How to protect your website? Protecting and improving the security of your website is key to protecting your company’s largest investment on the internet and all advertising and digital marketing campaigns. Internet attacks are the daily bread! How to avoid being a victim of online pirates and scammers? With this easy guide, I help you protect your website and keep you safe from any malware, virus, or attack.
We will make your website fall in love with your customers!
We will squeeze your website until you fall in love: well positioned in Google and other web search engines, safe, fast, and, above all, efficient and profitable for your company, attracting potential customers and achieving real results!
It doesn’t matter what type of company you are in and what business sector you are in: if you have a website, you are probably the perfect target for a cyber attack. I do not want to start this post being an alarmist, but I do want you to be aware that any company and website can suffer an attempt at identity theft and data theft, or be easy prey to viruses, malware, ransomware, or any type of malicious programs that have appeared recently. You may hire a hacker here hackers for hire
Whatever garbage they try to send you or put on your website, you must know perfectly how to protect the website because, if your website has all the security measures installed and applied, it will withstand any attack they make.
However, the sad reality is that many website owners and webmasters! they do not know how to guarantee the security or how to protect the web and, even worse, they do not care about it, believing that “ nothing could happen to them, they are not an Apple or an Amazon… ”. But instead, they do invest a lot of money in an SEO and web positioning agency or through an advertising management company in Google Ads.
I am not saying that investing in SEO or PPC, is an action of little importance for a company, not at all! But it is of little use to generate a lot of traffic to a web page if it has been attacked and is not working correctly or is stealing the data of the company, its clients, or the money of both! There is too much at stake not to make it a top priority to improve security and know-how to protect the website.
Before getting into the subject, let me tell you that in the event that, either because you have little time available or you do not have the necessary technical knowledge, you prefer to leave this delicate work in the hands of professionals, the maintenance and web update services that we offer in Xplora includes, among many other advantages for your company, shielding your website against any attack on your online business or your customers.
11 tips so you know how to protect your website yourself
Now, how can you create a security barrier against these attacks? There are several simple steps to create a shield that keeps this type of pirates, scammers, and malicious programs away, and in this post, I leave you a simple step-by-step guide to know how to protect your website.
Start protecting your website by always updating the software and the CMS platform
The first step to maintaining a secure web, the most basic and important, is not to ignore the software updates and the CMS platform.
Many times, people get upset when a new software update comes out. ” Again! How heavy! They release an update every few days! It sure is for a chorradita! ”. But I, who have collaborated in several updates of plugins of the WordPress CMS platform, can assure you that these updates are not done in vain. It is true that some are to improve aspects that are not directly related to security, but most of the updates are related, directly or indirectly, to the security of the website.
Keeping up to date with software updates and the CMS platform of your website means having a basic and crucial first shield to protect your website from viruses and attacks on the security of your website.
To avoid the entry of viruses or malicious software, as well as attacks that violate the security of your website, it is important to be up to date with the updates of your platform, yes or yes, without excuses or delays!
Many of the web hosting companies are already in charge of updating certain open source CMS platforms but, as we cannot trust that they will remember or that the automatic system works correctly, you should be careful to check when a new update appears and apply it yourself. same on your website.
In a CMS like WordPress, this process is very simple and I will comment on it in detail in other articles:
How to update the WordPress page?
How to do WordPress web maintenance?
I want you to know that there is a very fine line between your website security and hacker attacks. Hackers are very smart at spotting any security hole in your CMS software and platform, and quickly getting in there. Having these completely updated you avoid leaving a door open for them to enter the bowels of your website.
If you want to know more, I recommend another article where we explain how to protect WordPress without using plugins.
Install or buy the best security plugins (extensions)
Add-ons or security plugins reinforce the security of your website and make it more difficult to breach.
If your website works with a WordPress template, you will find specific plugins for WordPress. If not, maybe a tool like SiteLock can do a lot for you.
Every time a new security add-on comes out, you should be willing to install it, especially if it was designed specifically for the style of business you have, as that means there are viruses and any kind of malware out there, attacking websites like yours.
Plugins often have additional security options and it never hurts to have them.
