BigWolfChris -> RE: Hacked website (4/18/2010 3:26:14 PM)
|
Erik, could you please pass these tips over to Elliot if he already hasn't done these I give these tips to all of my clients for the sake of site security Change any ftp passwords and ensured any coding that allows file uploading has been double checked and sanitized (Also, run a virus checker on both site and any computer used for FTP access) Also would be better if he uses SFTP protocol to upload files as standard ftp usually sends passwords as plain text which are really easy to get using packet sniffers Though, unfortunately many hosts don't allow SFTP which can be a real problem If the host itself was hacked through their own backdoors, then it is down to them to secure the webserver better But 8/10 it is usually down to a weakness in the FTP or the site coding itself
|
|
|
|