Level Computer & Technology Articles | MD Computing http://www.mdcomputing.com/tag/intermediate Keeping you and your computers, email, websites, and networks healthy Sun, 25 Dec 2011 02:28:59 +0000 en-US hourly 1 https://wordpress.org/?v=6.7.2 How to Keep Your Website From Getting Hacked http://www.mdcomputing.com/how-to-keep-your-website-from-getting-hacked http://www.mdcomputing.com/how-to-keep-your-website-from-getting-hacked#respond Wed, 28 Dec 2011 13:58:09 +0000 http://www.mdcomputing.com/?p=85 There are many different ways websites can be attacked, and often site administrators do not even realize that they have put themselves at risk until it is too late. Fortunately, these seven easy security guidelines can help you beef up your site security and avoid nefarious attackers.

Computer Websites Being Hacked1. Change default passwords. The first thing you should do when setting up a new site is to change all default passwords. Be vigilant and make sure no default passwords go unchanged. An amazing percentage of attacks are successful due to site administrators simply forgetting or failing to change default passwords. Often, if default passwords do not grant immediate access, attackers will simply move on to an easier target that does use default passwords.

2. Use passwords that are unique and complex and change them regularly. Not only should you use complex passwords, but you should also use unique passwords for all aspects of your site and change them on a regular basis. For example, you should never use the same password for both FTP access and administrative control panel access. If you use the same password for both methods of access, an attacker that knows the single password has the keys to the kingdom. Instead, use complex and different passwords for all access accounts. Create passwords that are not easy to guess and that use upper and lowercase letters, numbers and special characters. Do not use regular dictionary words in your passwords because those are easy to crack or guess.

3. Delete the built-in admin account. One of the simplest security steps to take is to delete default and built-in administrator accounts and create more obscure ones. You should create at least one administrator account that does not have a name that flags it obviously as an admin account. By making your admin powers harder to find, you make it more difficult for attackers to destroy or deface your site.

4. Keep software and all plug-ins updated. Unfortunately, there are many plug-ins and other web software out there that seem legit but actually contain malicious code or back doors. Carefully screen all plug-ins and software before you use them. Additionally, keep a close eye on your trusted software and plug-ins as well. If official updates are released, be vigilant about installing them. Updates are often released to patch holes and bugs that can allow attackers access to your site. By patching quickly, you can reduce your exposure to these risks.

5. Restrict access to your home folder from other IP addresses. Many hosting companies allow you to restrict administrative access to specific IP addresses. If you have this capability, you can prevent outsiders from doing damage to your site. Set access to only allow the IP addresses that you perform administrative duties from.

6. Audit permissions regularly. If an account does not administrate permissions, remove them. Check the permissions on your web folders and set folders that hold static content to read only. Assign only the minimum amount of permissions necessary to accounts and folders. By carefully monitoring access levels and permissions, you can prevent or limit the amount of damage that can be done when an attacker strikes.

7. Keep your PC clean and protected. While many focus on securing their website, often securing the PCs that are used to maintain the websites gets overlooked. The best passwords in the world cannot protect your site if your PC is automatically sending your secure passwords to an attacker. Malware installed on a computer can record keystrokes and send other sensitive data to attackers over the internet. As a result, it is vital to ensure that the PC you use for administrating your site is secure and clean. Use a trusted brand of antivirus software and always practice safe computing habits.

The best way to avoid having your website hacked is by being vigilant in your security practices and following these guidelines closely. However, with the speed that new exploits spread at, even the most vigilant administrators may discover that attackers have found a security loophole to crawl through. In this unfortunate, yet realistic, scenario these security guidelines can also help you minimize the damage that an attacker can do if they gain access to your site.

]]>
http://www.mdcomputing.com/how-to-keep-your-website-from-getting-hacked/feed 0
Network Security Basics For Your Business http://www.mdcomputing.com/network-security-basics-for-your-business http://www.mdcomputing.com/network-security-basics-for-your-business#respond Wed, 21 Dec 2011 21:09:44 +0000 http://www.mdcomputing.com/?p=66 Network security is often a confusing and frustrating subject. It seems as though no matter how many precautions are taken, hackers can still manage to find a way in. While it may be true that there is no such thing as fool-proof network security, there are many ways that any business can drastically improve.

email phishing hookA layered method is the best way to approach network security and make your network a hard target to tackle. By adapting these five layers, you can effectively increase the level of network security your business has and thwart many would-be attackers.

Layer one: Secure your wireless connections

Wireless access points provide convenient network access for employees and contractors, but unfortunately they also provide convenient access to hackers and attackers as well. All wireless access devices should either be secured or disabled if they are not in active use. Active devices should use WPA2 security at a minimum and utilize strong passwords that are not easy to guess. Additionally, an easy way to gain an extra layer of security is to set your wireless device to not broadcast its network name, or SSID.

Simple wireless security practices include:

  • Using WPA2 security
  • Enabling MAC address filtering
  • Setting strong passwords that are periodically changed
  • Limiting the broadcast range of your access point
  • Disabling SSID broadcasting

Layer two: Avoid suspicious emails

Innocent looking emails are the number one way attackers gain entry to networks. Often, innocent emails will carry dangerous payloads that can install viruses and other malware on PCs, even those that use updated antivirus software. The best way to avoid these threats is to immediately delete suspicious emails without opening them. If you do not recognize the sender, or the message seems at all suspicious, the best course of action is to simply delete the email.

Layer three: Set up a proxy or web filter

Malicious websites are another top attack vector utilized by hackers and other nefarious attackers. Even an innocent looking website has the potential to download harmful files to your PC. The best way to avoid this scenario is to use a proxy or web filter that automatically blocks users from browsing to these sites. A proxy can prevent users from accidentally stumbling upon a site that does damage to their PC and your network.

Layer four: Create strong password policies

Passwords are one of the simplest ways to keep attackers out, but they are also one of the most overlooked aspects of network security. Simple password policies can create a secure environment that is not easily breached.

Strong password policies include:

  • Changing the default passwords on computers and network devices
  • Requiring that network passwords are strong passwords that include letters, numbers and special characters
  • Educating employees to avoid writing down passwords and never keeping passwords that are written down in visible or easily accessible locations
  • Educating employees to never share passwords with anyone

Layer five: Audit your security regularly

The best way to ensure your network is secure is to have security audits performed regularly. A good auditing company can spot security loopholes before attackers can, and this allows you to tighten your security before your network is attacked. By working with a trusted auditing company, it is possible for your network security to stay one step ahead of the attackers. The auditing company can spot security holes that your staff may not be aware of, and the auditors are often able to provide detailed guidance about what security measures need to be taken.

Network security is a tough subject to tackle, but employing layers of security can easily help your business become more secure. A layered approach makes your company a difficult target to tackle. When hackers face obstacles like the ones created by this approach, they will often give up and seek out easier targets. While it may be impossible to create a network that is 100 percent secure, these methods will help you keep bad guys out and create a network that is not easy to attack.

]]>
http://www.mdcomputing.com/network-security-basics-for-your-business/feed 0