Monday, November 26, 2012

Protect Your Website!

"Freedom of Speech" Everyone has the ability to speak their mind without limitation. Yet, this has been questioned many times in different ways. In social media, freedom of speech is a widely accepted convenience wherein conversations are often not be restricted (or monitored); this give rise to the question about security and privacy.

Social sites have the power to spread stories and information that increase awareness. Once in a while, people assign different values, multiple comments and various approaches; some are compliments and some are aimed to spark controversy. In instances like these, online moderation is a valuable service.

SIGN-UP!

Moderation can start from the very point when users sign-up. The sign up process requires users to provide information before granting them the ability to comment on your website (example: name, email address, but not phone numbers or other type of codes). This is done to ensure they are real people using real identities.

COMMENT MODERATION

Moderation of comments is a tedious task but it is necessary.

1. To avoid offending others. Racist, sexist must be strictly controlled to keep your site pleasant. 2. To delete or remove ridiculous off-topic discussions. Messages that are not related to the subject. 3. To encourage proper online activities. Each should be sensitive enough to consider the feelings of others. To enforce this, moderation pushes for proper decorum online. 4. To avoid unlawful and distracting advertisements. Conversations that promote or publicize their products and services in direct violation of set rules. 5. To avoid personal attacks. Some users post negative comments and use profanity as a form of bullying or defamation. Moderation aims to eliminate these activities. 6. To avoid fraudulent generalizations. Some users have the knack for using stereotypes and profiling by using words like "all of them" or "a lot of them" these result in unnecessary debates and arguments. Moderation identifies users who cause this and take action to remove these comments or ban the user(s).

Comment moderation is important in maintaining the reputation and dignity of a website. It guarantees that the user experience does not decrease, that members keep signing up and that all rules and regulations are followed without exceptions. Moderation is indispensable in the goals for growth of a business website; and though it is a hard task that might seem unending, it is still a task that needs to be done nonetheless.

Rules can be posted to restrain comments and guide users, but it is unavoidable in any website that has numerous users to not have violators. These violators may either be committing offenses unintentionally or intentionally. Having a moderation service will make violations identifiable, preventable and virtually non-existent. Online moderation gives business and website owners the power and ability to correct mistakes, approve or reject posts and eliminate sources of conflict.

Protect your website from abusive users. Guard against spamming, trolling and flooding.

An Explanation of CISPA for Small Businesses   Protect Your Privacy With Reputation Management   Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

What Are SSL Certificates? Why Is It So Important For Every E-Merchant To Have Them?

The SSL cert is the simplest and fastest way for anyone who promotes the sale of goods or services online to protect customer transactions from conniving, credit card pilfering hackers and the malware they devise to help them in their sticky-fingered criminal endeavors. And this makes equipping your site with SSL Certificates vital. Because shopper apprehension of credit card stealing hackers is the No.1 reason why e-merchants lose sales! - Otherwise known as Shopping Cart Abandonment.

Top SSL Certificates give you quick online issuance, advanced encryption, 24/7 e-merchant support, and strong warranties. But most important of all, an SSL Certificate helps you create a secure e-business environment in which sales can proliferate. The best SSL Certificates are designed with a 2048 bit signature, and are recognized by 99.3% of all Internet Browsers. This helps maximizing the reach of your e-business.

Most top SSL Certificates also feature another safeguard called "Point-to-Verify Site Seal Technology." Point-to-Verify Site Seals, or trust marks, verify the steps you've taken to keep customer transactions secure. These steps are publicly displayed whenever a site visitor hovers their mouse cursor over a seal.

Now you know what an SSL Certificate is and how it will help you and your online business thrive. But one important question remains. Of the three most powerfully used SSL types, which one is right for you? Let's find out.

The most basic SSL Certificate you can deploy is the DV SSL

DV SSL stands for Domain Validation Secure Sockets Layer. When your Website employs a DV SSL, its Certificate Authority has confirmed that your site is owned by an individual with a specified and fully registered email address. Top DV SSL provide your Website with Interactive Trust Marks site visitors can hover over to read the actual authentication information the Certificate Authority offers.

