Affichage des articles dont le libellé est Hackers. Afficher tous les articles
Affichage des articles dont le libellé est Hackers. Afficher tous les articles

samedi 12 novembre 2016

Shared Hosting Security: Protecting Yourself From Hackers



alt="Shared Hosting Security: Protecting Yourself From Hackers" src="http://whsr.webrevenueinc1.netdna-cdn.com/wp-content/uploads/2015/04/default-image-500x308_c.jpg" />

class="border" src="http://www.webhostingsecretrevealed.net/images/2012/0823-1.jpg" alt="Security For Shared Hosting" width="750px" />

When your website functions as part of a shared hosting platform, there are only a few basic steps that you can take to protect the website from hackers and other users on the server that don’t act responsibly. For the most part, your website will be managed by the hosting service. However, your best interests aren’t always what they are looking out for. Hosting companies may be forced to make decisions that influence your hosting environment in order to protect the hundreds to thousands of users on the same server.

Make Regular Backups

Your web hosting company tells you that it makes regular backups, but you should never rely on these services to protect the information on your website. Use the web hosting companies backup as a fail-safe measure, but make sure to create and maintain your own backups off-site. Using a simple file manager (or better still, href="http://www.webhostingsecretrevealed.net/featured-articles/mastering-the-cron-job-and-automating-basic-server-tasks/">use cron) you can download all of your website files to your computer. Make sure you download any databases that your website needs to function as well.

Keeping Your Site Clean

If you aren’t using an email account, remove it from your server. Email accounts, FTP accounts and other unused applications should be removed if they aren’t being used. Look for any unneeded files and remove those as well. Extra files make backups take longer and the less files on a website the better the chances of finding something that doesn’t belong there.

Most importantly, if a script is not being used on your website, remove it as soon as possible. Hackers love to take advantage of out-dated scripts that the website owner has forgotten about.

Password Protection

If you are using SSH or multiple FTP accounts, use a different password for each account. Hackers that gain access to one of your passwords can quickly damage your website if all of your MySQL databases, FTP Accounts, CMS installations and anything else that uses a password all use the same password. Once you have changed your passwords, change them regularly and always update passwords with a strong password that consists of letters, numbers and symbols.

Avoid using common phrases or words as those passwords in many cases can be cracked quickly. If you are using a CMS such as Joomla, Drupal or even an LMS such as Moodle, password protect the web address for the administrator login. This adds another level of protection and makes it more difficult for hackers to identify which application is running on your server.

File Permissions

There are several private areas on a site that should never be accessible to the public. Make sure your permissions for read-only files are set appropriately. Setting all files to 7-7-7 is an invitation to hackers to access your website and change or delete required files. When changing permissions you have to be careful. Often content management systems require specific permissions to operate effectively. Before changing any permissions, take note of the current permissions. This can be done easily with a screenshot. If the website stops functioning, you probably changed a permission you shouldn’t have. Consult the documentation for any application you have running on your website.

Application Updates

Regardless of what applications or software you are using on the website, subscribe to security releases and updates relating to your application. When a new CMS update comes out, don’t wait for Fantastico or other auto-install scripts to update with the latest upgrade. Learn how to perform upgrades on your own and make sure to keep everything up-to-date. Updates protect your website from known security vulnerabilities and will greatly improve your ability to keep hackers from taking advantage of older out-of-date software.

Monitor Your Scripts

While it may seem convenient to allow opportunities for users to share your website with friends, this is an open invitation for hackers to use your website to send unsolicited email to thousands of users. Make sure that any script you use is updated regularly and protected against hackers. One way to accomplish this is to keep email forms off the public area of the website. Use password protected logins to make sure that only registered users can access certain, more vulnerable areas of the website.

Forums

If you have forums on your website, disable the option for people to inject code, use Java applets or use HTML on your public forum posts. You can always ban users that have to register on your website if you find one of them is using malicious code. However, for public forums, you have to take additional security precautions to ensure that hackers can’t inject code on your website.

