Skip to main content

5 Tips and Tricks to Improve Your Server's Security

Your web servers are the focal point of all your website's security; they are where all of your information gets stored and because of this they essentially constitute what your website is.
Thus, it's not surprise that you have to keep these servers as secure as possible at all times to protect not only your online presence but also your customers and anyone else who entrusts you and your site with their sensitive private information.



Luckily, keeping your servers secure isn't really that hard and it's certainly not expensive. With a few straightforward and relatively easy to implement steps, you can eliminate an overwhelming part of your chances of getting hacked, seeing your site destroyed or your information stolen. Let's go over a few tips and tricks now.


Buy Dedicated Web Servers from a Reliable Provider

You will almost certainly be hosting your website or sites on a commercial hosting provider's servers, and this is a good idea, since they will already have their own professionally designed security measures in place. Nonetheless, not all hosting providers are created equal and not all types of hosting are equally secure. For one thing, for extra security and traffic handling capacity, you're better off buying your own dedicated server space from reliable webhost. This will cost you at least 5 times more per month than regular shared hosting, but having your own servers also makes your security much more solid and your ability to cope with Denial of service attacks more robust.



Buy Secure Hosting

In addition to buying dedicated server space, you should also review the security features your host provides to its clients. These should include: up-to-date server apps like PHP, MySQL, Apache and others, strong internal firewalls within the webhosts systems, automatic backups, internal antivirus protection, DDoS (distributed denial of service attack) protection and SFTP (secure file transfer protocol), which allows you to securely move files to your servers (thus website) from another machine.

Regularly Update All your Server and Website Applications

Your server based applications will probably be automatically updated by your hosting provider, but you will almost certainly have your own list of third party applications working on your website and installed on your servers; update these regularly. These might include applications like Flash, JavaScript or Adobe Acrobat and they could also include third party website content management systems like WordPress and all of their associated plugins. At least once a week, go through all of these applications and make sure that the versions you're using are the latest available. Outdated apps are a hacker's chief attack vectors.


Use Secure Passwords

Your hosting cPanel, servers, MySQL, FTP and any other password protected parts of your server and website controls should all be protected by highly secure passwords that are at least 10 characters long and consist of randomized upper and lowercase characters, numbers and symbols all jumbled together. An overly simple password can easily be cracked by dictionary attack software that can run millions of word combinations per second. You should be particularly careful about also adding internal passwords inside your cPanel and servers that give different levels of access to different people if you have multiple site administrators accessing your website's servers.

Secure Your Personal or Work Computer

A convenient and often forgotten access point for attackers trying to get into your servers will be your actual computer. This machine will probably contain the desktop File transfer protocol (FTP) application which you use to transfer files and media to your website. If this is the case, keep this machine safe! Install strong and regularly updated antivirus/anti spyware software on the computer, limit access to it to trusted people and make sure that both the computer and the FTP inside it are both password protected and have automatic login disabled, forcing you to type in your passwords each time you leave them for more than a few minutes.

A hacker can easily sneak hack software and malware into this computer and use it to gain access to your actual web servers either through direct attack or simply by recording the passwords you type in to reach all your secured systems. Again, keep the computers you use to access your servers secure!

Use Your Own Web Server Protection Software

Aside from the protection offered by your hosting provider's security software, you should also set up your own defense systems by using third party server and website protection applications. A powerful security software package can offer your servers diverse protection against viruses, malware, Trojan horses, data thieves, spy bots and DDoS attacks, amongst other things. Some very reliable and highly affordable server/website security products include membership software services such as Incapsula or Cloudflare.


Encrypt your Data Files

As a last quick server security tip, we should also mention internal data encryption. While encrypting any sensitive information stored on your server won't actually protect the server itself from attacks, it will at least ensure that anyone who does manage to hack your system has unreadable files on their hands, thus blocking them form finding out what sorts of customer data and other information you've got stored.

About the Author: John Dayton is a leading expert on server security tips. When he is not writing, you can find him at home or working as a consultant to partners like LWG Consulting.

To write guest posts for us, please follow the link below

Write Guest Articles for us

Comments

Popular posts from this blog

5 Blogging Mistakes That Can Be Fixed Easily

This is a guest post by Crystal J. Briscoe about five common Blogging Mistakes That Can Be Fixed Easily . One of the most annoying things about reading a really good blog content is the inability to navigate the blog or change the view with ease. While most bloggers usually make certain errors while building their blogs, the following are some of the mistakes that can make your blog useless and what you can do to fix them. 1) Using Mysterious Fonts For Your Blog Contents Whereas making use of distinct fonts to design your blog logo or to create titles for your sidebars can provide your site with a unique look, they should not be used for creating blog content. Fonts that every blogger should use when developing contents for their sites are Times New Roman, Georgia and Serif. This is because these fonts are easy to read by virtually anyone. 2) Building A Compacted Content Zone First-time web developers usually make the error of stuffing their content in a small region on their...

