Deprecated: Assigning the return value of new by reference is deprecated in /home/hostco/public_html/blog/wp-settings.php on line 520

Deprecated: Assigning the return value of new by reference is deprecated in /home/hostco/public_html/blog/wp-settings.php on line 535

Deprecated: Assigning the return value of new by reference is deprecated in /home/hostco/public_html/blog/wp-settings.php on line 542

Deprecated: Assigning the return value of new by reference is deprecated in /home/hostco/public_html/blog/wp-settings.php on line 578

Deprecated: Function set_magic_quotes_runtime() is deprecated in /home/hostco/public_html/blog/wp-settings.php on line 18

Warning: session_start() [function.session-start]: Cannot send session cookie - headers already sent by (output started at /home/hostco/public_html/blog/wp-settings.php:520) in /home/hostco/public_html/blog/wp-content/plugins/wordpress-automatic-upgrade/wordpress-automatic-upgrade.php on line 119

Warning: session_start() [function.session-start]: Cannot send session cache limiter - headers already sent (output started at /home/hostco/public_html/blog/wp-settings.php:520) in /home/hostco/public_html/blog/wp-content/plugins/wordpress-automatic-upgrade/wordpress-automatic-upgrade.php on line 119
Web Hosting Security | Web Hosting India - Part 2

Archive

Archive for the ‘Web Hosting Security’ Category

Uses Of .htaccess File For Authentication and Authorization.

May 12th, 2011 Comments off

The .htaccess stands for ‘Hypertext Access this file used for configuring a web hosting server and to control its activities. This file plays an important role in security and performance of the websites residing on that particular server. It is popular among webmasters for keeping control on their websites.

There are multiple ways to configure .htaccess file, in this post you can see following two important factors of .htaccess file.

.htaccess
.htaccess

Authentication and Authorization.

The .htaccess file controls and provides, authenticationa and authorization for the visitores of your website, it also has to ability to restrict certain pages of your websites from getting views by particular visitors. This is a great utility to get rid of spam-bots, spam mails, form submissions and uwanted comments. Through .htaccess file a webmaster can block any particular domain name of IP address from which is facing spammy visits. This was all about blocking the access and further more a webmasters can also set specific permitted access by setting password (.htpasswd file) for his websites, so that authorised people can only enter in to protected webpages which may contain sensitive data, of his websites. This uritlity is very useful for a blog or a collaborated website where multiple people are responsible for updating them.

Advantages Of Hosted Desktop And Desktop Virtualization

March 28th, 2011 No comments

We know, mainly virtualization is connected with either Windows VPS or Linux VPS services, but as far as typical web hosting services are concerned from people’s point of view, they always think of number of websites on a single web server but in Desktop virtualization process it is not necessary to decrease number of computers and contract the things in to a single server. Reduction in the cost of infrastructure and management required to server maintenance is one of the most important feature of Desktop virtualization. Through manageable desktop environment, modified provision of systems and other devices of client side one can notice the benefit of Desktop virtualization and additionally the important factor like bandwidth is used in more improved manner. Upgrades are easily possible and available to servers in terms of storage and network stuff very easily.

A user uses data and applications from the similar server on which is running and streaming those applications and data, and this allows it to provide improved security to the applications as well as an improvement in transmission of desktop processed workload from client side to the hosted location. Adopting to virtualization also enable to client to split up any important or confidential data and applications and make it secure from any type of suspicious and unauthorized offends. Different level of security patches and permissions can be assigned to virtual machines by network administrators.

PNG - Better Replacement For GIF?

February 25th, 2011 No comments

PNG which stands for Portable network Graphics is widely used and popular format of images. Though it had few major cons like it is not supported by all the browsers, with the latest compatible browsers it is becoming more and more popular. PNG is treated as a more advanced version of the GIF format with lot of improvement. The PNG image in a lossless possibly has 5% to 25% more compression than the GIF format of the same image. Transparency is the main idea behind a PNG format which is not possible with GIF up to that level. The only major disadvantage a PNG has is lack animation.

Following are major features of PNG format.

  • Improved Indexation – color images of up to 256 colors.

  • Streaming – It is possible to read and write PNG file in a serial order so that file format can be used as a communicating protocol.

  • Progressive display – It is possible to display an PNG image as it is received as a communication link while interacting. It is shown as yielded image with the lower resolution at the start and then the original one with original specifications.

  • Transparency – As discussed in the starting of this post a PNG image can be marked as a transparent one by creating effect.

  • Truecolor and Grayscale images – PNG supports up to 48 bits for truecolor images and up to 16 bits for grayscale images.

  • Ancillary information – It is possible to store textual comments and other type of data withing a PNG file.

  • Good replacement for GIF – PNG has covered lot drawbacks of GIF format like more effective 100% lossless compression, legally unencumbered, more reliable, straightforward detection of file corruption, full alpha channel.

Why phpBB board is so popular?

February 25th, 2011 No comments

Following are the features available in phpBB board making it one of the most popular board for forums owners.

