Hacks and Malware Attacks!
In recent weeks there has been various Linux Platform hacks which have affected some well known and respected hosting companies. According to experts there is still a need to clarify the exact method these attacks have been made, they believe however that security holes in web applications along with their modules and plugins are the most logical explanation.
Because of this we are urging our clients to keep all their web applications including WordPress and ImpressCMS along with any modules and plugins up to date. If you have a support plan which covers free upgrades you must open a ticket with us to make an upgrade request. If you are unsure how to upgrade your web application and require our support then please purchase a support plan for your chose system, if it isn’t available then please open a ticket to discuss your options.
Things to keep in mind for your account and web hosting packages:
- Always choose a strong password for your account and FTP access, also change your passwords from time to time to ensure no one else can gain access.
- Keep your local computer(s) upto date and ensure you have reputable AntiVirus and Malware to protect yourself. Remember if someone accesses your credentials from a poorly secured system then they could also access your other web accounts including your hosting package with us, Paypal, Internet Banking, etc, etc.
- Our servers use PHPSuExec, all folder permissions should be set to 755 and file permissions should be 644. If you don’t set these correct permissions then your web application will most likely cease to function correctly.
- We also recommend you use SFTP as this is securer.
In addition to this we have taken extra measures recently such as installing PHPSuExec to ensure a higher level of security, we also have our systems monitored to inform us of potential issues. That said, we are not complacent and advise the same of you.
On our part, you can rest assured that we are taking all measures possible to avoid any such hack on our servers. We have various security mechanisms in place that block these malicious actions from taking shape and we have also implemented various automated and periodic scans which identify any such patterns and cut them out from the root.
Please be vigilant and proactive in taking all precautionary measures.
Should you have any concerns then please do not hesitate to contact us.