Java Applications

Java offers incredible flexibility and makes it possible for website developers to create custom applications.

It also provides information about users computers and can be accessed by knowledgeable hackers to exploit users to your website. Reduce this possibility by providing access to special features only to users that have registered on your website. It won’t eliminate the possibility of injectable code being utilized on your website, but it will provide more security for your shared server.

Protect Your Computer

Your FTP program may be compromised simply by using an unprotected computer. There are malware and viruses that are designed to exploit FTP programs and gain access to your websites files. Protecting your computer from viruses, spyware, malware and hackers is essential. Make sure you install a reputable antivirus program that has the ability to track intruders on your machine. If you aren’t using the Internet, disconnect to prevent hackers from accessing your system.

Store Sensitive Information Offline

Don’t store your passwords and other sensitive information on any computer that has access to the Internet. Hackers can get into your computer often without you ever knowing. If they access your passwords, then any password they obtain can be used to access private files, banking information or anything else that you store online.

CMS Installations

Content Management Systems such as Joomla, WordPress, and Drupal are commonly used for their simple and easy to use interfaces.

However, if a hacker knows what version you are using they can exploit vulnerabilities to gain access to your website. When possible, hide your plugins and make it difficult for browsers to identify what CMS you are using. There are often extensions that can be installed that automatically remove this information from files on your website.

Safe-Mode

PHP scripts exist that allow users to access information on a shared hosting environment. Ensuring that your PHP settings are correct and prevent the ability for non-authorized users to execute scripts provides a level of protection. To do this, make sure “Safe-Mode” is turned on. If you don’t know how to do this, a simple ticket to your web hosting companies tech support should resolve this issue. Without “Safe-Mode” it is possible for users to run a script that lists all of your passwords, files, directory and other sensitive website information.

Use Databases

Don’t store sensitive information in a file on your website. Use a database to store and protect your sensitive user information from hackers. With most applications, the database is used automatically. However, some applications offer the option to use the server hard drive or the database to store session information. Whenever possible, use the database option to provide an additional layer of security on your website.

Configure .htaccess

Linux websites have an option for website users to href="http://www.webhostingsecretrevealed.net/web-hosting-knowledge/the-basics-of-htaccess/">set privacy preferences in a .htaccess file. There are several code snippets that you can insert into the file to make your website more secure. Prevent access your htaccess file and set the permissions to 644 so that users visiting your website can’t access the file. Additional measures include restricting access to certain file types, prevent unauthorized browsing of the site directory, change the default index page to make your website more secure, disguising script extensions and securing directories to the local area network or a specific IP adress so that only you have access to files.

Hosting Company

One of the best ways to secure your website is to choose a website hosting company dedicated to preserving your information. Not all website hosting companies offer the same level of security – this is why you need href="http://www.webhostingsecretrevealed.net/hosting-reviews/">reliable hosting reviews like mine ;). Ensure that your host has the knowledge and staff to monitor website activity and stop hackers before they have a chance to access your website and files by using scanners and other industry-grade protection.

Final Considerations

Shared hosting provides an unsecured environment that makes it possible for hackers to potentially access and steal data from your website. There are only so many options you can use to protect your website from hackers on a shared server. Consider purchasing a dedicated, semi-dedicated or VPS if you are storing important user information. Never collect credit cards or personal information if you don’t have an SSL certificate installed. If a hacker gains access to your users credit card information, you could be held personally responsible. For any issues that you don’t feel comfortable correcting on your own, consider hiring a IT professional or enlisting the help of your hosting server to secure your website.


Page 23 – Web Hosting Secret Revealed




Web Hosting News Update: Google Cloud’s Down Time, Blog’s Inventor, SlideShare’s Changes, and Shellshock Hackers Hit Yahoo



alt="Web Hosting News Update: Google Cloud’s Down Time, Blog’s Inventor, SlideShare’s Changes, and Shellshock Hackers Hit Yahoo" src="http://whsr.webrevenueinc1.netdna-cdn.com/wp-content/uploads/2014/10/google-cloud-500x238_c.png" />

October isn’t yet halfway over and already has been a big news month for web hosting. From down time, to hackers, to changes in how various websites work, there is enough news to keep you in reading material for days. While we can’t cover all the news items, WHSR will focus on a few of the ones we feel are important to website owners.

