A month ago we made the first step to increase the adoption rate of SSL certificates amongst our customers by starting to issue automatically Let’s Encrypt certificates for all domains hosted on our servers. However, there still remained a manual step to configure all applications to use the certificates we’ve made available. We knew that if we really wanted to see a rise in the HTTPS usage we not only needed to provide the SSLs, but also make it easy for our clients to implement them. Today we are happy to announce that we have achieved this second goal for a large group of our customers — the WordPress users.
Continue reading “HTTPS for WordPress With a Click”Happy HTTPS 2017 to you!
Last year we made a big step towards making the SSL certificates more widely used. We backed financially the super cool open SSL project Let’s Encrypt and we provided an easy cPanel interface, from where all our users can issue free Let’s Encrypt certificates with a single click. This has resulted in more than 40 thousand new SSL installations on our servers. However, there is still a long way to go before we see HTTPS protocol completely replace the insecure HTTP. Now, in the very beginning of 2017, we are happy to announce that we have taken the next big step in this direction — we have started to automatically issue Let’s Encrypt certificates for every domain that is hosted on our shared servers.
Continue reading “Happy HTTPS 2017 to you!”PHP 7.0 is Now Default on SiteGround Servers

Last December we were among the first hosting companies to make PHP 7.0 available on our entire infrastructure. Thanks to our system which allows multiple PHPs to be used on one server, anyone could have switched to PHP 7.0 since its zero-day release, while we still kept an older and well-tested PHP version as the global default setting. Now, an year later we believe it’s time for the next step – setting PHP 7.0 as default for all new accounts.
Continue reading “PHP 7.0 is Now Default on SiteGround Servers”
When Your CMS Reaches End of Life
End of Life (EOL) in the CMS world refers to the point in time when an older version stops being supported by the company or community that has built it, and all efforts are focused on current and future versions. No support means performance, and more importantly, security issues, which nobody wants.
As a web host, we see our fair share of EOL CMS usage. While we often make our own patches to keep outdated client websites secure and in other cases we notify them about issues, it really is the application’s responsibility. We can’t possibly keep track of every outdated software we host and every security vulnerability that comes with it. Hence, here is more about what to do when your application becomes outdated and no longer supported.
Continue reading “When Your CMS Reaches End of Life”Jetpack Critical Security Vulnerability

Today a critical vulnerability was found in one of the most popular and widely used WordPress plugins – Jetpack. Fortunately, according to the plugin authors there is no evidence that this issue has been used to hack real sites. However, an update of the plugin was released – Jetpack 4.0.3.
As usual, our security team was pro-active and updated our WAF (web application firewall), adding rules to prevent the hack from being used. This means that even if your plugin is not updated to the latest version, your site will still be protected. However, we urge all Jetpack users to update the plugin to its latest version in which the vulnerability is patched.
[subscribe_cta]
We Are Recommended by WordPress.org!

DISCLAIMER
This blog post was published on May 17, 2016 and contains information relevant to that time period. Please note that circumstances, facts, and developments may have changed since the publication date.
We are very happy and honored that SiteGround has been listed as a recommended WordPress hosting provider on the WordPress.org hosting page. We perceive this as a high evaluation of the quality of our hosting product and work with the WordPress community.
Continue reading “We Are Recommended by WordPress.org!”ImageMagick Vulnerability Fixed

ImageMagick is one of the most widely used services to process images. Most of the web applications use it for many different purposes – to crop images, to resize them, to generate different thumbnail sizes, etc. Unfortunately, a serious vulnerability was discovered within the service, that allows an attacker to execute code remotely on your site. As usual our security team started working on a way to protect our customers immediately and came up with a solution hours after the vulnerability was disclosed.
Critical glibc Vulnerability Patched on all SiteGround Servers

Hours ago a critical vulnerability in the GNU C Library (glibc) was announced alongside a proof of concept for the attack. This library is one of the main components in the majority of Linux distributions (if not all) including those, used for server OS’es. Without getting into too much technicalities, the exploit allows an attacker to remotely execute code by following a simple link. That’s one of the most severe vulnerabilities discovered in the recent years and potentially affects pretty much any Linux server out there.
Given that all SiteGround servers run on CentOS – a Linux distribution, we took immediate measures to secure our machines. I am happy to announce that a patch has been applied on all our servers and our customers are well protected against this security threat!
[subscribe_cta]
WordPress 4.4.1 Security & Maintenance Release

A new WordPress security update 4.4.1 was announced yesterday. The latest version fixes a cross-site scripting vulnerability that allows a site to be compromised as well as some minor issues.
All WordPress sites at SiteGround with enabled autoupdate service have been updated to the new version 4.4.1 last night and are safe and sound. For all WordPress sites that do not have the autoupdate option on, we have applied a rule in our WAF (web application firewall) that will block possible hacking attempts. As our firewall rule is not covering all possible hack scenarios, we are additionally patching WordPress sites on versions 3.7 to 4.4 at a website level.
Regardless of the security shields we have placed, we still recommend all websites that have not been autoupdated to upgrade to the newest version 4.4.1 or to the latest version within their current branch as soon as possible.
[subscribe_cta]
Critical Vulnerability in Joomla Fixed on Zero-day

Yesterday, a serious vulnerability that affects all major Joomla versions was disclosed. Using this security breach a hacker could do a full remote command execution on the targeted site. We have worked together with the Joomla Security teams and came up with a rule in our WAF (web application firewall) that would block hacking attempts using this vulnerability and we don’t have reports for hacked accounts through this exploit.
Continue reading “Critical Vulnerability in Joomla Fixed on Zero-day”

