<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; website security</title> <atom:link href="http://www.ghacks.net/tag/website-security/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 09:52:46 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Website Security Testing Software Websecurify</title><link>http://www.ghacks.net/2010/03/29/website-security-testing-software-websecurify/</link> <comments>http://www.ghacks.net/2010/03/29/website-security-testing-software-websecurify/#comments</comments> <pubDate>Mon, 29 Mar 2010 14:45:10 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Linux]]></category> <category><![CDATA[Mac]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[linux software]]></category> <category><![CDATA[mac software]]></category> <category><![CDATA[Open Source]]></category> <category><![CDATA[security-software]]></category> <category><![CDATA[website]]></category> <category><![CDATA[website security]]></category> <category><![CDATA[website security testing]]></category> <category><![CDATA[windows software]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=24027</guid> <description><![CDATA[Webmasters need to be jack of all trades. They need to configure and design their websites, interact with the community, make regular backups and ensure that the website is secure and up to date so that it cannot be hacked, at least not by button pushers. Tools aid the webmaster in securing and testing the [...]]]></description> <content:encoded><![CDATA[<p>Webmasters need to be jack of all trades. They need to configure and design their websites, interact with the community, make regular backups and ensure that the website is secure and up to date so that it cannot be hacked, at least not by button pushers.</p><p>Tools aid the webmaster in securing and testing the website. The programs available depend largely on the type of website but there are several general tools that can be used.</p><p>Websecurify is one of those tools. It is an open source program that is available for Windows, Linux and Macs.</p><p><span
id="more-24027"></span>Webmasters who run it can test a website against a fixed set of known security vulnerabilities and issues that the program will display in a report if found.</p><p>The program is extensible which means that it is possible to extend the functionality with add-ons. The project website <a
href="http://code.google.com/p/websecurify/">contains</a> documentation for that feature.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2010/03/website_security_testing-500x428.jpg" alt="website security testing" title="website security testing" width="500" height="428" class="alignnone size-medium wp-image-24028" /></p><p>Webmasters who want to use the program right away need to click on the launch test link in the main interface. This opens a configuration window where a website url has to be entered into the target form.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2010/03/web_site_security-500x294.jpg" alt="web site security" title="web site security" width="500" height="294" class="alignnone size-medium wp-image-24029" /></p><p>A report window is shown with all issues that have been found. A short explanation is displayed in the report window but it is generally required to research the issues found further.</p><p>Websecurify comes with tools like a basic web browser or error console that can be helpful in the analysis and research of issues.</p><p>It takes some time until the program finishes a website security test completely. The window sometimes was not responding to user input during that time but recovered from that eventually.</p><p>Websecurify can be downloaded <a
href="http://code.google.com/p/websecurify/">from the</a> software&#8217;s Google Code page.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/03/29/website-security-testing-software-websecurify/feed/</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>Website Security Check</title><link>http://www.ghacks.net/2008/12/16/website-security-check/</link> <comments>http://www.ghacks.net/2008/12/16/website-security-check/#comments</comments> <pubDate>Tue, 16 Dec 2008 17:28:40 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[The Web]]></category> <category><![CDATA[check websites]]></category> <category><![CDATA[hidden links]]></category> <category><![CDATA[malicious links]]></category> <category><![CDATA[unmask parasites]]></category> <category><![CDATA[website scan]]></category> <category><![CDATA[website security]]></category> <category><![CDATA[website security check]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=9088</guid> <description><![CDATA[Webmasters should pay close attention to their websites. Just missing one update of the blogging software, forum script or database engine can be enough to give attackers the means to take over. Websites can be defaced or &#8211; which some webmasters consider even more seriously &#8211; manipulated in various ways. This includes links to other [...]]]></description> <content:encoded><![CDATA[<p>Webmasters should pay close attention to their websites. Just missing one update of the blogging software, forum script or database engine can be enough to give attackers the means to take over. Websites can be defaced or &#8211; which some webmasters consider even more seriously &#8211; manipulated in various ways. This includes links to other websites, malicious content that is served to visitors or changing the account ID of the Google Adsense account so that the hacker earns the money &#8211; or part of it &#8211; from that moment on.</p><p>All of this can have consequences for the webmasters. Search engines can punish websites who manipulate rankings, advertisers can kick webmasters and security software and scripts can flag a website to be malicious.</p><p><a
