Web Site Infections is hurting many domains on the net. The infection rate is high in WP, Joomla and similar free script, due to fixed nature of the scripts as well as lack of security know how of the users.
Types of Infection:.
There are few frequently possible site infections.
In the most of the cases the main site page is replaced with another one, uploaded by a hacker.
There are also specialized hackers who upload whole programs to the website, in order to take the website’s domain and look for big security holes.
This is most likely a result of a compromised and not fully updated application, site, exploitable php scripts, etc, which can be used by the attacker (most of the time an automated spider).
Important note: The infection is not limited to particular type of websites, all websites are prone to attacks.
Most of our clients are using more than one application and/or 3rd parties software. In these cases knowledge is required about how to avoid attacker attempts.
Meassures to Avoid Infection:
Here are some useful advices:
- Regular update of each application, particularly security patches.
- Regular changing of passwords /control panel, ftp, email.
- Regular reviewing and investigating for malicious content.
The update of your applications is a process, which can be handled by yourself. This can be done automatically or manually.
Please note: if the application was manually installed, it should be manually updated as well.
An automatic update can be done trough the application's web administration /recommended/ or cPanel's Softaculous interface.
Here are some related pages with information, describing this process for two of the most common platforms - WordPress & Joomla
http://codex.wordpress.org/Hardening_WordPress
http://codex.wordpress.org/FAQ_Installation
http://codex.wordpress.org/Updating_WordPress
http://wordpress.org/news/2009/09/keep-wordpress-secure/
http://codex.wordpress.org/Hacking_WordPress
http://docs.joomla.org/Upgrade
http://docs.joomla.org/Security_and_Performance_FAQs
http://docs.joomla.org/Security
You can use Feedburner by Google in order to subscribe for newsletters reporting all new security updates.
The link below is for WordPress update reminder subscription.
http://feedburner.google.com/fb/a/mailverify?uri=wordpress-releases&loc=en_US
web hosting company
- 69 Users Found This Useful