Choose a secure web hosting service
Choosing a good web hosting service is a much more critical decision than it seems at first glance. My advice is that you don’t make this decision lightly; choosing one or the other simply for a matter of price, a friend’s recommendation, advertising, or another factor of little value in terms of the security of your website.
The web hosting service you choose must be secure and offer you daily backups, automatically update your CMS, fixed and secure IP, your own server resources, as well as monitoring and control systems for your website.
How to protect the web page by choosing the hosting well? This will depend, to a large extent, on the type of site you want to set up. Normally, those based on sales and transactions must have very high-security standards ( their own SSL certificates, private IP and from the same country, CDN system, etc.), so that customers do not feel distrustful in providing personal or banking data, and in completing an electronic transaction on said website.
This is for me one of the most important aspects when deciding on one hosting service or another, and more so now, when ‘masters of online scams’ abound, who seem more skilled and planned than Dani Ocean and his eleven robbers (in the movie ‘ Ocean’s Eleven’ starring George Clooney and Brad Pitt).
Cinema aside, don’t think that these scammers and identity thieves “grope” or take the wrong steps; No, dear reader, they detect and know perfectly which websites are vulnerable due to their outdated security system, insecure web server, or other details that we will see later, and they enter ‘like a thief in the night’: nobody hears them, detects them or he sees it.
Install an SSL certificate and protect your website in HTTPS
If your website still does not work under the HTTPS protocol, that means that Google and Chrome label you as an ‘unsafe site’. You must fix this ASAP! This should be the second urgent thing to do today (remember that the first thing is to update your CMS).
Migrating your standard HTTP website to an HTTPS protocol lets your customers know that you care about their security and prevents cyber thieves from finding cracks to steal data or scams.
The problem with a website that connects via HTTP, instead of HTTPS, is that it leaves unencrypted or secure time spaces between the browsing device and the website, as it does not have an SSL certificate, and this causes online pirates to intercept the information and access confidential data that the client and your website are exchanging.
Install a secure SSL certificate on your web server and migrate your page to the HTTPS protocol, many hosting providers offer it for free!
How to protect the web page working from HTTPS? Switching to HTTPS is not as expensive as it used to be. In fact, many web hosting providers already offer a free SSL certificate (Let’s Encrypt), with which you can have your website working under HTTPS for free!
And, once you have installed the SSL certificate and your website already works under HTTPS, seriously consider creating one more protection barrier, installing HSTS to improve security.
Install an SSL certificate and migrate your website to HTTPS
Create daily backups of all your data
Automatic daily backups of all your data (web and databases) alleviate many of the worries and headaches.
Many web hosting providers provide this option for free, so don’t hesitate to ask them.
Having a backup is vital in case someone manages to enter your website and steal data or cause damage to your files. Starting a website from scratch is expensive and difficult, but rebuilding one that has the data stored is much easier.
Protect your website from SQL Injection! Configure your queries to be parameterized
So far, this is one of the most technical steps that you will have to execute knowing how to protect your website from attacks based on SQL injections or SQL injections, something that is doing a lot of damage to many websites every day!
SQL is a structured query language through which the information in the web page databases is accessed. The web pages where you find forms or buy/sell transactions accumulate information in their databases, which are vulnerable to SQL injections.
SQL injections allow the hacker to enter your website’s database and download customer data, invoices, bank accounts, passwords, etc.
A standard or slightly restrictive search configuration, on your website, allows SQL injections by hackers, which are nothing more than the infiltration of false codes and intruders with the aim of entering your database. web page. Once the intruder has managed to enter, he can download all the data from your website: customer data, invoices, bank accounts, passwords, etc.
This serious security hole is solved by parameterizing the SQL queries as we see below.
This would be a basic query:
“SELECT * FROM table WHERE column = ‘” + parameter + “‘;”
If the hacker changes the input parameter to ‘ OR’ 1 ‘=’ 1, which is very simple, now the previous query would become:
«SELECT * FROM table WHERE column =» OR ‘1’ = ‘1 ′; »
When making the alteration, which seems hardly visible, it follows that ‘1’ is equal to ‘1’, which is a positive query and in this way the attacker could access the information in the database registry of data, being able to carry out the following query, with that information, thus achieving access to where the information stored in the database appears.