Google Cloud’s Down Time

Many small business owners utilize Google for a variety of tasks.

Let’s face it, love Google or hate them, they offer services that small business owners such as bloggers need to be effective.

Whether you use Google Drive, Google Hangouts or utilize their analytics to figure out how well your site is performing, you may have experienced interruptions on Wednesday, October 8th.

Analytics was fixed within minutes, but users also experienced downtime with Google Cloud Storage. The problems were reported starting around 11:30 EST and went on for about 90 minutes. Google posted in their forums:

“We apologize for any issues this may have caused to you or your users and thank you fo ryour patience and continued support.”

They went on to reassure users that it is a priority to make sure their systems are reliable.

Inventor of Blogging Celebrates 20 Years

On Saturday, October 11th, href="http://www.theguardian.com/technology/2014/oct/12/happy-20th-anniversary-dave-winer-inventor-of-the-blog" target="_blank">The Guardian reported on the inventor of the blog, Dave Winer. This month, in 1994, Winer published his first blog post via software he created. It was called Davenet.

For more than 20 years, Winer has been on the cutting edge of Internet innovations. He had a hand in helping create how RSS runs.

Today, Winer is still blogging via his blog href="http://scripting.com/" target="_blank">Scripting News. Spend five minutes reading through his blog and you’ll be as hooked as I was. He is obviously one of the clearest thinking bloggers on the Internet and a true pioneer of blogging.

href="http://www.webhostingsecretrevealed.net/blog/hosting-updates-news/web-hosting-news-update-google-clouds-down-time-blogs-inventor-slideshares-changes-and-shellshock-hackers-hit-yahoo/attachment/slideshare-screenshot/" rel="attachment wp-att-11180">class="alignright wp-image-11180" src="http://whsr.webrevenueinc1.netdna-cdn.com/wp-content/uploads/2014/10/slideshare-screenshot.jpeg" alt="slideshare app" width="300" height="534" srcset="http://whsr.webrevenueinc1.netdna-cdn.com/wp-content/uploads/2014/10/slideshare-screenshot.jpeg 319w, http://whsr.webrevenueinc1.netdna-cdn.com/wp-content/uploads/2014/10/slideshare-screenshot-168x300.jpeg 168w, http://whsr.webrevenueinc1.netdna-cdn.com/wp-content/uploads/2014/10/slideshare-screenshot-300x534.jpeg 300w" sizes="(max-width: 300px) 100vw, 300px" />SlideShare Releases iOS App

Businesses who use SlideShare for presentations or to promote their websites will be thrilled to learn that the company has released an href="https://itunes.apple.com/app/id917418728" target="_blank">iOS app. What this means is that users can now access their slides from anywhere via Apple devices.

The release is for iOS 8 and above and the app is optimized for the iPhone 5 and above.

There are several ways you can utilize this app. Create a presentation ahead of time and share it on the fly with a potential investor. Read through other people’s presentations to gather ideas and inspiration. Or, even use it to review a slide you previously created before going into a big meeting.

Yahoo! Attacked by Romanian Hackers Via ShellShock?

Jonathan Hall of href="http://www.futuresouth.us/wordpress/?p=25" target="_blank">Future South Technologies, an online security company, released a pretty strong blog post about the infiltration on Yahoo! and insists it was from Shellshock vulnerability.

While the attack was going on, Hall did his best to inform Yahoo! as well as Lycos and WinZip and he contacted the FBI about the exploitation of these sites.

Hall’s issue with Yahoo! is that Alex Stamos, CISO of Yahoo!, posted a statement that they were not iimpacted by Shellshock but they “isolated a handful of servers” that were at risk. Hall uses facts to back up his statement that Yahoo! was indeed breached via the Shellshock vulnerability.

