Showing posts with label hacked. Show all posts
Showing posts with label hacked. Show all posts

Tuesday, May 18, 2010

Wordpress Attacks Reported On Shared Host

1 comments
Just a heads up if you are running Wordpress on a shared hosting account such as Hostgator. There are starting to be several reports that Wordpress sites on shared hosting accounts are under attack. You can read much more on this here and there is even a PHP upload clean up fix should you get infected. Although I have yet to hear Hostgator named specifically, the initial reports today were restricted to Dreamhost, GoDaddy, Bluehost, Media temple and other places with the common theme being shared hosting platforms. This has even been reported on sites using the latest 2.9.2 version of Wordpress.

Saturday, April 4, 2009

It's A Large World After All

0 comments
Sometimes we tend to forget that it is called the World Wide Web, not just Google. I get a few emails from people every now and again that get really upset with being deindexed in Google and wondering what they should do. Trust me when I say it is not the end of the world, yes Google traffic is great, but there are other search engines and other means of getting targeted traffic. Believe it or not, non BANS sites get deindexed as well, even PHPBay sites. There usually is a REASON why and ignoring that problem will only lead to future deindexed sites. Usually it because the site is so thin or using all scraped content or leaving too many obvious footprints of a thin door way site. I have seen people rebuild sites on a new domain name to suffer the same fate. While you clean up the deindexed site to match Googles guidelines, you should continue to build legitimate backlinks and look far beyond Google and the the other SERPS for traffic. This means social sites, article directories, niche related blogs and forums and even related directories. Before re-submitting a deindexed site for review, you need to make sure your site is an honest to good engaging site, it also needs to be checked for exploits with this tool. I have looked at a few deindexed sites in the past for people to find that they have been exploited and thus likely the reason they were deindexed. Also be prepared to wait a LONG time to get back into the Google index. You are not alone as they get thousands of request a day to go through. Do not put yourself into a hole only relying on Google, open your eyes and see how wide of a world web it really is.

Thursday, March 26, 2009

A security Alert You Need To Know About

3 comments
I have been playing around with some article directory databases as of late and noticed a very scary thing. It is the type of thing we all take for granted on any site that we have to create a username and password with. Most of the time, your username and password are not encoded. In playing around with one of the databases, I had usernames, emails and passwords for all 3000 plus members. Scary isn’t it? If you use article directories or any site for that matter that you have to provide a username and password for, you better be unique to that site. If you use the same username and password for several sites, you need to change them. People buy and sell these databases all the time for hackers to get their hands on. For sites that you get paid on, such as Pay Pal, EPN, Pepperjam or one of the many other affiliate programs out three, every username and password better be unique. Sure it is a pain in rear, but identity theft and fraud are higher than ever in a down economy. The article directory and link directory scripts are the worst of these. You may think no one can see this info, but I am here to tell you, anyone who knows how to use phpmyadmin for database administration can get this info in 5 minutes flat. There were a ton of EPN account hijacks a few months ago and this very well could of been how the emails and passwords were attained. Several EPN members use the article directories and if they used the same email and password for their EPN account, they were a sitting duck. EPN has included a bit more security now for any account changes, but that does not mean you shouldn't be any less cautious.

Keep a notebook or spreadsheet if you must for ever login. Once again it is a pain, but can help more than you think. Also use a junk email address for the less important signups. A great deal of sites use the email address as the username, so having an email address for just article and link directory sites will help a great deal. This is a serious matter and I hope you head my advice and change ALL of your very important passwords right this second.

Saturday, February 21, 2009

Good Practices To Prevent Hacking

0 comments
Feeling a little under the weather today, so this post will be short and sweet. Most do not worry about being hacked until they are already hacked. It is good to be as preventive as possibly when it comes to your sites safety. Google Webmaster blog has a great post up on the best practices to prevent hacking. The post also offers up some ways to identify the hacking of your site or sites.

