Guide to Technology

eg: UK or Brides UK or Classical Art or Buy Music or Spirituality
 
eg: UK or Brides UK or Classical Art or Buy Music or Spirituality
 
Business & Money
Technology
Women
Health
Education
Family
Travel
Cars
Entertainment
Featured Sites
SD Editorials
Online Guide and article directory site.
Foodeditorials.com
Over 15,000 recipes & editorials on food.
Lyricadvisor.com
Get 100,000 Lyric & Albums.
  • Business & Money
    • A Guide to Business
    • Guide to Finance
    • Ideas for Marketing
    • Legal Guide
    • Guide to Insurance
    • Lettre De Motivation
    • Guide to the Stock Market
    • Human Resource Career
    • Sales Marketing
    • Forex & Trading
    • Advertising & Marketing
    • Startup Guide
  • Technology
    • Guide to Technology
    • Cell Phones
    • Computer Software
    • IT Hardwares
    • Internet
    • Online Security
    • Cameras
    • Search Engine Optimization
    • Science & Technology
  • Women
    • Guide to Women
    • Relationship Advice
    • Marriage
    • Jewelry
    • Pregnancy
    • Fashion Style
    • Divorce Guide
    • Wedding Guide
    • Dating Guide
    • Natural Beauty
  • Health
    • Guide to Health
    • Guide to Medical
    • Plastic Surgery
    • Weight Loss
    • Sports
    • Body Wellness
    • Cancer Treatment
    • Common Illness
    • Health & Lifestyle
  • Education
    • Military Service
    • Politics and Policy
    • Arts & Humanities
    • Education and Teaching
    • Learn Languages
    • Colleges & Universities
  • Family
    • Quality Home Improvement
    • Hobbies and Interests
    • Family Guide to
    • Pet Guide
    • Loans Guide
    • Credit Cards
    • Gardening Guide
    • Home Security
    • Real Estate
    • Home Decor
    • Gift & Present
  • Travel
    • The Travel Guide
    • Adventure Travel
    • Cruise Ships
    • Beach Holiday
    • Travel Accommodation
    • Holiday Destinations
  • Cars
    • Information on Cars
    • Traffic Violations
    • Auto Insurance
    • Trailers
    • Sport Cars
    • The Bikes
  • Entertainment
    • Entertainment Guide
    • World Music
    • Photo & Video
    • Television & Games

How To Secure Your Website

    View: 
SSL provides visitors to your website with the confidence to communicate securely via an encrypted session. For companies wishing to conduct secure e-commerce, such as receiving credit card numbers or other sensitive information online, SSL is essential.



For SSL to work a valid signed SSL certificate is essential. Certificates are a standard way of binding a public key to a name. Public key encryption is a tactic that uses a pair of asymmetric keys for encryption and decryption. Each pair of keys consists of a public key and a private key. The public key is made public by distributing it widely. The private key is never distributed; it is always kept secret. Data that is encrypted with the public key can be decrypted only with the private key. Conversely, data encrypted with the private key can be decrypted only with the public key. This asymmetry makes public key cryptography so useful.

You can generate a self-signed certificate and use it for some time until the certificate "signed" by a trusted external authority

VeriSign certificate authority

or

GeoTrust Site Seals

And it will be ready.

To enable SSL for your website with self-signed certificate:

1.Click on the Site tab;

2.Select Website Settings. Your website General Settings appear on the screen;

3.Click the Secure Website tab. The secure website summary appears on the screen;

4.Click the Generate a Request button. The certificate-request form appears on the screen;

5.Fill the form:

1.Select your country of residence from the Country drop-down menu. If needed, scroll the list;

2.Select your State from the State (US or Canada) drop-down menu;

3.Or type your State in the State (other countries) textbox;

4.Type your city or town of residence in the Locality textbox;

5.Type your company name in the Organization name textbox;

6.You can optionally type your company branch or affiliate name in the Organization unit name textbox;

7.Type your website name in the Site name textbox;

6.Click the Submit button. The updated secure website summary appears on the screen: now both the certificate request and private key exists, but the secure website is not available because the SSL certificate is absent;

Note: Do not forget to backup your private key: click the SSL private key details link (the private key content will appear in popup window) and copy your private key content to a file.

7. Click the Generate the SSL Certificate button. In a few seconds the screen reloads with the updated secure website summary: now the certificate is in place and the secure website is available;

8. Click the Enable SSL button.

To send a certificate request to an external certificate authority (if certificate request is already generated and the private key saved, as described in steps 1 -7 above):

1.Click on the Site tab. Website general settings appear on the screen;

2.Select Secure Website tab. The secure website summary appears on the screen;

3.Click the SSL certificate request details link. The content of certificate request appears in the popup window;

4.Copy the certificate request content in a file and send it to the certificate authority.

