{"id":905,"date":"2015-04-18T08:09:13","date_gmt":"2015-04-18T13:09:13","guid":{"rendered":"http:\/\/www.serverpronto.com\/spu\/?p=905"},"modified":"2018-07-20T11:11:26","modified_gmt":"2018-07-20T16:11:26","slug":"five-server-security-mistakes-to-avoid","status":"publish","type":"post","link":"https:\/\/www.serverpronto.com\/spu\/2015\/04\/five-server-security-mistakes-to-avoid\/","title":{"rendered":"Five Server Security Mistakes to Avoid"},"content":{"rendered":"<p>Although the digital age has provided us with all kinds of benefits we probably couldn\u00e2\u20ac\u2122t live without, it\u00e2\u20ac\u2122s also served up a number of challenges too. By far, the biggest of these challenges is probably the risk to digital security. Keeping your server secure is just as important as the security you would employ on a building. In some ways, it may even be more important, considering all the information (social security numbers, customer credit card numbers, payroll figures, etc.) that could be potentially harvested from a hacked server. The following five server security mistakes are ones you should avoid making to keep hackers at bay.<!--more--><\/p>\n<h2>Changing File Permissions<\/h2>\n<p>A lot of the server security mistakes you\u00e2\u20ac\u2122re making probably started with good intentions. For example, if you install scripts on your server, it\u00e2\u20ac\u2122s to be expected that you may have to set permissions for at least some of the folders.<\/p>\n<p>Usually, this gets done with a CHMOD command via some FTP program. However, if you find that getting the settings correct is a challenge, like a lot of people, you might end up setting all of your folders to the most accommodating setting possible, 777.<\/p>\n<p>The problem with doing this is that hackers now have extremely easy access to your folders. It\u00e2\u20ac\u2122s like keeping the key to your front door outside and in plain sight.<\/p>\n<p>Fortunately, most servers already come with quality default permissions. You should only have to change them in rare circumstances.<\/p>\n<h2>Wildcard Indexing<\/h2>\n<p>One reason you\u00e2\u20ac\u2122ll need a server is for your website. This is where you\u00e2\u20ac\u2122ll probably have a folder that keeps all your audio files, images and page files that don\u00e2\u20ac\u2122t show up on the web.<\/p>\n<p>That\u00e2\u20ac\u2122s all fine, of course. Just be sure that when you try to visit your root directory, you get a server error. For example, when you type in \u00e2\u20ac\u0153\/pics\u00e2\u20ac\u009d after your homepage\u00e2\u20ac\u2122s URL, you should receive an error 403 or 404.<\/p>\n<p>If you\u00e2\u20ac\u2122re successful in visiting your root directory, something has gone wrong. A list of the directory\u00e2\u20ac\u2122s files will be displayed and this can potentially open up your server to hotlinking, leeching and exposing even more of the directory tree as well.<\/p>\n<p>To turn off indexing for those folders, either edit your .htaccess file by adding a file you name \u00e2\u20ac\u0153index.html\u00e2\u20ac\u009d or, for those using cPanel, go to the Index Manager for disabling indexing.<\/p>\n<h2>Outdated Software<\/h2>\n<p>There are a number of reasons your software may need updating. Of them all, the most important is that if you don\u00e2\u20ac\u2122t update it, you can be exposing yourself to risk unnecessarily. This is especially true when you consider how easy it is to update your software. Not doing it is a huge mistake that could cost you dearly. Everything from password hacks to database injections can occur when your software becomes outdated.<\/p>\n<h2>Forgetting about Backups<\/h2>\n<p>Although picking the right server should keep your information safe, having backups is still important. If you run your site off something like WordPress, all you need is a plugin to keep your information backed up.<\/p>\n<p>For other sites, something as simple as logging into it through FTP and downloading everything right onto your hard drive is all it takes.<\/p>\n<h2>Bad Passwords<\/h2>\n<p>Don\u00e2\u20ac\u2122t drop the ball because of your passwords or those of your staff lack in quality. Instead, use a password generator and change them regularly. Doing this will make it incredibly difficult for a hacker to compromise your privacy.<\/p>\n<p>At ServerPronto, we don\u00e2\u20ac\u2122t just specialize in servers and hosting. We are also specialists where server security is concerned. Let us know if you need help in any of these critical areas. Our expertise is at your disposal.<\/p>\n<p><a href=\"https:\/\/www.serverpronto.com\">ServerPronto<\/a> offers the best affordable and secure hosting service in all dedicated server packages.<\/p>\n<p>&nbsp;<\/p>\n<p>Sources:<\/p>\n<p id=\"ph_pcontent2_0_MainHeading\" class=\"title\"><a href=\"https:\/\/redmondmag.com\/articles\/2012\/05\/01\/10-standard-security-slipups.aspx\">10 Common IT Security Blunders (and How To Avoid Them)<\/a><\/p>\n<p id=\"what-is-secure-hosting\"><a href=\"https:\/\/www.whoishostingthis.com\/compare\/secure\/\">What is Secure Hosting?<\/a><\/p>\n<p>Photo cred: Flickr \/\u00c2\u00a0<a href=\"https:\/\/www.flickr.com\/photos\/jakerust\/\">GotCredit<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Although the digital age has provided us with all kinds of benefits we probably couldn\u00e2\u20ac\u2122t live without, it\u00e2\u20ac\u2122s also served up a number of challenges too. By far, the biggest of these challenges is probably the risk to digital security. Keeping your server secure is just as important as the security you would employ on<\/p>\n","protected":false},"author":9,"featured_media":915,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"image","meta":{"footnotes":""},"categories":[8],"tags":[123,17,112,22,18],"class_list":["post-905","post","type-post","status-publish","format-image","has-post-thumbnail","category-dedicated-server-best-practices","tag-cloud","tag-dedicated-server","tag-hosting","tag-server","tag-web-hosting","post_format-post-format-image"],"_links":{"self":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/comments?post=905"}],"version-history":[{"count":6,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/905\/revisions"}],"predecessor-version":[{"id":2438,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/905\/revisions\/2438"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media\/915"}],"wp:attachment":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media?parent=905"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/categories?post=905"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/tags?post=905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}