Subscribe to Acqal

Got Thoughts? Write Us!

Contact
Request
Validate

Approved TYPO3 Agency

Acqal is an approved TYPO3 agency focusing on support, training and website migration.

This means that we...

  • are available on TYPO3.org
  • make substantial contributions to TYPO3 teams
  • are registered as business members of the TYPO3 Association
  • have completed more than four TYPO3 projects
  • have proven our technical abilities with quality TYPO3 extensions
  • use TYPO3 for our own website

Acqal is a TYPO3 Association Business Member

Popular Blog Posts

Blog Topics

Virgil on Twitter

Please wait while virgilhuston tweets load Twitter is loading

Recent Blog Posts

Blog Archives

Quick Tips for TYPO3 Security

Security Check Results

Security Check Results

TYPO3 Security Cookbook Localconf Suggestions

TYPO3 Security Cookbook Localconf Suggestions
Monday, October 12, 2009 6:13 AM EDT

By: Michael Cannon

voting in progress Submitting your vote...
Rating: 5.0 of 5. 1 vote(s).
Click the rating bar to rate this item.

How do you check your website's TYPO3 security?

TYPO3 website security is an imperative these days and ignoring it is quite costly in terms of time, money and resources. However, with TYPO3, many of the most common security checks can be easily done with a single TYPO3 extension.

Security Check, found as security_check in the TYPO3 extension respository, runs from the TYPO3 backend and checks about 40 of the most common TYPO3 security concerns. Besides a report of potential lapses and guidance on how to fix them, there are a couple of tools for finding unnecessary and insecure files.

When TYPO3's Security Check is combined with the principals and steps outlined in the TYPO3 Security Cookbook, downloadable below, a TYPO3 website's security is quite solid from the server side.

So... What Does Security Check, Check?

Per the security_check manual, the following points are checked. Sample results at right.

  • Php Ini Check

    • Test if the Setting open_basedir is set
    • Is the PHP Setting "error_log" is set?
    • Is the PHP Setting "register_globals" off?
    • Is the PHP Setting "display_errors" off?
    • Is the PHP Setting "magic_quotes_gpc" off?
  • Database Check

    • Test the access to mysql config Database
    • Test the Host Restrictions of the Mysql User
    • Test the Mysql User passwords
  • loacalconf

    • Is the encryptionkey set?
    • Are the Filerights on creation of new Files to hight?
    • Are the Filerights on creation of new Folder to hight?
    • Is the Installtool Password changed?
    • Is the Option lockSSL active?
    • Is the Security level the highest?
    • Is a Warning E-Mail Address inserted?
    • Is the Session Timeout to hight?
    • Is the SQL-Debug Feature disabled?
    • Is the Display of Errors disabled?
    • Is the Option to install global Extension disabled?
    • Is the Flag "disable_exec_function" activated?
    • Is the Option to edit of Extensions disabled?
  • Backend Access

    • Is the access to Typo3 Backend protected?
    • Is the access to Typo3 Install Tool protected?
  • Files Check

    • Are there Backup Files on the Server?
    • Are there CVS Files on the Server?
    • Are there Files without Extension on the Server?
    • Are there CVS Files on the Server?
    • Are there Readme Files on the Server?
    • Are there Subversion Files on the Server?
  • Typo3

    • Is the standard Password used?
    • Checks if insecure Extensions loaded.
    • Is Typo3 up to Date?
  • External Tools

    • Search PHP-Info Outputs.
  • File rights

    • Checks the Rights of Folders.
    • Checks the Rights of Files.

User Input TYPO3 Security Suggestions

While Security Check and the TYPO3 Security Cookbook help with server side concerns, these following TYPO3 extensions check incoming data. In turn, they help protect the website from spamming, cross-site scripting XSS and SQL injection attacks.

Keywords:

  • typo3 security, web security, internet security, website security, typo3, security_check


Acqal Corporation is an approved TYPO3 agency with over 40 years of Internet experience. Acqal offers you TYPO3 support, TYPO3 templates and TYPO3 training and tutorials.

Please subscribe to Acqal Newsletter and Acqal Blogging via or RSS Feed Acqal RSS Feed.

© 2009 Acqal Corporation. All Rights Reserved.

Please Share This Post

Tweet thisRedditBookmark on deliciousStumble thisShare on Facebook

Send this article via email to your friends and peers.

Leave a Comment

Add comment

* - required field







Notify me when a new comment is added.
By Maarten Mandemaker on Tuesday, October 13, 2009 5:39 AM EDT
Gravatar: Maarten Mandemaker I've tried the security_check extension but somehow it doesn't work. When I start the test it keeps saying...please wait... I waited for more than 10 minutes so I quess that should be sufficient. No results.
By Maarten Mandemaker on Wednesday, October 14, 2009 7:19 AM EDT
Gravatar: Maarten Mandemaker Update: Nevermind, it works on FireFox... When I first tried I was on IE7. (Bad, bad me!)