5 Benefits of Cloud Hosting

The popularity of cloud computing in recent years can be attributed to many things. The ability for many users to share resources is certainly one of them, by doing so a group of users can leverage the participation of multiple users into significant cost savings. One of the many aspects of cloud computing is that of cloud hosting. Cloud hosting is the use of multiple servers that are all connected together. These connected servers are cumulatively referred to as a cloud. Sites on the servers may use resources from any or even all of the servers in the cloud. The concept of cloud hosting has become very popular during the last few years because all of the hard drives, processing power and memory are shared by all of the sites in the cloud. Servers can be added to or removed from the cloud according to need. The benefits of cloud hosting are numerous but five of the more significant and apparent ones are listed below: 1. Scalability The concept of using numerous servers that a...

Technology through the years

"Technology" is a word which has come to mean a variety of different things to different people. Some may imagine space stations, while others

Preventing a Vulnerable Network with Good Patch Management

Every admin knows the importance of good patch management, but not every admin knows the tips and tricks that make for a great patch management strategy. There is so much more to patching than just running Windows Updates, and in this article we’ll share with you the nine tips for great patch management to prevent your network from having vulnerabilities. 1. Stay informed You can’t fix it if you don’t know it’s broken, so staying informed is the right place to start. Subscribe to the security and patch bulletins from your operating system vendors and your critical application vendors. You really want to consider subscribing to a third party alert like the ones offered by SANS, Bugtraq, or others so you are aware of vulnerabilities even when there aren’t patches yet, and also to cover the smaller but no less important applications that are on your network. 2. Test your patches I’d rather deploy an untested patch than not patch at all, but I’d really prefer to test all patches fi...

Asus Eee Pad Transformer Prime: World’s First Supercomputer Tablet

This is a guest post by Alia Haley . In this post, we will talk about Asus Eee Pad Transformer Prime, a tablet based on Android operating system. This is the successor of Eee Pad Transformer tablet PC and world’s first tablet with ARM Cortex A9 processor (Nvidia Tegra 3 Quad Core CPU). With use of this processor, this will be the most powerful consumer tablet and ultimate consumption device on the planet. Performance, gaming experience, graphics everything will be maximized still with a battery backup of 12 hours with a 22 WH battery. Are you excited? Read on to know more. Apart from a star processor, Asus is throwing many other extra goodies to make sure you buy the new Transformer Prime. Starting with the looks, the design is reworked with finish that is more metallic, thickness has gone down to 8.3 mm and the weight decreases to 586 grams. If we talk about the original Transformer, the thickness was 12.9 mm with a weight of 690 grams. The metallic finish makes the tablet more dur...

How To Maximize Real Time Communications

Voice over Internet Protocol (VoIP) and the primary rate interface (PRI) services that come with the infrastructure have given offices many different options when it comes to real time digital communications. Some of the features of these services can be integrated into an office so that problems are more quickly solved and communications become more efficient and cost-effective. These ways to maximize real time communications in the office can rely on intrinsic features of the technology or they can involve carefully chosen suites of applications that work together. Session initiation protocol (SIP) forking is a feature of many business VoIP services . SIP forking allows a single digital channel to be forwarded to multiple destinations. This can be used to send a call from a single phone to multiple other devices. If an employee is not at a particular station to answer a phone, then the signal can be forked to a cell phone or another location until the employee receives the call. Th...

How to Reduce Your Need for Home Computer Repairs

This is a guest post by Sachin about how to Reduce Your Need for Home Computer Repairs . Some of us are still afraid to use our computers for fear of calling for computer repairs. In most cases, we will not need pc repairs or laptop repairs if we follow some basic principles. Computers only have a limited lifetime. The fact is the world of technology is changing so fast, if we don’t spend the money to stay with that change, personal computers actually end up costing us a lot more. Here is how to reduce, if not completely avoid the need for repairs. New devices . If you are using a personal computer that is more than 2 years old, you can bet you will start to have problems. The problems are not related to the hardware. The only real place you have problems is with your hard drive. Replacing that will not cost much money. The problems relate to protocols of communication and the speed of your device. Older machines are slow, and cannot keep up-to-date software running. New device...

Pros & Cons of Shared Web Hosting

Shared web hosting is a source where multiple websites share the resources and space of a web hosting server, keeping website partitioned from each other while creating a secure environment for multiple sites. The Web hosting company charges variates in accordance with the space and bandwidth requirements of client, as each site operate on its own space and bandwidth. When one purchase/ hire a shared web hosting, domain name is included and added to server which enables to develop / upload website and allows getting it online. As a general rule, it is a good feasible idea, to go for shared web hosting specially when in small business scale with limited sources and budget. Before making any hosting decision, the concept of shared web hosting and it’s all pros and cones must be kept in mind. Pros of Shared Web Hosting The main advantage of shared web hosting is that you are free from worries, to up-keep of complicated server technology and proper technical maintenance. That’s the w...

Company Takes on Social Media Background Checks for You

There was a day and age where job applicants only had to concern themselves with what was on their resumes and pretty much nothing else. In today's Internet age, however, social media is a big factor and is becoming even bigger as people look for work in the challenging economy. Whether it is what one perceives as an innocent picture or comment that was meant in jest, what individuals say on their Facebook, Twitter, LinkedIn, Google+ accounts, and other social media sites is being more closely monitored. According to one CareerBuilder survey of approximately 2,000 hiring managers and human resources professionals, 37% of HR managers reported using social media sites to attain more information on prospective candidates as part of the background checks process. Meanwhile, another 11% said they would be doing likewise soon. For those businesses that may just be starting out or have been around for a while but are newer to social media, social media background checks need to be d...