Securing your site

Typical attack vectors for hacked sites are the following:

  1. Insecure file and folder permissions where write access has been given to publicly accessible files.
  2. Third-party apps (WordPress, Joomla etc) that have NOT been secured and kept up to date, including any add-on modules. 
  3. Compromised Passwords for FTP, Control Panel or CMS etc that allow a hacker access to the hosting plan files.
  4. Compromised Mail accounts which may have emails with ftp/panel passwords saved or that allow hackers to request password resets from your host.

Tips for securing your site

Write permissions should only be assigned to files/folders that explicitly require write access and if possible they should be hosted below the websites root folder where they are not directly accessible by website browsers.

In our Windows hosting you can manage permissions using the control panel file manager by clicking the padlock next to any file or folder, you need to alter. Users should avoid ticking the "enable write permissions" option in the website properties page as this will assign write permissions to all files and folders in the site and is highly insecure.
 
In our Linux hosting, you can set permissions via the file manager or via the FTP chmod command.
 
Always use complex passwords for all accounts. Using a password manager like Lastpass or Keepass to generate and manage complex passwords is a good idea.

We offer security audits for a small fee and they can save you time understanding where your site may be lacking is security.

 

  • 10 Users Found This Useful
Was this answer helpful?

Related Articles

What is a parked domain or domain alias

A parked domain name (Also called a Domain Alias) is an additional domain name that leads to the...

Updating Wordpress on our Windows Hosting

If you have secured WordPress correctly on our Windows hosting then the vast majority of your...

What is an email "alias" and what is it for? (Windows Hosting)

What is an email alias and what is it for? (Windows Hosting) An email alias is an alternative...

Is there a limit to the number of MSSQL databases you can create?

The only limitation for Microsoft SQL Server databases is the space, you can create unlimited...

Can I view my site before the DNS has propagated?

Windows Hosting All websites are issued with an Instant alias based on the domain you supply...