but it's gest if you use remove the URL and the text

and leave the codes be!!! since if you remove the codes.. you site will not even load!!!

my advice to remove the watermark is

1- copy and paste your codes into a txt file before doing anything.. so if you messed up.. you can just re-paste them

2- if you want to remove the trademark of the front page..

remove THE URL and the TXT in the Replacement line

so what you looking for is

www.siteground.com and joombla extensiones by siteground..

or soemthing like those two within the $replacement =

that's all
2010-09-19
Reviews: 13
Easy install. Just do what the other reviewer recommended to remove URL on front end pages. Took about 5 seconds.

Thanks so much for this FREE security extension!
2010-09-13
Reviews: 3
This extension is released under the GNU public licence... therefore, that means you can modify it according to your needs... You can remove the publicity by removing these lines in /plugins/system/jhackguard.php

function onAfterRender() {

$output = JResponse::getBody();
if (!(preg_match("/sgfooter/", $output))) {
$pattern = '//';
$replacement = "Secured by Siteground Web Hosting";
$output = preg_replace($pattern, $replacement, $output, 1);
}
JResponse::setBody($output);
return true;
}
2010-09-08
Reviews: 1
About plugin: this is exellent plugin to protect Joomla.
About footer link :) you can remove it, if dont like it.Problem is that people dont know where to remove and try to tell bull thinks like that first review about footer link and some charge $49.
:) dont be stupid, this plugin cost free, no body ask about money, use it and be happy of FREE...
2010-09-06
Reviews: 3
Was disappointed with this as once installed an 'Extensions by Siteground hosting' link appeared on every page and even in the backend!

When I uninstalled the plugin it was still there and they wanted to charge $49 to advise how to remove it!!
Owner's reply

Hello,

We have extensively tested the plugin and we can guarantee that the link does not stay after the plugin is uninstalled. I would guess that you have some cashing extension that causes this problem with your particular websites. However, we cannot say for sure without testing it on your website.

We would like to thank you, however, for the feedback about the backlink to our website. We have added this token of appreciation since it is a standard practice amongst such extensions but we will consider making it optional for the next versions.

1 of 1 people found this review helpful
2010-08-28
Reviews: 16
This is a great, anti-hack (or anti hacker) security plugin.

However, I agree with everyone here who said that the back link is simply cheap, and makes the developers look more greedy than credible. Should be an option.

Note to the JED Team:

Please consider reviewing your criteria for a non-commercial plugin. The back link should optional for user, otherwise all our sites will look like link farms. The great gallery component Phoca, and many others are in the same boat.
1 of 1 people found this review helpful
2010-08-22
Reviews: 5
This pulgin shows sitegrond link on every page.I have uninstall this plugin but still siteground link display at bottom of the page. Developers please note how to remove this link.
2010-08-16
Reviews: 5
I really don't know if this plug-in work or not? But I do know it creates a great deal of errors when it comes to the components and plug-ins that I have. When logging out of Jomsocial 1.8.7 it create an illegal key error, plus created another error when I was using Virtuemart 1.1.5 the new version. So until it has a little more wear and tear I am not going to use it. Because I can't have my members running into errors pages.

Another thing: placing the Siteground link on one page is fine, but when it places the siteground link on all my pages and throws my template out wack, I was left with one choice remove the link...

But what good is this plug-in when everything you have or want to use conflicts with it? Just do a search on this plug-in and it clear more than 50% of the people thats using it or have used it have un-installed it. And I still don't know if it ever worked! But I do know the link to Siteground website worked! And no one in this review section knows if it works or what it does? There no read out or any that shows what it blocked or prevented! Wait, here a thought and a scary one at that maybe the hackers was supposed to see the Protected By Siteground and run away...or find another website to hack into...

No one that have downloaded this plugin knows what this plugin does?
0 of 1 people found this review helpful
2010-08-16
Reviews: 29
Why people put bad review? You can always cut away footer link and use it. Try to vote for tool not emotions.
2010-08-14
Reviews: 3
[ First time to give a rating and I never thought that it would be a "Very Poor" one. ]

Like all the high quality security extensions I've tried and installed on all the sites that passed through my hand, I'd love to use this one.

But adding a "Secured by Siteground Web Hosting" footer on all the pages is a huge turn off.

First, and as was said before, it's misleading. Second, does it have to be on all the pages?

I really liked it when I looked at the code, it's just sad that I can't use it, more so recommend it.

I hope you'll add an option to disable the footer. If that's not possible, maybe you could provide a commercial version so that people who really want to use jHackGuard can do so but without the Siteground footer.
Page 1 of 2