Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Tuesday, January 20, 2015

12 Tips to Protect Your Company Website From Hackers - Entrepreneur Magazine



By: Stan Washington
Date: January 20, 2015

Story by John Rampton See Full Story http://www.entrepreneur.com/article/241620

Making your website live is like unlocking the door to your premises with your office and safe open: Most of the people who visit your physical building will never even know that all of your data is there to discover just by walking in. Occasionally you will find someone with malicious intent who will walk in and steal your data. That is why you have locks on doors and safes.
Your website is just the same, except that you will never see anyone come in unless you have protection systems in place. Electronic thieves are invisible and fast., searching for your website for details of customers’ accounts, especially for their credit card information. You have a legal obligation to protect this data from theft and to report security breaches that occur.
Theft is not the only thing on the mind of a hacker: Sheer destruction is a major motivator. Hackers may want to destroy all your records, put a sick message on your customers’ screens or just destroy your reputation.
You can never undo the damage done by a hacker, you can take steps to prevent it. Even the most basic protection will discourage many hackers enough to make them go looking for easier pickings elsewhere. Thieves are likelier to steal from people who leave their doors unlocked.

1. Stay updated.

You need to stay up to date with hacking threats. If you have at least a basic knowledge of what is possible then you can protect your website against it. Follow updates at a tech site such as The Hacker News. Use the information you gain to put fresh precautions in place when necessary.

2. Toughen up access control.

The admin level of your website is an easy way into everything you do not want a hacker to see. Enforce user names and passwords that can not be guessed. Change the default database prefix from “wp6_” to something random and harder to guess. Limit the number of login attempts within a certain time, even with password resets, because email accounts can be hacked as well. Never send login details by email, in case an unauthorized user has gained access to the account.

3. Update everything.

Updates cost software companies money. They only do it when necessary, yet many people who use the software do not install updates immediately. If the reason behind the update is a security vulnerability, delaying an update exposes you to attack in the interim period. Hackers can scan thousands of websites an hour looking for vulnerabilities that will allow them to break in. They network like crazy, so if one hacker knows how to get into a program then hundreds of hackers will know as well.

4. Tighten network security.

Computer users in your office may be inadvertently providing an easy access route to your website servers. Ensure that:
  • Logins expire after a short period of inactivity.
  • Passwords are changed frequently.
  • Passwords are strong and NEVER written down.
  • All devices plugged into the network are scanned for malware each time they are attached.
Ever since I founded my hosting company, we've had to watch our network security on a minute-by-minute basis not to be hacked. 

5. Install a web application firewall.

A web application firewall (WAF) can be software or hardware based. It sets between your website server and the data connection and reads every bit of data passing through it.
Most of the modern WAFs are cloud based and provided as a plug-and-play service, for a modest monthly subscription fee. Basically, the cloud service is deployed in front of your server, where it serves as a gateway for all incoming traffic. Once installed, web application firewall provides complete peace of mind, by blocking all hacking attempts and also filtering out other types of unwanted traffic, like spammers and malicious bots. This is a great way to avoid getting hacked like Craigslist.

6. Install security applications.

While not as effective as a full blown WAF, there are some free and paid for security applications that you can install that will make life a bit more difficult for hackers. In fact, even some free plugins such as that from Acunetix WP Security can provide an additional level of protection by hiding the identity of your website’s CMS. By doing so this tool makes you more resilient against automated hacking tools that scout the web, looking for WordPress sites with specific build and version, which has one or more known vulnerabilities.

7. Hide admin pages.

You do not want your admin pages to be indexed by search engines, so you should use the robots_txt file to discourage search engines from listing them. If they are not indexed then they are harder for hackers to find. This tutorial from SEObook.com is all the help you will need.

8. Limit file uploads.

File uploads are a major concern. No matter how thoroughly the system checks them out, bugs can still get through and allow a hacker unlimited access to your site’s data. The best solution is to prevent direct access to any uploaded files. Store them outside the root directory and use a script to access them when necessary. Your web host will probably help you to set this up.

9. Use SSL.

Use an encrypted SSL protocol to transfer users’ personal information between the website and your database. This will prevent the information being read in transit and accesses without the proper authority.