How to protect the website from SQL injection attacks? A simple way to prohibit this type of easy access to malicious people is by parameterizing the SQL queries as follows:
$ QuerySQL = $ pdo-> prepare (‘SELECT * FROM table WHERE column =: value’);
$ QuerySQL-> execute (array (‘value’ => $ parameter));
Protect your website with the content security policy (CPS)
The content security policy or CPS is useful to keep your website safe from XXS (Cross-site Scripting) attacks, which are characterized by the fact that a third party injects malicious code (with a virus) to all your pages. Once this code is injected, when a user browses your web page, from whatever device it is, they will be infected with this virus, which usually carries an intrinsic JavaScript code, but can adopt another type of language, with the aim that the pirate has designed, such as stealing your personal or financial data.
By applying CPS you avoid XXS (Cross-site Scripting) attacks that would infect your users’ devices to steal personal or financial information.
In this way, when a hacker tries to make maneuvers from his web domain (external to your web domain), the user’s browser will detect that this web connection attempt is not valid or authorized, and will reject it.
How to protect the website with the CPS? Simply put, you will need to add HTTP headers to your web page, where you authorize web domains and specify valid script sources (eg from Google Analytics, Google Tag Manager, Google Ads, etc.).
XXS attacks are very easy to perform and can appear even though a simple blog comment.
How to detect if your WordPress website has been hacked and fix it yourself
Keep your files and folders safe with the proper permissions
A web page is reduced to a pile of files and folders. In these, all the corresponding information is stored, as well as codes and scripts necessary for your page to work as it should.
Each folder and file has a configurable code (permissions) that allows controlling the functions that can be executed in it, such as reading, writing, modifying, etc.
If your folders and files are configured so that anyone can read, write to them or perform certain actions, then it means that you are vulnerable to any invasion of your website through it; It is the gateway for the hacker.
When the permissions of the files and folders are not correct, a person with basic hacking knowledge will easily enter your website, and the results can be the worst because they can do whatever they want with it.
Configure the permissions of all the folders and files of your web server; folders at 755 and files at 644.
How to protect the web page, its files, and folders? To avoid this scenario, it is recommended to assign to the folders (directories) the permission code 755 and to the files the permission code 644. Each of the 3 numbers indicated, gives certain specific permission to the owner of the file, to a person who is within the group of people who own the file, and the reader (public), respectively.
Do a regular cleaning on your website
Keeping your website clean and free of unused files is vital to keep it safe.
From time to time it is recommended to do a deep cleaning and to facilitate this process you have to keep the files well organized.
It tries to remove all the obsolete or old files to avoid the entry of viruses and to be able to detect malicious files.
Be on the lookout for error messages, no clues to protect your website!
The error messages do not contribute anything relevant to the users of your website but, without a doubt, a hacker does know how to take advantage of it. How to protect the website and avoid displaying this information?
When you create error messages, be cautious and leave only the information that is really useful and necessary. Leave the details for the logs (LOGS) of your server.
Customizing your error messages on your website is efficient to provide basic help to the user and can prevent your website from being very easy prey for attacks such as SQL injection that I mentioned earlier.
Conclusion:
take action as soon as possible to protect your website The security of a website is not a task for later. You may think that you are not a target of hackers, but statistics reveal that last year cyberattacks took more than 5 billion dollars. For this year, experts seem to agree that, with such an increase in attacks and fraud attempts, the losses will be much greater, making those who have not yet suffered the first attack of this type more vulnerable.
Are you going to wait for the enemy to catch you? Ensuring the security of your website is essential to conquer search engines and lead your niche because, if customers feel vulnerable, they will not make any transactions on your website or want to provide their data.
The more secure your website is, the more likely you are to have a high conversion rate and make a profit.
You don’t have to be the United States Secret Service to keep your files and database safe, so don’t let excuses keep you from your goal.
If despite these tips, you still have problems with your website, in another article we explain how to fix your website easily.
Do you think this article is helpful? For sure YES! That is why I invite you to share it with your friends on social networks.
Below is a simple form that you can fill out to send me your questions and comments. And so I will contact you and help you! If you want to tell me how your results are going when applying these tips, I will be waiting for it, because that way I will help you in the process.