Monday, November 24, 2008

Always Be Concerned About Site Security

1 comments
The web is always full of people wanting to hack into your website or account info. It seems as if there has been a resurgence in people hacking either EPN account or BANS sites as of late. It is always good practice to stay on top of your own security by constantly changing your login details for FTP access, admin sections of both Wordpress and BANS and yes even affiliate program details. If you have some upcoming free time over the holidays, I highly suggest you set aside some time to change your passwords and login information. You should never get into the habit of using the same username and password across several sites. As tempting as it is, you are just asking for problems. Keep a notebook if you must a write it down or create a secure file on your computer to house them all. Do not let yourself be an easy target. Security should always be first and foremost in your mind.

Saturday, April 19, 2008

Monitor Your Niche Store Server

3 comments
As promised, I will show you how to monitor your Build A Niche Store server changes. Let me first say that this tutorial is based on you hosting your BANS stores on Hostgator. The script can be cgi script can be modified for any server, but I will cover the installation for Hostgator.

First you will need to create a directory in your top level of your server named "scripts". Not in your public_html directory, but in your root of your server. Next in the directory of scripts create another directory named "custom".

You will next need to download these 2 files. directories.txt and PWSmonitorchanges.txt to your hard drive.

Open up directories.txt and change the word username to whatever your Hostgator username is. Save the file back to your harddrive.

Next open up the file PWSmonitorchanges.txt and look for the 3 entries below:

$sendto_email = 'You ';

$sender_email = 'You ';

$path = "/home/username/scripts/custom";

The first 2 entries are your email address where you want the emails sent when changes are made on your server.

The last entry is the path, change the word username to your Hostgator username.

After these edits have been made save the file back to your harddrive as PWSmonitorchanges.cgi not PWSmonitorchanges.txt

Next you want to upload both of these files
directories.txt and PWSmonitorchanges.cgi to your custom folder which is in the scripts folder you created. Next you want to chmod the PWSmonitorchanges.cgi file to 700. The script and directories.txt should now be installed.

Next you need to create a cron job that will run this script at whatever interval you choose. I suggest every 6 hours. Log into your cPanel of your Hostgator account and click on Cron jobs and then click on Standard. Copy the below string into the command box, but change the word username to your Hostgator username.

/usr/bin/perl /home/username/scripts/custom/PWSmonitorchanges.cgi

underneath that you can select how often to run it. Like I said I would click Every Six Hours, Every Day, Every Weekday, Every Month. When done, click Save Crontab.

That is it, now every time you are anyone or an error happens it will email you any changes to any files made on any sites on your server. It will be normal to see some error logs pop up in the report, but you are looking for any unauthorized file changes or file uploads that YOU did not make. This will also track all of the changes you make as well. I hope I have explained this well enough for you and it should be simple to uninstall should you feel you do not need it.

The script comes courtesy of Premier Website Solutions.

EDIT

One of the blog readers left a great comment I will add here:

Thanks Mike!


The cron job can be set for every 6 hours as stated, or any frequency you want, BUT make sure you also change the variable:
$minutes = 15;
in the script to the same.

If minutes is left at 15 and cron is set to run every 6 hours, it means every 6 hours the script will look for files altered within the last 15 minutes, so it would miss anything altered more than 15 minutes and less than 6 hours ago. Miss pretty much everything. ;-)

Friday, April 18, 2008

Wordpress Blog Hack

0 comments
Well, I have been very busy trying to straighten out several infected files on all of my BANS stores after being hacked through my Wordpress blogs on a few of my Niche Stores. If you have any Wordpress blogs on any of your servers you might want to look into this. Here is a post about the security issue. You need to check every folder of all of your sites or ask your hosting company to run a check for you. I had 61 files that I had found, even on sites without a blog attached. I have now finished up installing a new script that checks my servers every 15 minutes to see if files have been changed or uploaded. I will post tomorrow on how to install and run this on stores hosted with Hostgator. Get busy and check those sites tonight.

Followers

Twitter Updates

    follow me on Twitter
     

    Build A Niche Store Blog. Copyright 2008 All Rights Reserved Revolution Two Church theme by Brian Gardner Converted by Bloganol dot com Privacy Policy