For a long time, I recommended DropMySite for offsite website backups that didn’t impact your site. I even wrote about using DropMySite with NameHero and why it was so good. Compared to other backup solutions, DropMySite was far cheaper and more efficient. It gave you a fixed amount of storage and backup for unlimited sites […]
Category: Website Security
Is It Wise to Block (Almost) All Bots?
Your write and maintain your website for human visitors. And yet when you peer into your analytics logs, you see that the vast majority of hits to your server come from bots. These don’t show up on client-side measuring tools like Google Analytics, but they appear on the server logs. Most traffic these days is […]
Forget Blocking – A Cloudflare JS Challenge Is The Best!
As website owners, we want to make our sites as accessible as possible to the right people. Unfortunately, there’s an inverse trade-off between strict security measures and the possibility of blocking real visitors. For example, I’d recently written a post on rate-limiting on Cloudflare, where we stop spammers from hammering our server with costly requests. […]
How to Protect Yourself From Network Traversal Attacks
The other day when looking at my ConfigServer Security logs, I saw the following line: I’ve been getting a few of these recently. Attempts to access paths on my server that look like this: /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/hosts It looks strange, because these are encoded characters. “%2e” stands for dot (.). So the path above is actually trying […]
Can We Block External Access To PHP Files In WordPress?
Sometimes when checking my VPS logs, I’ll see a large number of attempts to access PHP files on my server. These files will be of different names and different paths – all attempting to probe my site for weaknesses, find expired plugins to exploit, and more. And this is after I protect my WordPress site […]
Is It Safe To Disable The Antivirus On Your Linux Server?
Under what circumstances can we safely disable ClamAV – the ubiquitous antivirus on a Linux server? I recently migrated my site WP-Tweaks to a NameHero “Managed Cloud” VPS. The increased dedicated resources make my site hum along nicely – operations that used to take a long time were near-instantaneous. I’ve often found myself randomly opening […]
How To Give Someone Temporary Root Access
The other day, I had a problem with my server, where I got an e-mail saying that some SSL certificates were about to expire. These came with the original VPS, and I’d already installed my own SSL certificates, so I wasn’t worried about my webserver going down. However, I WAS worried that something else might […]
How To Add A Public Key To Your Server Without SSH
I recently migrated to a new VPS server and needed to import a public key for my backup service so that I wouldn’t have to hand out a username/password combination. It had been a while since I’d used SSH for anything and didn’t feel like taking the time to learn everything from scratch again, so […]
How To Minimize Scraping Of Your Site
Have you ever come across a website that’s almost an exact duplicate of yours? It can be a somewhat disorienting experience! It seems incredible that a 3rd party would take your content and claim it as its own without attribution. They even copy the images! These people are called “scrapers”, and site scraping can be […]
Disable JSON REST Entirely on WordPress!
It’s been a cat and mouse game for me over the past few months, dealing with the REST API requests made to my WordPress site. The overwhelmingly large majority of these requests are not benign. They’re hackers scanning for weaknesses. I’d written an article earlier on how I disabled JSON username enumeration based on the […]
