Security [CENTRAL] Forum - SCforum.info
24. May 2012., 01:29:59 *
Welcome, Guest. Please login or register.

Login with username, password and session length

SCforum.info - Security [CENTRAL] Forum

↑ Grab this Headline Animator

Custom Search
News: For ultra cheap bullet proof vests, hard armor ballistic plates or for advice on body armor in general visit SafeGuardClothing.com
 
  Home Help Chess Links Login Register   *

SCforum.info


furniture store



Members
Total Members: 11256
Latest: rbraik
Stats
Total Posts: 15636
Total Topics: 4337
Online Today: 2172
Online Ever: 51419
(01. January 2010., 10:27:49)

SCF UnSpam

Top Ten Antivirus Software

Friend of WOT


SCF Feedburner

SCF Facebook

SCF Twitter

Welcome to SCforum.info - Security [CENTRAL] Forum, a home of the SCF Community devoted to provide Computer related News, Alerts, Downloads and FREE Help in such a way that even the novice computer user can understand.

Getting started using our community is extremely easy, check the two steps below:

Step 1: Create an account by clicking here and wait for approval from Administrator. It's completely free with no hidden strings attached.

Step 2: If you have a computer problem and need some help, or just want to take part in opened discussions, simply browse Forum. Once you *Register an account, you can quickly post your questions and comments.

(*Registered Members get: free support, also, they can communicate privately with other members via PM, removal of this message, see fewer ads and much more...)






Pages: 1
  Print  
Author Topic: Website security  (Read 1964 times)
0 Members and 1 Guest are viewing this topic.
Blake
SCF Newbie
*

KARMA: 1
Posts: 5


« on: 21. September 2010., 19:26:14 »

Hello folks!

So as I mentioned in the "introduce yourself" thread, I found this forum because my friend's website was recently hacked.  It's a Wordpress blog, but with a unique (non-wordpress) URL.

The hack actually was done by the hacker breaking into the hosting company's servers and replacing many sites' index.php pages.

So I've started finding some resources on improving website security, particularly Wordpress security, but specifically I'm wondering what can be done to protect one's website if someone breaks into the hosting company's servers.  Is there anything, or is that something a webmaster has no control over?  Do you just have to pick a hosting company with better security?

Also, like I said in the intro thread, I basically know nothing; I'm just a user, not a programmer.  :-)  Thanks for any help!
Logged
Security [CENTRAL] Forum - SCforum.info
« on: 21. September 2010., 19:26:14 »



 Logged
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5077


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #1 on: 21. September 2010., 21:14:52 »

Hi again Blake.

First thing to check is did you have latest version of Wordpress and to every version Upgrade install immediately.

Second thing is that you have proper settings permissions for files on server.

Related to Server you can't do to much, except to choose some well know service which install Upgrades to MySQL and other things ASAP.

For the end please check this advices also:

http://www.problogdesign.com/wordpress/11-best-ways-to-improve-wordpress-security/

http://www.famousbloggers.net/improve-security-wordpress.html

http://www.thesitewizard.com/blogging/secure-wordpress-blog.shtml


Hope this will help you??

I also expect more reply's and advices for other SCF Members.

Best Regards,

Samker


P.S.

So sorry for my bad English...
Logged

Blake
SCF Newbie
*

KARMA: 1
Posts: 5


« Reply #2 on: 21. September 2010., 21:28:17 »

No need to apologize for your English!  I understand you perfectly.  Thank you.

I'll talk to my friend about Wordpress updating, but I bet that wasn't the problem.  She stays on top of that sort of thing.  Thank you very much for the links; those plus the ones I already found, I've got quite a bit of reading to do.

I was afraid that she couldn't protect against an attack on her server.  That's good to know, though, to tell her not to blame herself for something she couldn't control.
Logged
haz
SCF Advanced Member
***

KARMA: 26
Gender: Male
Posts: 117



« Reply #3 on: 22. September 2010., 07:50:57 »

I Agree with what Samker said, I think if the hacker was able to break into the hosting company servers and replace many websites index, he mush have the root or admin account, thats not wordpress's fault, you need a better & more secure host !
Logged
neerajrawat1
SCF Moderator
*****

KARMA: 24
Gender: Male
Location: India
Posts: 159


We believe in sharing is caring


WWW
« Reply #4 on: 23. September 2010., 16:43:35 »

Blake it can happen with any hosting company even the top ones because everyday new viruses and vulnerabilities keep on discovering here you cant do anything

but yes few steps you can take at your side

always use a good security software at your side that too updated one

always keep a back up of your website on your pc and on external source as well as anytime your pc security can also be compromised even the server backups can be destroyed depending upon the severity of the attack so that you can make your site running up any time

and always use wp plugins from trusted sources as they may contain malicious code as well
Logged

Blake
SCF Newbie
*

KARMA: 1
Posts: 5


« Reply #5 on: 24. September 2010., 21:03:54 »

Thank you both; good advice, for sure.
Logged
manual2100
SCF Member
**

KARMA: 3
Posts: 27


« Reply #6 on: 12. October 2010., 11:31:57 »

if your friends server is not updated maybee the attacker gained access from some other process and not wordpress. You should always update the server OS, use firewalls, install patches for wordpress.. There are still some 0day attacks. You can use intrusion detection systems as well.. Still, nothing is 100% secure..always have backups of your files..
Logged
krrjhn
SCF Advanced Member
***

KARMA: -3
Posts: 213


« Reply #7 on: 05. January 2011., 09:58:22 »

I agree with smaker i think its a perfact link for you!!
Logged
Pages: 1
  Print  
 
Jump to:  

Enter your email address to receive daily email with 'SCforum.info - Security CENTRAL Forum' newest content:

Terms of Use | Privacy Policy | Advertising
Powered by MySQL Powered by PHP Powered by SMF | SMF © 2011, Simple Machines
TinyPortal © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 28. April 2012., 04:32:32