Who hacks sites? In most cases your site is hacked by your acquaintances, friends, classmates etc. Why are sites hacked? Sites are usually hacked for fun because as a rule your sites do not contain any valuable information which a hacker could use for mercenary ends. Whose fault it is? This is only YOUR fault because you do not fulfill the elementary security requirements. How to protect a site form hacking? - Do not log in to your Control Panel from somebody else’s computer, from an internet café, institute, school etc.
- If you still entered Control Panel from somebody else’s computer never save your password in a browser and always click "Logout" button before you close a browser.
- Don’t give your passwords to anyone.
- Use different passwords for everything (e-mail, Control Panel, user-administrator etc.).
- Don’t use easy passwords (123456, 123qwe, qwerty, password, mypass etc.). Your passwords must look like this: jDk9eu8kd (i.е. a random set of characters).
- Do not allow ordinary users to add news, blog entries and so on everywhere where they are allowed to use HTML. Remember that it is only YOU who need this site. If you have friends who want to help you with your site, move them to another group (e.g. "Checked") and allow this group to add information to the site.
- Do not assign people who you don’t know well as administrators and moderators.
When creating the uCoz project we laid stress on system safety. There has not been a single case yet when a violator got the access to the site not through the fault of the site owner or the moderators. That’s why we advise you to follow the recommendations above. One can log in to uCoz Control Panel only if he knows the password, and no XSS will help find it out. The passwords are not stored in cookies, but only on the server in encrypted form. So if a violator got to your Control Panel then you let your password be stolen (i.е. didn’t observe the security rules). P.S. We highly recommend you NOT to reply to such e-mails: Quote The mail service/administration of your host *@your_mail/host is edulcorating the accounts. If you don’t want your account to be removed reply to this e-mail and provide your username and password in the "Subject" field in the following format: username; password -- Administrator
I'm not "man", "sir" or whatever. I'm female! About signatures, screenshots etc...
|