To import an SSL certificate signed by a certificate authority:

1.Click on the Site tab;

2.Select Website Settings. Your website general settings appear on the screen;

3.Click the Secure Website tab. The secure website summary appears on the screen;

4.Click the Install the SSL Certificate button. The form for SSL certificate importing appears on the screen;

5.Do one of the following:

1.Type the path to a file containing the SSL certificate in the Certificate file name textbox or click the Browse button to locate the file;

2.Or paste the certificate content in the Certificate content textbox;

6.Click the Submit button. The secure website summary appears on the screen;

7.Click the Enable SSL button.

To import both your backup SSL certificate and private key:

1.Click on the Site tab;

2.Select Website Settings. Your website general settings appear on the screen;

3.Click the Secure Website tab. Secure website summary appears on the screen;

4.Click the Install the SSL Files button. The form for both the SSL key and certificate importing appears on the screen;

5.Submit the key and certificate:

1.Type the path to a file containing the private key the Private key file name textbox (click the Browse button to locate the file) or paste the private key content in the Private key content textbox;

2.Type the path to a file containing the SSL certificate in the Certificate file name textbox (click the Browse button to locate the file) or paste the certificate content in the Certificate content textbox;

6.Click the Submit button. The secure website summary appears on the screen;

7.Click the Enable SSL button.

Notes:

Netscape and Mozilla browsers automatically detect whether a website uses encryption of transmitted data or not (as for Internet Explorer, please encourage your website visitors who use IE to use Internet Explorer 5.0 or later). Thus, if you use a self-signed certificate, your website visitors will be notified that your website uses encryption, but the authority that signed a certificate is not recognized. So if you intend to conduct e-commerce at your website, it is better to obtain an SSL certificate signed by VeriSign orThawte.

Secure website can be enabled only for IP-based website (i.e., a website that does not share an IP address with other websites). So if you have several websites on your server and only one IP address - any of these sites (but only one of them) can be SSL-capable. Go for GeoTrust Power Server ID Wildcard Certificate.

If you have any question, query or feedback than please send us at TheSSLStore.com
How To Secure Your Website
Most people on the internet are good, honest people. However, there are some people browsing the internet who derive fun from poking around websites and finding security holes. A few simple tips can help you secure your website in the basic ways. Now, obviously, the subject of data security is a complicated one and way beyond the scope of this column. However, I will address the very basics one should do which will alleviate many potential problems that might allow people to see things they shouldn't.

Password Protecting Directories

If you have a directory on your server which should remain private, do not depend on people to not guess the name of the directory. It is better to password protect the folder at the server level. Over 50% of websites out there are powered by Apache server, so let's look at how to password protect a directory on Apache.

Apache takes configuration commands via a file called .htaccess which sits in the directory. The commands in .htaccess have effect on that folder and any sub-folder, unless a particular sub-folder has its own .htaccess file within. To password protect a folder, Apache also uses a file called .htpasswd . This file contains the names and passwords of users granted access. The password is encrypted, so you must use the htpasswd program to create the passwords. To access it, go to the command line of your server and type htpasswd. If you receive a "command not found" error then you need to contact your system admin. Also, bear in mind that many web hosts provide web-based ways to secure a directory, so they may have things set up for you to do it that way rather than on your own. Barring this, let's continue.

Type "htpasswd -c .htpasswd myusername" where "myusername" is the username you want. You will then be asked for a password. Confirm it and the file will be created. You can double check this via FTP. Also, if the file is inside your web folder, you should move it so that it is not accessible to the public. Now, open or create your .htaccess file. Inside, include the following:

AuthUserFile /home/www/passwd/.htpasswd

AuthGroupFile /dev/null

AuthName "Secure Folder"

AuthType Basic

require valid-user

On the first line, adjust the directory path to wherever your .htpasswd file is. Once this is set up, you will get a popup dialog when visiting that folder on your website. You will be required to log in to view it.

Turn Off Directory Listings

By default, any directory on your website which does not have a recognized homepage file (index.htm, index.php, default.htm, etc.) is going to instead display a listing of all the files in that folder. You might not want people to see everything you have on there. The simplest way to protect against this is to simply create a blank file, name it index.htm and then upload it to that folder. Your second option is to, again, use the .htaccess file to disable directory listing. To do so, just include the line "Options -Indexes" in the file. Now, users will get a 403 error rather than a list of files.

Remove Install Files

If you install software and scripts to your website, many times they come with installation and/or upgrade scripts. Leaving these on your server opens up a huge security problem because if somebody else is familiar with that software, they can find and run your install/upgrade scripts and thus reset your entire database, config files, etc. A well written software package will warn you to remove these items before allowing you to use the software. However, make sure this has been done. Just delete the files from your server.

Keep Up with Security Updates

Those who run software packages on their website need to keep in touch with updates and security alerts relating to that software. Not doing so can leave you wide open to hackers. In fact, many times a glaring security hole is discovered and reported and there is a lag before the creator of the software can release a patch for it. Anybody so inclined can find your site running the software and exploit the vulnerability if you do not upgrade. I myself have been burned by this a few times, having whole forums get destroyed and having to restore from backup. It happens.