An even more popular, basic SSL Certificate is the OV SSL:

OV SSL stands for Organization Validation Secure Sockets Layer. When an e-merchant chooses this more advanced basic SSL Certificate, his Certificate Authority has confirmed both that your Website is owned by an individual with a specific email address, and that your Website is linked to a fully registered brick and mortar address. Top OV SSL provide you with floating and anchored trust marks to display throughout your Website. These increase customer confidence because their interactive capacity allows your potential buyers to hover over or click on them to read the kind of authentication information about you, your Website and your company that is very reassuring.

The most advanced SSL Certificate is the EV SSL:

EV SSL stands for Extended Validation Secure Sockets Layer. And the technology built into an EV SSL definitely supplies your Website's customers with extended validation! The EV SSL validates the security and integrity of your site and the location and identity of your company. But that's not all. Once you purchase an EV SSL, two things happen as soon as an online shopper types your URL into their computer's address bar. FIRST; their address bar turns green, alerting them to the fact that yours is one of the most secure, high quality e-merchant sites on the Web. Then SECOND, their view of both your Home Page and the Site Pages that follow includes floating and anchored trust marks. These insignia announce that your customers' credit card transactions are fully protected and can not be hacked. Finally, top EV SSL are bundled with tools that scan your Website for malware. You are also provided with the PCI Scan Compliance Reports you must submit to banks and credit card companies quarterly. And, of course, the best EV SSL come from Certificate Authorities that provide impressive Warranties and 24/7 technical support services.

So now you know why you need SSL Certificates and all about the types there are to choose from. Want a tip? If you're an e-merchant attempting to make site sales without the help of SSL, you're doing your company, your customers and your bottom line a disservice. Look into getting the right SSL Certificate today.

An Explanation of CISPA for Small Businesses   Protect Your Privacy With Reputation Management   Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

Purging Virus Threats From Your PC for Better Protection Online

Protection from virus threats can be a never ending process as virus attacks are largely present online. Even if you keep a sharp watch on threats you may find yourself overlooking one at some point in time.The best way to deal with it is to install a robust antivirus program and keep it updated against the latest online threats. Adware, spyware, malware and Trojans have never ending effects on our daily schedule online thus it seems difficult to keep a track over vulnerable activities. It's an obvious fact that you won't like to install such programs on your PC thus it's important to understand the complexities involved with such threats.

It's certainly more critical to understand which malware is dangerous and which is easy in purging threats from your system. Users start experiencing certain hassles while operating a system without computer virus protection, which may result in slow down of system, crash, data corruption, pop-up windows and slow internet speed. In the worst cases you can even lose your personal information, which is likely to be used for malicious purposes. Online security from spyware and Trojans are the example of some of the few solutions offered by experts.

Such assistance helps an individual to engage proper techniques in order to store and wait for total repair. So be it computer spyware removal or PC diagnostic, dynamic antivirus protection software downloads can help fix the problem efficiently. Viruses manifest themselves with different applications and can destroy the entire system badly. It's essential to stay vigilant all the time whenever you are online as spyware program may use other application in order to perform unauthorized functions. An antivirus program can be a better option as it can really help you detect all the hidden threats and it certainly comes for free. These antivirus programs can be updated for free as there are various versions you can choose from online. Free antivirus programs are good enough to make arrangements for your own system. A real time antivirus program provides automatic protection against database updates, on-demand system scanning, removable media checking and download monitoring very well. The best antivirus program works usually strong and can very help you update the database as the paid ones. Various defense systems can be bundled together to receive the features of the best antivirus protection.

It's important to make informed choices and check the reviews of other various best antivirus software online. Take the most of your virus protect software and solve your purpose perfectly as safety is the basic concern online.

An Explanation of CISPA for Small Businesses   Protect Your Privacy With Reputation Management   Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

PHP/MySQL: Easy Solutions to Protecting Passwords in a Database

One of the most common errors that a novice PHP/MySQL programmer will commit when creating a membership site is storing passwords in the database without securing them in some way. Why is this a problem? If a database is hacked, and this can occur easily without sufficient safeguards throughout the code of the entire website (one loophole and it could be accessed and the information harvested), a hacker could easily discover all over your users' passwords and not only use this information to take control of their accounts (including admin accounts!) but also accounts of other services of which a user may be using the same password (Gmail, Facebook, Twitter, PayPal, you name it!).

