contemporaneous notes from post-release maintenance activities
29 November, 2018
- Take backup
- php File scan
- check baseline;OK
- Review Changelog; Update Extensions
- Admin Tools pro 5.1.4 to 5.2.0
- Akeeba backup Pro 6.2.1 to 6.3.1
- Alledia Framework 1.6.3 to 1.6.4
- Reg Labs Articles anywhere 8.3.1 to 8.4.1FREE
- Reg labs adv mod mgr 7.8.6 to 7.9.2FREE
- Reg Labs Articles Anywhere 8.4.1 to 8.5.0FREE
- Reg Labs Extension Mgr 7.2.2 to 7.3.1
- php File scan
- Create new baseline
- Update Joomla Core
- 3.9.0 to 3.9.1
- php File scan
- Create new baseline
- Take backup; copy offsite
7 November, 2018
- Take backup
- php File scan
- check baseline;OK
- Review Changelog; Update Extensions
- Reg Labs Articles anywhere 8.3.1 to 8.4.1FREE
- Reg Labds Cache cleaner 6.3..0 to 6.4.0FREE
- Reg labs adv mod mgr 7.7.1 to 7.8.6FREE
- JSiteMap Pro 4.5.1 to 4.5.2
- JoomDonation 5.4.8 to 5.4.10
- Coalaweb gears 0.5.2 to 0.5.3
- php File scan
- Create new baseline
- Update Joomla Core
- 3.8.13 to 3.9.0
- php File scan
- Create new baseline
- Enable new 3.9.0 feature for User Action Logs
- Take backup; copy offsite
10 October, 2018
- Point nameservers for draut.us to siteground nameservers
- Transfer backup fileand install using akeeba kickstart
- note - Akeeba Site transfer did not succeeed - had to revert to 2-step process.
- First light after backup restored
- Account login URL: https://ua.siteground.com/login.htm
- Account:
This email address is being protected from spambots. You need JavaScript enabled to view it. - Primary Domain: draut.us/aa2018
- Server: us189.siteground.us
- Directory: /home/autismam/public_html/aa2018
- php: 7.1.22
- Joomla 3.8.13
- Lets Encrypt cert on draut.us
- php File Scan
- set new baseline
- purge old file cache and reports
- Check WAF
- Delete all old security Exceptions
- Delete all old IP Blocking history
- Add my current IP to "never block"
- Implement latest security defaults:
- See: https://docs.joomla.org/J3.x:Joomla_3.8.8_notes_about_the_changed_default_settings
- disable upload of shockwave files
- do not send user password
- set default blacklist for administrator text filter
- See: https://docs.joomla.org/J3.x:Joomla_3.8.8_notes_about_the_changed_default_settings
- Add additional Autism* domains as Parked on Siteground account;
redirect to https://autismamerica.org/ (currently still at BlueHost)- autism-america.{com,org,net}
- autismamerica.{com,net,us}
- autismingeorgia.{com,org}
- autismintexas.{info,net,org}
- autismintexas.com domain expired on Bluehost - GC/KD say to let it go
- Update Nameservers on Bluehost for above additional Autism* domains to point to Siteground nameservers
9 October, 2018
- Create webhosting account on SiteGround:
- Primary Domain: draut.us
- Base Joomla install:
- https://draut.us/aa2018 - autismamerica
- https://draut.us/ds2018 - drautandsons
- Take backup
- php File scan
- check baseline;OK
- add administrator/logs/error.php to exclusions
- Review Changelog; Update Extensions
- Reg Labs Articles anywhere 8.2.2 to 8.3.1FREE
- Reg Labs Extension manager 7.2.1 to 7.2.2