  • Availability of various font styles and multiple sizes which are compatible for many quoting styles, codes, inserting images and automatically converting the URLs in to links.
  • Standard and extended BBCode tags and limited HTML tags are supported in phpBB boards.
  • Participant can conduct polls with multiple options in the posts and can view the public opinion on specific subjects.
  • Notifications through emails can be send whenever anyone replies to a post.
  • Topic subscription is possible in more effective to know each update over it.
  • Emotions can be from original to portray.
  • Default search facility with many search options available.
  • Private messages can be sent as emails to other members of the board.
  • Multiple types of avatars like local, remote and uploadable are supported on board.
  • Topic edition is possible after posting.
  • Post can be deleted, moved, locked and unlocked for administration and moderation purpose.
  • Topic can be divided in parts.

How Hackers Do That?

February 17th, 2011 No comments

Number of cases are rising of hacking a web hosting accounts and websites. Though Hackers loves blogs more than websites as they are easier then the websites for getting hacked. The word hacking describe the unauthorized and unwanted entries in a private network or computer which mostly work as a web server and capturing its most possible controls and functions. The main strength of any hacker is the lack of webmaster’s knowledge about the latest technologies and tools and how they works.

Emails are the mostly used as a hacking attempt starting process. Webmasters receives emails which includes requests of software installation or certain types of plug ins and this all is provided at fully free of cost. According to human tendency of acquiring free things webmasters get attracted quickly towards such emails. These type of free programs are specially constructed with the ability of spying the activities done by you and controlling the networks.

To avoid such attacks a webmaster need to be always aware of the up-gradation of standard softwares installed on his servers. Older versions of security softwares possibly may include few exceptions of errors and bugs which are unable to prevent your website hosting servers from external attacks. Hackers are capable of studying these security systems and using the drawbacks of those ones. Always make sure to do not click on the links of unknown emails which claims suspicious free stuff for free from a fishy site. Though search engines are always blocking such sites but its not an easy task to always track such sites with surety. Never upload any file which you collected from a unknown source and never found anyone else using it ever before, such files comes with an inbuilt scripts which are capable of automatic installation of programs and spread itself throughout the network.

Usage of short and weak passwords as they are easy to remember but it is another big reason for getting a web hosting account getting hacked. As all of us know what are the characteristics of good passwords so never take it easily while using a password.

E-Commerce websites are most likely to be on the target of hackers because they always deals with money transactions. Such websites should be checked by setting up regular maintenance schedule on hourly basis which can be effective to keep hackers away from web hosting accounts and web servers.

PuTTY : A Great Utility To Establish A SSH Connection

January 18th, 2011 Comments off

One can describe PuTTy as a client program for the network protocols which are mostly used for running a remote sessions on a computer system which is connected to a network. Such programs include SSH, Rlogin network protocols and Telnet. This PuTTY obligates towards client side of a particular session and not on the server side where does it actually runs.

In other words one can say that PuTTY makes it possible to analize a operation on the computer system which can be different that the computer system where actually it is running. For example you can operate a computer system having any operating system, software etc from other computer which has different parameters.

PuTTY supports both xterm terminal as well as DECterm but PuTTY’s default terminal type to any server is as xterm if any problem persists with it then it can be reconfigured as vt220.

If anybody has a question that ‘Which commands can be executed in a PuTTY terminal window?’ then it is basically wrong question because no process occurs inside PuTTY but it only a tool of communication which forwards the commands typed by you to the another computer and responses from that computer back to you. PuTTY has nothing to do with running applications on any of the both computer systems ans so that command execution depends on the system’s execution compatibility to those commands.

By using PuTTY the security level of web servers can be maintained. It is very easy to run PuTTY by downloading ‘puttygen.exe‘ which is widely available on Internet.

Is integration of Apache with Tomcat really worth?

January 8th, 2011 Comments off

As Apache and Tomcat have high importance in web server hosting industry. There are both good and bad side this integration of Apache with Tomcat and there are different opinion about the same. Following are some points I would like to attach the discussion.

Clustering – When Apache is used as front-end it works as a front door for multiple Tomcat instances. Apache has the ability to ignore if any one of Tomcats fails. For this you need to use a hardware which is load-balanced.

Security – I we compared Apache with Java then we can know that Java has its own security manages and Apache works on bigger mid-share. Though this is a controversial topic but when one prefer to go fo Apache he needs to secure two systems at the same time but which can be appreciated by search engines also.

Clustering / Security – It is possible to use Apache with multiple tomcats for multiple URL name-spaces and in such situations Tomcats can be more protected individually. Though Apache is smarter proxy server one need to take care of it.


Add-Ons – In Apache one can add PHP, CGI and pearl very smoothly and such addition is very effective for Tomcat. Unlike Tomcat, Apache has many modules to be plugged in.


Dcorators - It possible to perform multiple decorators when Apache is in front of Tomcat which does not support of quick code.