What do you think? Is Stamos being honest with the public? Does Hall have a good point?

Share your views in the comments area below. As always, if you have news that would be of interest to other website owners, feel free to share that as well.


Page 11 – Web Hosting Secret Revealed




Web Hosting News Update: Changing Cloudscape, Stopping Hackers and Security Upgrades



alt="Web Hosting News Update: Changing Cloudscape, Stopping Hackers and Security Upgrades" src="http://whsr.webrevenueinc1.netdna-cdn.com/wp-content/uploads/2014/08/internet-500x472_c.jpg" />

If there is one thing that is certain, it is that news in the category of web hosting changes often. In this news update, TSW takes a look at trends in cloudhosting and the changing cloudscape, what Google’s HTTPS algorithm means for website owners, important security upgrades, and a new system for blocking brute force attacks on WordPress.

Changing Cloudscape and Where Cloud Hosting Is Headed

Although the concept of cloud computing dates back to the 1999, when salesforce.com and Google launched consumer cloud services, throughout the 2000s the market has grown.

There is little doubt that cloud-based infrastructures are growing in popularity and that trend will likely continue into the next decade and beyond. The big names in hyperscale vending are AWS, Google, Softlayer and Microsoft are offering cloud services at discounted rates and price matching one another. The goal is to secure the majority of marketshare in the coming few years, maintain those clients and make a profit with sheer volume plus add-on sales. Look for great deals in cloud hosting in the next few years as the big four and those coming up behind them, such as Amazon, battle it out to see who the top dog in cloud hosting will ultimately be.

For readers who are keen to dig deeper, here are the pricing pages from href="https://cloud.google.com/products/compute-engine/">Google Compute Engine, href="http://aws.amazon.com/ec2/pricing/">Amazon AWS, href="http://blogs.msdn.com/b/windowsazure/archive/2014/03/31/microsoft-azure-innovation-quality-and-price.aspx">Microsoft Azure, and href="http://www.softlayer.com/virtual-servers">IBM Softlayer. Adrian Cockcroft has assembled my own spreadsheet summary of instance specifications from the above vendors:  href="http://bit.ly/cloudinstances">http://bit.ly/cloudinstances.

WHMCS Urges Security Upgrades

If you’re using a service, such as CloudFlare and other proxy services with your WHMCS installation, the site released a href="http://blog.whmcs.com/security.php" target="_blank">security update on their blog urging customers to update. The update provides an IP detection logic system to improve security features. The blog post states, “The update includes a significant update to the low-level cryptographic routines used for admin authentication. These changes will affect any 3rd-party integration which directly accesses the admin user database table; they should not have an observable impact on installations otherwise.”

Protecting Your WordPress Website

Automattic, the company that oversees WordPress.com, released an announcement that it has purchased BruteProtect. BruteProtect is a plugin combined with a service that protects website owners using WP from hackers. BruteProtect will be part of Jetpack and thus will be installed with a single click. Malicious logins can threaten the health of your site and business, so this is a welcome acquisition for WordPress-based sites.

Google’s HTTPS Algorithm Changes

It’s probably no surprise to website hosts that Google has yet again added another element to how they rank websites. This time, their focus is on how secure your website it. They href="http://googlewebmastercentral.blogspot.com/2014/08/https-as-ranking-signal.html" target="_blank">stated on the Google Blog:

“Over the past few months we’ve been running tests taking into account whether sites use secure, encrypted connections as a signal in our search ranking algorithms. We’ve seen positive results, so we’re starting to use HTTPS as a ranking signal.”

class="alignright size-full wp-image-10700" src="http://whsr.webrevenueinc1.netdna-cdn.com/wp-content/uploads/2014/08/site-security.jpg" alt="site security" width="300" height="259" />

Preference will be given to sites that offer visitors a secure HTTPS connection. Google’s focus on security may lead to development of more products and stronger security measures from hosting providers. In the meantime, you can talk to your web hosting company about what they will be offering in light of Google’s latest focus.