Perhaps an attack this drastic isn't as much of a problem if you have good code that prevents SQL injections and the like, but there is still the brute force or dictionary attack options that hackers could use to get a user's password, including the admin's password. It is therefore important for your own site and the privacy and safety of your users to ensure that your passwords are safely stored in your database. When a user gives you his password, he is expecting it to be safe; so don't let your users down!

There are many ways a PHP programmer can encrypt passwords before storing them in the database. The most common method is using a hash, which means that the process of encrypting a password cannot be reversed; so if a user loses her password, she must be given a new one as the old one cannot be decrypted and given back to her. Hashed passwords are usually checked during login in the same manner that an unencrypted password is: by comparing strings. There are exceptions to this method in stronger hashes, which I'll get to.

The easiest method (and a very common one) is through the use of md5 to encrypt the password. Though this method is incredibly easy, and certainly preferable than nothing at all, it is not very difficult to break the encryption, and there are many sites that help in doing exactly this. I tried one of these sites once, to great success.

But, if you feel this method will be secure enough for your site, at least for the time being, this is how it would be done:

$encrypt_pass = md5($pass);

Where $encrypt_pass is the encrypted password and $pass is the variable containing the password you wish to encrypt. But since this method is fairly insecure, let's look at other options.

A very similar but slightly better hash is sha1. It works in much the same way as md5 does, except it returns a 160-bit fingerprint rather than a 128-bit fingerprint:

$encrypt_pass = sha1($pass);

Another option is using a salt on top of md5 or sha1. The way this works is that a string is added to the password before md5 or sha1 hashes it. This is fairly good to prevent brute force or dictionary attacks, as the theory behind it is that a user's weak password can be strengthened by the salt before being hashed and inserted into the database. For example:

$pass = "pass123";//Let's say this is the password the user entered

$salt = "1y2Jdu1D8!b";//This is the salt algorithm

$encrypt_pass = md5($salt$pass);//We add the salt and hash

If the hacker can discover what the salt algorithm is, however, this method is just as weak as an ordinary md5 or sha1 hash. So what else can we do? How about combining methods?

$pass = "pass123";

$salt = sha1(md5($pass));

$encrypt_pass = md5($salt$pass);

Though this is not foolproof, it's really strong, and nearly impossible to crack without knowing the algorithms, which usually means access to the .php file. Of course, if you want to keep these passwords safe from others who may be working on a project with you and do have access to the files, there is yet another option to consider.

I personally like to use the "Portable PHP Password Hashing Framework" or phpass, an open-source solution on which password encryption for phpBB and WordPress is based on. With this system, a hash is different every time for the same password, meaning that one must use phpass's function to compare two passwords. Theoretically this makes it impossible to decrypt.

In order to use this framework, you must download the files from openwall. There will be a PHP file there called PasswordHash .php that has the hash class. Upload it to your server and require (or include) it on the page where the password will be encrypted. You can then call the class to hash the password:

$t_hasher = new PasswordHash(8, FALSE);

$hash = $t_hasher->HashPassword($pass);

Then, to check two passwords (during login for instance):

$check = $t_hasher->CheckPassword($pass, $hash); //$pass is the password being check and $hash would be the hashed password stored in the database

if ($check){ /*Let the user through*/ }

if(!$check){ /*Don't let the user through*/ }

The test .php file is well commented and will have more functions that may be useful to look over. It will also test everything to make sure it's working on your system.

So that's a quick rundown of what you can do to keep your site and your site's users safe. Please, please don't just store the passwords as plain text in your database. It's bad practice and it's not keeping the trust your users have in you when they register on your site. It's easy to do, and highly important.

An Explanation of CISPA for Small Businesses   Protect Your Privacy With Reputation Management   Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

Why a Managed Security Services Provider Is a Business's Most Critical Partner

A business's network assets are critical to its success. Despite their overwhelming importance, however, too many businesses leave those assets to chance. A managed security services provider can design a unique set of solutions to protect network assets from the relentless threats and attacks that occur on a daily basis.

Left unmanaged, these security risks, which can come from both internal and external sources, can wreak havoc on a business's ability to operate. They pose a very serious and real threat to corporate performance and continuity.

A recent ZdNet commentary titled "IT security and new regulations needed to protect critical infrastructures" shed light on the importance of having a managed security services partner. Pointing out that 2011 is the year that many have dubbed "the year of the hack," the site's commentator suggested business owners may never again think the same way "about the security of networks and systems."