- Reg Labs Sourcerer 7.3.0 to 7.3.1FRE
- Update Joomla Core
- 3.8.12 to 3.8.13
- php File scan
- Create new baseline
- Review Security logs
- delete aged records
- Check WAF
- Update to latest cloaking list
- check auto-ban list
- Take backup
1 October, 2018
- Take backup
- php File scan
- check baseline;OK
- add administrator/logs/error.php to exclusions
- Review Changelog; Update Extensions
- Admin Tools Pro 5.1.3 to 5.1.4
- Akeeba Backup Pro 6.1.1 to 6.2.1
- Alledia Framework 1.6.2 to 1.6.3
- CoalaWeb Gears 0.5.1 to 0.5.2
- Joom Donation 5.4.7 to 5.4.8
- JSiteMap pro 4.5 to 4.5.1
- Reg Labs Articles anywhere 8.2.0 to 8.2.2FREE
- Reg Labs Extension manager 7.1.7 to 7.2.1
- Reg Labs Sourcerer 7.2.0 to 7.3.0FREE
- php File scan
- create new baseline
- Review Security logs
- delete aged records
- Check WAF
- Update to latest cloaking list
- check auto-ban list
- Take backup
4 September, 2018
- Take backup
- Update components
- JoomDonation 5.4.5 to 5.4.7
- JSocial icons 3.1.4 to 3.1.5
- Reg Labs Articles anywhere 8.1.0 to 8.2.0FREE
- ShackSlides 3.1.9 to 3.1.10
- Update Joomla core
- 3.8.11 to 3.8.12
- Review redirects
- clear all new disabled
- stop collecting URLs
- Review security logs
- Update 404 cloaking to latest set
- rebaseline file scan
- Take backup
6 August, 2018
- Complete getting Kitty's MyNikken links up (activities over several days)
- Created the MyNikken webpage
- Created blog menu item
- Created blog entry - display on both home page and main Blog menu page
- Had to find a way to suppress all the other stuff on the homne page from showing up when following Read more -- default is to display the "more" on a page recognized as the Home page, even though it is a specific URL displayed for the article.
- Solution is to use the Advanced Module Manager and set the "Home Page" criteria from "Ignore" to "Include". This specifies that a module normally shown on the Home Page will only show if it is the exact home page i.e. no article reference.
- Created a module for magnetics to display on the Products and Solutions page.
- Take backup
- Turn on BoU
- Update components
- Akeeba Admin Tools Pro 5..1.2 to 5.1.3
- JoomDonation 5.4.4 to 5.4.5
- Reg Labs Articles Anywhere 8.0.3 to 8.1.0FREE
- Update Joomla core
- 3.8.10 to 3.8.11
- Take backup; copy offsite
- Regenerate php file scan report
- review WAF log
- turn off email after IP auto-ban
- add some more URLs to cloak
- Update auto-ban message
- Take backup; copy offsite
16 July, 2018
- Create Kitty's personal doTERRA webpage
- Add Blog entry and sidebar for Essential Oils to link to doTERRA site
- Delele a few bogus User accounts
- Disable new user registration from login screen
- Update components
- JoomDonation 5.4.3 to 5.4.4
- Adv Mod Mgr 7.6.3 to 7.7.1FREE
- Articles Anywhere 7.6.1 to 8.0.3FREE
- Review redirects
- delete all captured
- disable further logging
- Reduce WAF warning emails to Blocked IPs
- php file scan;
- reviewed;
- marked all "Safe"
- Take backup
28 June, 2018
- Redirects from the legacy and unassigned domains to AuitismAmerica.org appear to have been removed. Reapply..
