Has Your Website Been Defaced? Hacked?
Sunday, 11 July 2010
Reader of the Extra Cash Systems Weblog, you are appreciated, and I want you to know about things that are important to you, and your Extra Cash Systems generation.
Maintaining a secure webhost server is one of those things that is important to generating Extra Cash Systems. The following is an email reply I received from one of my webhosts, regarding possible security issues on said webhost. I hope you find it as useful as I did…
It is possible that a hacker could obtain your cpanel password through use of malware or viruses on your PC. There do exist (we see them a good bit) viruses that will infest a computer, and actually record keystrokes and the fields that they are used in.
If someone uploads a shell program to your webhost, such as a PHP Shell, then they can execute programs and explore the server with all the rights you have. However, your account really can’t do anything outside of your home directory. It is possible for a user to look at the account names of other users, but there is no way to view inside their directories, or take any action of any kind in another user’s directory. It is also not possible for someone using a PHP Shell to make changes on any file on the server that is not owned by the user that the shell is running as.
Here is a list of steps that you can take to ensure your sites remain secure:
1. Use the following online vulnerability scanner and ensure your software is up-to-date: http://secunia.com/vulnerability_scanning/online/?task=load
2. Download anti-virus and fully scan your PC for malicious files. Here are some free online scanners for Windows, which is typically the most vulnerable to infection. If you have a different OS, there are similar programs that can be located and run on your system to protect it in the same way:
MalwareBytes ( http://www.malwarebytes.org/ ) and
ComboFix ( http://www.bleepingcomputer.com/
combofix/how-to-use-combofix ) have been reported to be able to clean a recent strain of malware that resists detection by almost all other anti-virus agents. It is highly suggested that you use one or both of them and one of the following:-http://housecall.trendmicro.com/
-http://www.bitdefender.com/scan8/ie.html
-http://www.kaspersky.com/virusscanner
-http://support.f-secure.com/enu/home/ols.shtml
3. Update all passwords for any account that you access/own that may not be up to standards. Any passwords that have been compromised will need to be changed as well. Standards for secure passwords are available: http://en.wikipedia.org/wiki/Password_strength
#Guidelines_for_strong_passwords4. Ensure that all scripts/plugins/modules/components are updated to the most recent released version, as new versions are released primarily to address known security vulnerabilities in these sites.
5. Keep your computer secure from malware infecting it. If your computer is compromised, your account can be compromised through your password being used to access it.
- Ensure you use the latest browser version; Ensure that said browser subscribes to Google’s blacklist API (Mozilla Firefox, Google Chrome, Safari)
- Disable javascript
- Use the firefox addon noscript
- Make sure your antivirus has a subscription to new database and version releases. This may cost some amount of money, but is well worth the expense.
- Use http://www.avg.com.au/index.cfm
?section=avg&action=onlinescan to test suspicious links you are given in emails or find online.6. Ensure that all database configurations for your account are using a custom generated user and password combination, and that this information is not stored in plain text if this is feasible. Using your cPanel username and password to access your databases for your site may be convenient, but it introduces an incredible security risk.
7. Audit your account for unnecessary scripts, such as file uploaders. Ensure that if they are necessary that they are password protected, or if that is not feasible that they check the file type before allowing upload, to prevent upload of certain types of files.
8. Confirm that the permissions on the public_html folder is set to 750, as permissions of 755 will allow excessive amounts of malicious activity to the account.
9. Ensure that extended logging is enabled on your account so that any compromise can be investigated, as logs are regularly removed when statistics are run.
I mentioned the issue I was having, and thought that others were, over at the Warrior Forum, on this thread: Have You Been Hacked/Defaced?
Bottom line? Act on the advice shown above. You’ll be better off in the long run, and will keep your Extra Cash Systems safe, and profitable…
Quick Link: Copy, paste and link!
Just the link
Or Get the Description too.

- Subscribe to the feed!









No. 1 — July 17th, 2010 at 5:22 am
Hi, Some nice tips. Other few Good option to keep eyes on website security is (1) Create an alert in Google Alert. By that you can possibly receive updates if there are any changes made. (2) Regularly check SERPs around your website. Search engines shows and scans many websites for such malwares too.
No. 2 — July 20th, 2010 at 3:11 pm
You are a life saver, I had thought that my computer was acting a little funny. So I went to the links that you posted and got those scanners and let me tell you I was shocked! I couldn’t believe what I was seeing, I had so many malware and viruses. But everything is good now I just decided to re-format my computer. Thanks for the help.
No. 3 — July 25th, 2010 at 1:43 pm
This information has helped me no end, thank you very much.
No. 4 — July 29th, 2010 at 12:27 am
my computer was once hacked.it took me great pain to sovle it .
No. 5 — July 31st, 2010 at 1:53 am
keyloggers can be dangerous and so as malwares. it’ll take your password and all that vital info you keep in yourself.
.-= Joe@Cincinnati Divorce´s last blog ..When You Have Decided to Get a Divorce =-.
No. 6 — July 31st, 2010 at 1:43 pm
I did get hacked once. It wasn’t nice. I will follow some of this advise, maybe I should have done it sooner.
.-= Marc@Aluminium Ladders´s last blog ..Telescopic Extension Ladders =-.
No. 7 — August 1st, 2010 at 2:49 am
Fortunately I have never been hacked until now. And I hope I will never go with this trouble. But being on the safe side is always good. I will check for my blogs’ vulnerabilities. Thanks for sharing these sites.
.-= suman@Mobile phone offers´s last blog ..Top RIM Blackberry Applications you should have =-.
No. 8 — August 16th, 2010 at 3:36 am
you can possibly receive updates if there are any changes made.I will follow some of this advise
No. 9 — August 18th, 2010 at 5:10 am
All these tips are good tips. Thanks for the helpful information.
No. 10 — August 23rd, 2010 at 2:17 am
I went to the links that you posted and got those scanners and let me tell you I was shocked!
No. 11 — August 24th, 2010 at 3:20 am
This is such an important post. Really took me time to read all the comments, but I really enjoyed the article. It proved to be Very helpful to me and I am sure to all the commenters here! It is always good when you can not only be informed, but also entertained!I hope quality discussions follow this post.
Alesandra @ mustard costume´s last [type] ..Ketchup Costumes
No. 12 — September 8th, 2010 at 7:34 pm
Hello, This blog is very interesting and enjoyable to read. I am a big fan of the subjects discussed. I also enjoy reading the comments, but notice that alot of people should stay on topic to try and add value to the original blog post. I would also encourage everyone to bookmark this page to your favourite service to help spread the word. Thanks.
Jordans´s last [type] ..Nike Air Jordan shoes – countdown package 11-12