Although he recommended "the deployment of typical preventative technologies (e.g., firewalls, IPS, anti-virus, etc.)," he stressed that such technology in and of itself is not enough. What is required is proper design, implementation and maintenance of a process that allows a business to respond to any network threat in a "timely and effective manner." Of course, most companies don't have the resources to devote to that task, which is a 24/7 job. That's where "a Managed Security Services Provider (MSSP) [can] help them fill organizational capability gaps."

A managed security services provider can offer the following solutions:

Risk mitigation, so that any threat is stopped before it can turn into a full-blown emergency Improved network visibility with 24/7 monitoring for round-the-clock peace of mind Enhanced network performance, uptime, and utilization so businesses can maximize their effectiveness Flexibility to extend IT resources to strategic projects Simplicity in network management so business owners can devote their attention to more pressing matters Reduced network maintenance expenses for better bottom line A proactive approach to system issue resolutions

With all these benefits, it's hard to argue that a partnership with a managed security services provider isn't worth the investment, but for those CEOs who are still on the fence, "PC Magazine" echoes ZdNet's glowing recommendation of such a partnership. Several years back in an article on the topic of Managed Security Services, the publication said, "If your small business doesn't have full-time IT support staff, and you'd feel safer asking a specialist to handle security than tackling it on your own, consider outsourcing security to a managed security service provider (MSSP). MSSPs can provide a variety of services, such as firewall and VPN, content filtering, spam filtering, virus protection, and intrusion detection/ prevention services."

Today, a managed security services provider can provide all of that and a whole lot more, including (according to Wikipedia) "round-the-clock monitoring and management of intrusion detection systems and firewalls, overseeing patch management and upgrades, performing security assessments and security audits, and responding to emergencies." And in a day and age when network security threats are lurking around every corner, no business owner can afford to be without such protection.

An Explanation of CISPA for Small Businesses   Protect Your Privacy With Reputation Management   Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

A Whole New Reason To Secure The Best VPN Services: HTTPS Isn't As Secure As You Thought

On the internet there is a system in place to keep financial and other confidential and sensitive data from falling into the wrong hands: Secure Sockets Layer. This is a method of encrypting and decrypting the data transferred to, and from, the website or server you are communicating with. But according to a report released recently by the Trustworthy Internet Movement (TIM,) you may need to start using the best VPN services you can find to further secure the communications.

What Is This Movement About

One project that TIM undertook was the determination of the security of some 200,000 registered HTTPS websites. They developed a scanning program called SSL Pulse which scans websites for known vulnerabilities and hacking methods including page spoofing, man-in-the-middle, and brute force attacks. The scanner then returned the results to TIM who analyzed them and found that of the 200,000 registered secured websites only 10% were truly secure. This, assuming that the visitor isn't using any of the best VPN services. The scanner checked many SSL protocols, SSL 2.0, SSL 3.0, and TLS protocols, along with all the latest encryption ciphers, and key lengths.

How They Were Rated And The Scores

Websites were rated on a basis of 1 - 100, which was then converted into a grading system... an "A" being a score of 80 or more points. And while at least half received an A, only 10% showed up as totally secure from exploitation. In site of the high ratings though, at least 75%, or 148,000 websites, were found to be vulnerable to a popular exploit called "BEAST." Beast uses cookies and authentication tokens to invade the secured stream. This is a hack revealed in the 2011 security conference in Buenos Aires and will work on SSL/TLS block encryption ciphers such as AES and Triple-DES, but doesn't affect any of the best VPN services protocols like OpenVPN, or PPTP.

How To Tell If Your Communications Are Secured

First of all I want to emphasize: Do not stop using your HTTPS websites. For the most part, they are fairly secure. But you may consider enlisting the best VPN services provider you can afford and using it when you are conducting transactions that you want to keep confidential. A spokesman for the group said that "For your average Web site -- which will not have anything of substantial value -- the risk is probably very small." Then he went on to say that the larger institutions, like financial websites, have a much larger potential for being exploited. By using one of the best VPN services, and always allowing your browser to check the website security certificate, this larger risk can be averted.

An Explanation of CISPA for Small Businesses   Protect Your Privacy With Reputation Management   Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

Twitter Facebook Flickr RSS



Français Deutsch Italiano Português
Español 日本語 한국의 中国简体。