Reduce Your Error Reporting Level

Speaking mainly for PHP here because that's what I work in, errors and warnings generated by PHP are, by default, printed with full information to your browser. The problem is that these errors usually contain full directory paths to the scripts in question. It gives away too much information. To alleviate this, reduce the error reporting level of PHP. You can do this in two ways. One is to adjust your php.ini file. This is the main configuration for PHP on your server. Look for the error_reporting and display_errors directives. However, if you do not have access to this file (many on shared hosting do not), you can also reduce the error reporting level using the error_reporting() function of PHP. Include this in a global file of your scripts that way it will work across the board.

Secure Your Forms

Forms open up a wide hole to your server for hackers if you do not properly code them. Since these forms are usually submitted to some script on your server, sometimes with access to your database, a form which does not provide some protection can offer a hacker direct access to all kinds of things. Keep in mind...just because you have an address field and it says "Address" in front of it does not mean you can trust people to enter their address in that field. Imagine your form is not properly coded and the script it submits to is not either. What's to stop a hacker from entering an SQL query or scripting code into that address field? With that in mind, here are a few things to do and look for:

Use MaxLength. Input fields in form can use the maxlength attribute in the HTML to limit the length of input on forms. Use this to keep people from entering WAY too much data. This will stop most people. A hacker can bypass it, so you must protect against information overrun at the script level as well.

Hide Emails If using a form-to-mail script, do not include the email address into the form itself. It defeats the point and spam spiders can still find your email address.

Use Form Validation. I won't get into a lesson on programming here, but any script which a form submits to should validate the input received. Ensure that the fields received are the fields expected. Check that the incoming data is of reasonable and expected length and of the proper format (in the case of emails, phones, zips, etc.).

Avoid SQL Injection. A full lesson on SQL injection can be reserved for another article, however the basics is that form input is allowed to be inserted directly into an SQL query without validation and, thus, giving a hacker the ability to execute SQL queries via your web form. To avoid this, always check the data type of incoming data (numbers, strings, etc.), run adequate form validation per above, and write queries in such a way that a hacker cannot insert anything into the form which would make the query do something other than you intend.

Conclusion

Website security is a rather involved subject and it get a LOT more technical than this. However, I have given you a basic primer on some of the easier things you can do on your website to alleviate the majority of threats to your website.
More Articles from
Guide To The Internet Pg76
Build Content Management System
Carteras De Cuero En
E Commerce Internet Solution
Elizabethan Chain Of Being
Get Rich On Neopets
Help Me Find Myself
Make Money Stuffing Envelopes
Management Planning And Organizing
Mother Waddles Car Donation
Music In The Public Domain
Online Shopping For Games
Security Training In India
Serie A Fantasy Football
Tripp Lite Internet Office
World Wide Web Introduction
Can traffic-generating strategies help you achieve higher rankings for your website?
Cash Only Survey
Cash in on Demand for Freelance Designers
Career stuff
cash leveraging system
» More on
Guide to The Internet
  • Related Articles
  • Author
  • Most Popular
•How To Advertise Your Website, by Eric Menzies Menzies
•How To Advertise Your Website For Free, by Suraya
•How To Advertise Your Website Free, by Don Resh
•How To Build Your Website, by Stephen Ng
•How To Change Your Website, by Jkhjuk
About Author
Both Internet Security & David Risley are contributors for EditorialToday. The above articles have been edited for relevancy and timeliness. All write-ups, reviews, tips and guides published by EditorialToday.com and its partners or affiliates are for informational purposes only. They should not be used for any legal or any other type of advice. We do not endorse any author, contributor, writer or article posted by our team.

Internet Security has sinced written about articles on various topics from The Internet, Web Development. Buy SSL certificate of http://www.thesslstore.com/verisign.aspx?>Verisi. Internet Security's top article generates over 480 views. Bookmark Internet Security to your Favourites.

David Risley has sinced written about articles on various topics from Computers and The Internet, Business Marketing and Computers and The Internet. . David Risley's top article generates over 3600 views. Bookmark David Risley to your Favourites.
Cheap Flights " Hotels
Check the flight schedule to the last detail. The small print is important and your negligence can land you in rather sticky situations!
 
A Guide to Business | Guide to Technology | Guide to Women | Guide to Health | Family Guide to | Travel & Vacations | Information on Cars

EditorialToday Guide to Technology has 3 sub sections. Such as Technology, Increase Adsense Revenue and Information & Technology. With over 20,000 authors and writers, we are a well known online resource and editorial services site in United Kingdom, Canada & America . Here, we cover all the major topics from self help guide to A Guide to Business, Guide to Finance, Ideas for Marketing, Legal Guide, Lettre De Motivation, Guide to Insurance, Guide to Health, Guide to Medical, Military Service, Guide to Women, Pet Guide, Politics and Policy , Guide to Technology, The Travel Guide, Information on Cars, Entertainment Guide, Family Guide to, Hobbies and Interests, Quality Home Improvement, Arts & Humanities and many more.
About Editorial Today | Contact Us | Terms of Use | Submit an Article | Our Authors