- AutismAmerica.com
- AutismAmerica.net
- AutismAmerica.us
- Autism-America.com
- Autism-America.net
- Autism-America.org
- AutisminTexas.com
- AutisminTexas.info
- AutisminTexas.net
- AutisminTexas.org
- Update components
- Alledia Framework 1.6.1 to 1.6.2
- Coalaweb Web Gears 0.5.0 0.5.1
- Shack Slides 3.1.8 to 3.1.9
- Take backup
- Update Joomla Core
- 3.8.8 to 3.8.10
- Upgrade Compoenents
- Akeeba Backup Core to Pro
- Akeeba Admin Tools Core to Pro
- Take backup
- Configure Admin Tools
- WAF
19-20 June, 2018
- Take backup
- Update components
- Admin Tools core 5.0.2 to 5.1.2
- Akeeba Backup core 6.0.1 to 6.1.1
- JoomDonation 5.4.1 5.4.3
- Adv Mod Mgr 7.6.1 to 7.6.3FREE
- Article anywhere 7.5.6 to 7.6.1FREE
- Cache Cleaner 6.2.1 to 6.3.0FREE
- ShackSlides 3.1. to 3.1.7
- CoalaContact Pro 1.1.4 - upgrade from Core
- ShackSlides 3.1.7 to 3.1.8
- CoalaWeb Gears 0.4.4 to 0.5.0
- Configure Captcha/ReCaptcha
- register domain with Google ReCaptcha system
- enable Captcha pluginon CoalaWeb Contacts; add site & secret key
- enable Captcha-ReCaptcha on Joomla Global Config/Site settings page
- Configure usage on JoomDonation forms
- Configure usage on CoalaWeb Contact forms (requires pro version)
- Update Joomla core
- 3.8.7 to 3.8.8
- review redirects
- redirect some links from old site to new areas
- purge masses of penetration attempts
- Take backup; copy offsite
26 April, 2018
- Worked with Bluehost to restore email service to autismi8 account
- Checked
This email address is being protected from spambots. You need JavaScript enabled to view it. email account- has not been checked since created
- emails from web forms have reached it in the past and from todays test
- notified Gordon/kitty
- Activated Sitelock Basic
23 April, 2018
- Take backup
- Update components
- Alledia Framework 1.6.0 to 1.6.1
- Coalaweb Gears 0.4.8 to 0.5.0
- JoomDonation 5.3 to 5.4.1
- Update Joomla core
- 3.8.6 to 3.8.7
- Enable new redirect manager plugin
- Take backup; copy offsite
- Investigate autismi8 account possibly being used to originate spam
- relocate unused and older website directories to /home4/autismi8/archive_html -- i.e. off the web
- replace the Gordon Joomla Contact form with a notation to use the Coala contact form in the sidebar
- Worked with BlueHost to conform spam originated here; Bluehost suspended email service for the account
- Worked with CoalaWeb plugin guy to confirm problem was withthe standard Joomla contact page, not CoalaWeb's contact page
- Check and redirect some URLs captured by the new redirect manager plugin
4 April, 2018
- Take backup
- Update components
- regular Labs - Cache Cleaner - 6.2.0 to 6.2.1FREE
- regular labs - articles anywhere - 7.5.3 to 7.5.6FREE
- regular labs - Adv Mod Mgr - 7.5.1 to 7.6.1FREE
- JSSocial Icons - 3.1.2 to 3.1.4
- CoalaWeb Gears -0.4.5 to 0.4.8
- Take backup
- Enable caching
13 March, 2018
- Update component:
- JoomDonation 5.2 to 5.3
- Take backup
- Update Joomla Core
- Take backup; copy offsite
12 March, 2018
- Prior: get basic SSL cert from Bluehost
- Export/edit/import Metadata for https:// URLs
- set site for "https: always"
- Take backup
- Update components
- Akeeba Admin tools core 4.3.1 to 5.0.2
- Akeeba Core 5.6.3 to 6.0.1
- RegLabs Adv Mod Mgr 7.5.0 to 7.5.1FREE
- RegLabs Article Anywhere 7.5.1 to 7.5.3FREE
- RegLabs Cache Cleaner 6.1.0 to 6.2.0FREE
- RegLabs Sourcerer 7.1.11 to 7.2.0FREE
- Take backup; copy offsite
- Note: Joomdonation update fails; working with support
7 Feb, 2018
- Update Joomla core
- 3.8.3 to 3.8.4
- Take backup
31 Jan, 2018
- Update sponsorship to remove "Incorporated" from Draut and Sons
- Take backup
- Update components
- Coala Web Gears 0.4.4 to 0.4.5
- Coal Web Core 1.1.3 to 1.1.4
- JSiteMap 4.3.6 to 4.4
- Advanced Module Manager 7.2.2 to 7.4.0FREE
- Articles Anywhere 7.3.1 to 7.5.1FREE
- Extension Mnager 7.1.4 to 7.1.7
- Sourcerer 7.1.10 to 7.1.11FREE
- ShackSlides 3.1.4 to 3.1.5
- Update Joomla core
- 3.8.3 to 3.8.4
- Take backup; copy offsite