The Internet is fluid and web hosting news changes from day to day. WHSR will always highlight the top concerns website owners might have about hosting and bring you the latest updates. However, it is impossible to cover everything. If you have something to add to this list, please share your news in the comments section below.


Page 12 – Web Hosting Secret Revealed




Russian Hackers and What It Means for Your Website



alt="Russian Hackers and What It Means for Your Website" src="http://whsr.webrevenueinc1.netdna-cdn.com/wp-content/uploads/2014/08/sql-injection-500x332_c.jpg" />

A group of Russian hackers, dubbed the href="http://www.nbcnews.com/tech/security/just-how-did-those-russian-hackers-steal-billion-passwords-n175471">CyberVor hackers by Hold Security, stole more than one billion passwords from sites both big and small this year. The group used a botnet to steal the passwords from an estimated href="http://www.thehostingnews.com/russian-hackers-steal-over-a-billion-usernames-and-passwords-32284.html">400,000 sites.

A botnet is basically a virus that infects a network of computers. The botnet then acts in the background doing one thing and doing it very well. In this case, it tested every website those using any of those networked computers visited to try to find security vulnerabilities. The attack was an SQL injection.

“Hackers did not just target U.S. companies, they targeted any website they could get, ranging from Fortune 500 companies to very small websites,” said Alex Holden, Hold Security Chief Information Security Officer (CISO). “Most of these sites are still vulnerable.”

src="http://player.theplatform.com/p/2E2eJC/nbcNewsOffsite?guid=tdy_pete_hacking_140806" width="750" height="520" frameborder="0" scrolling="no">

How the SQL Injection Works

The attack is performed by the bot finding any blank fields that can be typed into, such as comment boxes, searches and other blank boxes. The bot then starts working to see if the site can be hacked into and secure information compromised, such as:

  • Names
  • Addresses
  • Passwords
  • Credit card numbers

NBC News indicates that website owners can protect the forms on their websites.

style="color: #333333;">The website’s creators just have to make sure those fields can’t use certain characters, or access a separate system from the main databases. – NBC News

However, it is difficult to make sure you’ve caught every possible security vulnerability. Many news media sites equate the CyberVor hackers with household burglars. The burglar, or hacker, goes to each and every window and door in your home, trying to find one that is left open or easy to break into. The hackers do the same thing on your website, systematically testing each and every possible point of entry.

Protecting Your Site and Your Visitors

There are some very specific things you can do to protect both your website and your site visitors from this attack.

First, change your passwords that you use to access your websites and WordPress databases. Make the passwords as strong as possible.

  • Use upper and lower case letters.
  • Use at least two numbers.
  • Use special characters, such as ! and ?
  • Do not use the same password for all your sites or sites you log into and do not use a “system”, such as changing one number or letter for each consecutive password.

Next, you will want to use some best practices when it comes to SQL-based sites.

  • Try not to use dynamic SQL unless absolutely vital to the running of your site.
  • Install patches as soon as they are released.
  • Use input validation techniques where data input by users is authenticated based on very specific rules, such as length of query, type of query, and specific syntax. For example, if the field is for an email address, then there should be some settings that only accept characters that are in an email address. There should be an @, there should be a dot. There could be letters and numbers. There should not be any other characters, such as ! or ?.

You may also want to check out href="https://www.acunetix.com/vulnerability-scanner/download/" target="_blank">Acunetix’s Vulnerability Scanner, which will tell you where your site might be vulnerable to attacks.

class="aligncenter wp-image-10455 border" src="http://whsr.webrevenueinc1.netdna-cdn.com/wp-content/uploads/2014/08/sql-injection-ig.jpg" alt="sql injection facts" width="750" height="2860" />

While the Russian group did manage to obtain a large number of user passwords, there is no reason to panic. Make sure your site is secure and change your passwords today. However, also keep in mind that hackers are forever trying new and old tricks, so stay up-to-date on the latest news here on WHSR and take the steps necessary to protect your website and your livelihood.

 


Page 13 – Web Hosting Secret Revealed