href="http://www.unmaskparasites.com/security-report/">Unmask Parasites</a> is one web based security script that can scan a website for hidden content that might be an indicator that the website was hacked or manipulated by someone else.</p><p><span
id="more-9088"></span>It works without registration. All the user needs to do is to enter a url in the search form and let the script do the rest. The script will display a ranking like &#8220;This page seems to be clean&#8221; listing all the external references &#8211; scripts and links &#8211; that it founds on that page.</p><p>Webmasters can follow those references and let the script analyze them as well or perform additional tests on the website. The two additional tests are the following:</p><ul><li>Finding infected web pages using Google. This is done by using the site parameter in combination with popular spam keywords.</li><li>Display Google&#8217;s Safe Browsing rating for the website.</li></ul><p>These tests can aid the webmaster in spotting hidden malicious links in a timely manner. It is possible to bookmark the test page and open it again which will initiate a new scan of the website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/12/16/website-security-check/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Secure your server with htaccess</title><link>http://www.ghacks.net/2008/03/31/secure-your-server-with-htaccess/</link> <comments>http://www.ghacks.net/2008/03/31/secure-your-server-with-htaccess/#comments</comments> <pubDate>Mon, 31 Mar 2008 17:08:47 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[The Web]]></category> <category><![CDATA[apache]]></category> <category><![CDATA[basic auth]]></category> <category><![CDATA[htaccess]]></category> <category><![CDATA[htpasswd]]></category> <category><![CDATA[password protection]]></category> <category><![CDATA[website]]></category> <category><![CDATA[website security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=3672</guid> <description><![CDATA[I apologize if this topic drifts a bit away from the usual ones you find here at ghacks but I thought it would be extremely useful for everyone who has a server or webspace that supports htaccess and htpasswd. Htaccess files can do much more than just secure a directory on your server or website but I want to concentrate on this topic because it is something that I have been using on some of my websites for a very long time to increase security.]]></description> <content:encoded><![CDATA[<p>I apologize if this topic drifts a bit away from the usual ones you find here at ghacks but I thought it would be extremely useful for everyone who has a server or webspace that supports htaccess and htpasswd. Htaccess files can do much more than just secure a directory on your server or website but I want to concentrate on this topic because it is something that I have been using on some of my websites for a very long time to increase security.</p><p>I use it mainly to secure certain directories on my websites from being accessed without the proper authorization. This is the admin directory in the case of WordPress for instance but could also be used to secure a directory that hosts some valuable files.</p><p>I would like to point out two possibilities that secure a directory with .htacess. The first is to protect the directory by only allowing users with a certain IP or IP range access to it. Everyone else would receive an access denied error message.</p><p><span
id="more-3672"></span>The second possibility would be to create usernames and passwords that have to be supplied before accessing the content.</p><p><strong>IP Protection:</strong></p><p>Create a .htaccess file and add the following code to it:</p><p><code>AuthName "Protected Content"<br
/> AuthType Basic<br
/> <Limit
GET POST><br
/> order deny,allow<br
/> deny from all<br
/> #Comment<br
/> allow from 255.255.255.255<br
/> </Limit></code></p><p>Change the IP address in the last line to the one used by the user / users. You can use wildcards * if the user is receiving dynamic IPs from his ISP. It is possible to add as many allow from lines to the .htaccess file as you want. Place that htaccess file in the directory that you want to protect. (all subdirectories are affected as well.</p><p>The problem with this kind of protection is twofold. If your IP changes, say you are on holiday or accessing from a different location, you need to add or change the IPs in the htaccess code. Users who happen to have a IP of that range can access the content without problems. This is usually a user from the same ISP.</p><p>A more secure protection is the basic auth protection.</p><p><strong>Password Protection:</strong></p><p>Whenever a user tries to access a directory or file a popup will appear asking the user for a username and password. This method requires two files, a htaccess file and a htpasswd file. The htpasswd file stores the usernames and encrypted passwords and should be placed outside of the root directory of the website.</p><p><code>AuthName "Restricted Area"<br
/> AuthType Basic<br
/> AuthUserFile /path/to/.htpasswd<br
/> AuthGroupFile /dev/null<br
/> require valid-user</code></p><p>Since the passwords are encrypted you need to use a script to do that. A working one is the <a
href="http://www.htaccesstools.com/htpasswd-generator/">htpasswd</a> Content Generator. Just enter a username and password and click on encrypt. Paste the line on the results page into the htpasswd file and place it exactly in the path that you specified in AuthUserFile.</p><p>It is possible to combine both protections for added security. I would begin by evaluating if your webhost is allowing those kind of files.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/03/31/secure-your-server-with-htaccess/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> </channel> </rss>
