NinjaSecurity PluginLanguage

Want to stop being being scared of having your site hacked or defaced?

Would you like something as simple to use as a virus scanner for your Joomla!™ Website? If so then you urgently need NinjaSecurity!

NinjaSecurity is a system plugin that monitors the what is called GPC data. Any incoming data is scanned for specially defined patterns, which you can modify as you want and if it detects these paterns, then any asttempts will be blocked and the Hacker will then be banned after the attacking attempt.

Available languages: English, German

Warning: You must remain vigilant with your security!

While Ninja Security will protect you from many attack types, there are some security leaks, such as "Remote File Inclusion” attacks, from which no Joomla!™ extension can protect.
However, all forms of "SQL and Code Injection” can be avoided thanks to Ninja Security.

Changelog:

Version: 1.0.3
Date: March 2009
Status: Bugfix Release

* Eliminated some syntax errors and warnings.

Version: 1.0.2
Datum: Febuary 2009
Status: Bugfix/Improvement Release

* Added Exclude Strings
* Added IP / IP range blacklisting
* Changed component excluding parameters to dynamic
* Changed folder structure
~/plugins/system/ninjasecurity is now saved under
~/media/ninjasecurity and with the next upgrades it needs not to be removed by hand.
* If you are upgrading from a version prior to 1.0.2, please note that you will have to delete the folder ~/plugins/system/ninjasecurity before installing the new version, because Joomla!™ didn't on plugin uninstallation.


Version: 1.0.1
Datum: January 2009
Status: Bugfix/Improvement Release

* Added Secure AdminPanel Login (inspired by JSecure Authentication)
* Added Frontend User Group Control
* Added Component Control
* Please note that you will have to delete the folder ~/plugins/system/ninjasecurity before installing the new version, because Joomla!™ didn't on plugin uninstallation.


Version: 1.0.0
Datum: January 2009
Status: Initial Release

* Scan for exploit patterns on all incoming data
* System alerts via email on detected exploits
* Configurable time window for banning attackers IPs

Report

Editor's Note
  • This extension requires registration to download.
I'm glad I installed this - it allows you to search for and block visitors who make url calls to your site containing certain strings (defined in the plugin parameters) where you've also got preset strings containing many common strings used to perform SQL injection attacks on web sites.

It also has the same functionality as jSecure built-in.

Do read the instructions CAREFULLY, as if you just install and publish you'll most probably lock yourself out of your site for 3 hours (!).

It's worth the financial and small time investment getting it working properly though.

Dave.