Simple Tips to Improve your Website Security

Understand the simple rule, Any loophole in your system is an open invitation for hackers to attack your website at there will and fantasty.

So the Thmb rule is simple, Keep all your doors secured and patch and monitor loopholes. Here we offer your few simple advices that could help you secure your website effectively and safe from attacks.

1. Keep All your Password Secured, The so called hackers employ scripts that brute force attack password using the possible permutation and combination. So Most Important enforce strong password Policy, use Larger than 10 charectores, Alpha numeric, with capital letters and special charectors combination.

Second aspect is never store your password in any FREE Public email accounts mailboxes or storage area, always adopt an alternate way to keep your password secure.

2. All Software NOT Upto Date are Open Invitation to hackers, Start from OS of both the Client and Server Operating system is uptodate, well patched and hardended to thwart any maleware or bit attacks. Than look for your FTP Clients, We strongly recomend avoid using pirated copies of any software including the FTP clients, in several cases it was found that the FTP client itself sending FTP credentials to hackers. We recomned use SFTP instead of FTP service and clients. Thirdly ensure your Front end and backend langaues like PHP, ASP, JSP, Perl, python, PostGREESQL and MySQL are latest one. and you have properly configured the front end and backend languages not to leake your memories due to poor safe gaurd and restrictions. Forthly ensure any CMS like WordPress or ecommerce application like magento etc are latest one. avoid plugins from not known sources, as this are also found to be backholes for hackers to enter your server.

3. Use Secured hosting only, use HTTPS protocol that provide security over the internet and ensures users are communicating with server in secured manner and while data being transfered between client and server its not being compromised. Install a secured SSL Certificate on your website.

4. Scan your website and webs server for any vulnerabilties, As several times you need to do external scan to check any vulnerabilties. and by known so you can patch and harden the vulnerabitityy.

Few of the Tools you can try :

https://securityheaders.com/
https://pentest-tools.com/website-vulnerability-scanning/web-server-scanner
https://www.qualys.com/forms/freescan/
https://sitecheck.sucuri.net/
https://www.ssllabs.com/ssltest/

‘Fauxpersky’ malware steals and sends passwords to an attacker’s inbox

A newly-discovered keylogger malware has been found infecting computers in the wild. Though the malware is far from advanced, it’s efficient at stealing passwords.

Continue reading “‘Fauxpersky’ malware steals and sends passwords to an attacker’s inbox”

WordPress Parameter Resource Consumption Remote DoS attack (CVE-2018-6389 )

A zero-day vulnerability in WordPress core was disclosed, which allows an attacker to perform a denial of service (DoS) attack against a vulnerable application. The vulnerability exists in the modules used to load JS and CSS files. These modules were designed to decrease page-loading time, but have effectively rendered the WordPress core susceptible to DoS attacks.

Continue reading “WordPress Parameter Resource Consumption Remote DoS attack (CVE-2018-6389 )”

Why Virtual Dedicated Server hosting gaining Popularity ?

Virtual servers made a noise, but IT industry’s advancement doesn’t have any intention. Not everyone is satisfied with the rigidity of servers or the insecurity of sharing hosting. The search for stable and more secure hosting alternatives resulted in another innovation – dedicated servers hosting service. Based on Hyper Visor technologies, VDS provides a dedicated OS to each server, allowing flexibility and the control they need to companies of medium and small sizes. This excludes hosting like degree of security’s weaknesses. The VDS technology can be new, but it’s gaining popularity extremely fast. VDS and VPS appear to be the same – almost, but not entirely – the difference between them being in the OS they use.

Continue reading “Why Virtual Dedicated Server hosting gaining Popularity ?”