10. Remove form auto-fill.

When you leave auto-fill enabled for forms on your website, you leave it vulnerable to attack from any user’s computer or phone that has been stolen. You should never expose your website to attacks that utilize the laziness of a legitimate user.

11. Back-up frequently.

Just in case the worst happens anyway, keep everything backed-up. Back up on-site, back up off-site, back up everything multiple times a day. Every time a user saves a file it should automatically back up in multiple locations. Backing up once a day means that you lose that day’s data when your hard drive fails. Remember every hard drive willfail.

12. You can't hide your code.

You can buy software that says it will hide the code on your webpages. It doesn’t work. Browsers need access to your code in order to render your website pages, so there are simple ways to get around web-page “encryption.”
Disabling “right-click” as a way to view your website code is annoying to users because it also disables every other “right-click” function, and there are simple workarounds that every hacker knows anyway. If you have been told that it is possible then read this article onHTMLgoodies.com to get in-depth explanations of why you can never hide your code.
Your Experience: Has your website been hacked? How did the criminals get in? Please use the comments facility below to share your story including the changes you made after the attack

Tuesday, May 13, 2014

Internet Explorer - It's safe to go back into the water!

By: Stan Washington
Date: May 13, 2014

In April the Department of Homeland Security issued a statement that Internet Explorer had vulnerabilities.  This scared the already nervous population of internet users and they began flooding away from IE in droves. I am a long time Microsoft user so this news made me do a little research.

The real issue was the support of the Windows XP operating system, said a  Microsoft spokesperson. People need to upgrade in order to remain secure. Here is that news item:

http://www.usatoday.com/story/news/usanow/2014/05/01/microsoft-issues-internet-explorer-security-fix/8562737/

If you wish to go back to Internet Explorer do this first:

Check for updates.  This security patch was not pushed because a large portion of IE users were not affected.  Check for updates and apply any pertaining to the operating system and Internet Explorer.  If you don't see updates, you were probably fine.

Saturday, March 29, 2014

Large Email Systems Hacked and what to do about it!

Date: March 28, 2014
By: Stan Washington

January 31st Yahoo reported their e-mail system was hacked. Since this occurrence, we have noticed a substantial rise in the number of email delivery failures due to people changing their accounts. Communication through this vehicle is extremely important. Stay updated and stay safe!

Here are a few things to do:



  1. Update your records for all of your clients and potential clients.  This is important to do on a regular basis to make sure you have the correct email address.
  2. Be email cautious. Check your own email and never open an email from "Friends' Name" as the only thing in the subject. 
  3. CHANGE YOUR PASSWORD! I know I have said this before. Pick an obscure date and change your password on a regular basis.
  4. Use a stronger password. The bad guys like to use apps to hack your password. Theses apps never get tired and are relentless in their pursuit.  Use @#$%^&* ()-_=+ characters along with numbers and letters to keep the hackers guessing. The longer the better!
  5. Don't share passwords across systems. I know, I know! This is truly a pain. Once you are hacked then other items are vulnerable. Secure your bank account with the strongest password and save the weaker ones for the church bulletin app.


BE SAFE!!


Thursday, November 7, 2013

Beware: Phone Scammers Impersonating IRS according to NBC Today


By: Stan Washington
Date November 07, 2013

The IRS has alerted taxpayers that the bad guys are pretending to be the IRS and are using a phone system to display the correct IRS phone number, according to NBC Today.


Avoid Phone Scammers by screening your calls
Pick up or not to pick up, that is the question. Do you have a sophisticated phone routing system? If not then you may need to screen your calls.  I have noticed an uptick in robot calls and scammers in recent months.

Take Down a Number and Verify
According the the IRS, the scammers can become belligerent and threaten to send the call recipient to jail. Remain calm, take down their number and contact the IRS or the agency they are impersonating.

How Broad is this?
There has been a report of a scam in every state. It takes a while to catch criminals like this so be on guard and be prepared. 

Here is the link to the IRS:
http://www.irs.gov/uac/Latest-News
-------------------------------------------------------------------------------------------------------------------------------
Please visit http://www.careercoachoffice.com if you desire safe and secure online payments, e-mail marketing and Client management all in one! Try it today!