Speed – Though it is very hard to compare speed between Apache and Tomcat, when things come to static content, Apache is quicker than Tomcat. But this only applicable in the case of high traffic websites. There are some exceptions where Tomcat wins the race by using connector wisely.

Socket Handling – In many cases Apache it known as better socket handler than the Tomcat. Tomcat handles the sockets through JVM which require to go through platform, hence makes Tomcat slower.

Internal server error - HTTP Error 500

January 7th, 2011 No comments

The best and easy way to figure out the reason for “Internet server error 500” would be to check the error logs generated for your website. You can check the error logs by accessing cPanel > Error Log. Or else you could check the error logs by contacting your Web Hosting Service Provider.

While checking the error logs using cPanel which is available with your cPanel Web Hosting Account you will see a detailed list of the last error messages generated by your website. It provides you with detailed information about each error occurred, with the date and time of the error, also information about the client receiving the error is included. It also provides information about which folder and file is causing or generating the error.

internet-server-error-500 Internal server error  - HTTP Error 500

Below mentioned are examples of some errors causing an Internet server error 500 and steps to fix them:

  • [2011-01-01 02:45:01]: error: directory is writable by others: (/home/user/public_html/)

The above error can be fixed by changing the permissions of the file or directory in consideration. You need to change the permissions by using the File Manager in cPanel, or by an FTP client. You need to enter the correct permissions, you can get the correct permissions by contacting you web hosting service provider.

  • [2011-01-01 02:45:01]: error: file has no execute permission: (/home/user/public_html/)

While fixing this issue, you need to use your FTP client or the File Manager through your cPanel account and change the permissions. You can get the permissions from your Web Hosting Service Provider.

  • [Sat Jan 01 02:45:01 2011][client 121.0.0.60] (13)Permission denied: /home/user/public_html unable to check htaccess file, ensure it is readable

The above error is caused because of incorrect permissions of the .htaccess file. Such an error message can also occur sue to incorrect permissions for the folder. You need to ensure that the permissions are correct. They can be obtained by contacting your web hosting service provider.

  • [Sat Jan 01 02:45:01 2011] [client 121.0.0.86] Premature end of script headers: /home/user/public_html

Such error message could be occurred sue to several reasons:

The script requires more than the usual time to be processed and is being killed or terminated by the system.

This could also be because of an error within the programming code of the script in consideration. In such a case it should be revised by a professional web developer who will be able to assist you further.

How can I disable new registrations for MediaWiki?

December 23rd, 2010 No comments

mediawiki_logo How can I disable new registrations for MediaWiki?

If you are looking forward to disabling the option for your MediaWiki visitors to register new accounts at your website then you would need to add the below mentioned code to your LocalSettings.php file :

$wgGroupPermissions['*']['createaccount'] = false;

Below mentioned is a detailed description as to how to do this on your website hosting account with the use of cPanel Control Panel :

*First you need to login to your cPanel control panel for your website hosting account.

*Navigate to the File Manager

*Click on the public_html folder

*Then click on the folder placed next to the folder where MediaWiki is installed

*Click on the file names LocalSettings.php

*In the top right corner you will see various management options for LocalSettings.php, you need to click on Edit File

*Lookup for a file named $wgGroupPermissions. If the file is not available, you would need to add it manually. But if it is available, you need to edit to :

$wgGroupPermissions['*']['createaccount'] = false;

*Once you save the edited LocalSettings.php file, new users would not be able to create new accounts.

If you are facing any further issues with the same, we recommend you to contact the support staff for you web hosting service provider.

How to Trace a Spammer?

December 16th, 2010 No comments

There are many ways to trace out the place from where the spam is coming, in few cases a spammer may not have any intention to hide his information from a webmaster because he very well know that the activities he is performing are intentional. In other type spammers will take lot efforts to hide their identities and contact information as they are aware of the disadvantages of spamming in better manner than the first ones.

Email address is the basic thing to be found very first in the process of detection of a spammer. Another solution is to find out the server location or web hosting provider from where the emails and spammy activities are starting, if one succeed to track out these thing then it becomes easy to stop the spammer easily.

Using Whois Database it is possible to find web hosting server on which the domain is hosted. If the domain has different extensions like .biz, .org, .net or the very common one .com then ‘Internic.net’ is also a very good tool to check these type of domains. In case of .ca domain extensions contacting CIRA Whois Database is the recommended. In case of regional country-wise domain extensions checking with top level registries for further details is beneficial. In final once you succeed to track the the information about the web hosting services provider of the spammer then having a talk on administrative level and requesting to stop the services of these spammers becomes easy.

 
 

Need Help ?

-- Client Area
-- Sitemap
-- Help Center
-- Tutorials

Resources

-- Web Hosting Forum
-- Web Hosting Blog
-- Knowledgebase

Partners

-- Affiliate program

Legal Information

-- Terms of Service
-- Service Level Agreement
-- Privacy Policy

Toll Free : 866 662 0909
1.213.255.7012 &
1.302.294.5628