In the middle of June, we launched our upgraded Site Scanner service. Little did we know back then how soon we would see the new functionality in full action. Just a few months after the upgrade the Site Scanner saved thousands of WordPress sites from a well-disguised attack, aiming to redirect traffic to bogus sites through a fake plugin, called Zend Fonts. Imagine all the reputation and other business damages a hack like this could have caused and take a read how our hero, the Site Scanner, saved the day.
How does the “fake Zend Fonts plugin” work?
The attack involved uploading an infected fake plugin called Zend Fonts through a backdoor. Once uploaded, the infected plugin would redirect site visitors to bogus scam sites without the site owner even suspecting it. The uploaded plugin file looks like that:
What makes the attack really bad is that this plugin file is hidden from the wp-admin or wp-cli plugin list, meaning the WP Admins would not be able to easily spot it, due to the following function:
Also it is configured to trigger the redirect only if the website is accessed by a normal user, not the site admin or editor:
//do redirect if user from REF and NOT Admin
if(isset( $_SERVER['HTTP_REFERER']) && !$isAdmin){
redirect();
}
All these factors make the attack pretty much invisible for the site owners/editors, while the normal visitors would be redirected to scam sites. This hack could easily result in significant losses of sales, reputation damages, and other harms such as bad standings in search engines and more.
How did SiteGround detect the attack?
Our System Administrators monitor the load and behavior of our servers 24/7 and soon after this exploit was launched, we observed an abnormally high number of malicious files detected by our Site Scanner service crawling for malware. Our Sys Admins started digging further and spotted a pattern – there was an attempt for a massive fake Zend Fonts plugin upload affecting by that time around 2000 of our clients’ WordPress installations.
How does Site Scanner protect the sites it’s on?
Usually, in attacks like the Zend Fonts one, for the sites with Site Scanner Basic, reports are received in less than 24 hours after the malware is detected (right after the scheduled daily scan) and for those with Site Scanner Premium, an alert is received immediately after the (attempted) upload, giving our clients the opportunity to quickly react and delete the malicious files before they can cause any damage.
Furthermore, for the sites with Site Scanner Premium where quarantine is switched on, the files never reach the attacked sites – they are safely quarantined for the site owners to review and delete when convenient. The quarantine effectively stops the attack and protects the sites from malicious hack attempts, and the business and reputation impact resulting from them. And the best part – the site owners don’t have to do anything.
Using Site Scanner data to protect all clients
Once our System Administrators had detected that the Zend Fonts plugin upload was not something isolated, but was happening across the whole platform, they deleted all malicious files from our servers. Furthermore, our Security Engineers added a new rule to our web application firewall (WAF) to prevent further attacks towards other WordPress sites hosted with us.
We are quite excited to see how our Site Scanner service is actively protecting sites from a variety of really bad attacks. For massive, large-scale attacks such as the Zend Fonts plugin one, the Site Scanner helps us detect a pattern and take actions to protect all our clients by implementing WAF rules or enhancing our monitoring system. While this is something that we will continue doing, updating a platform-wide system takes some time and will not include smaller, site-specific malware attacks. If you want to have an early-on, comprehensive malware detection for your site, we strongly recommend that you activate one of our Site Scanner plans. And if you’re looking to not only detect but proactively stop malware attacks, get the Premium Site Scanner with quarantine on.
With the rapid development of technology, the complexity of phishing attacks improves. The more technologically advanced people become, the more advanced the phishing attacks. Last but not least, now that everybody spends more time online, the number of phishing attacks also rises. Here is our short guide on simple things to remember in order to stay safe from phishing attacks, while browsing online.
What is Phishing?
Born circa 1995, just 4 years after the first site appeared, phishing refers to the practice of using deceptive emails and websites to illegally get personal and corporate information from users. That information – usernames, password, credit cards – is later used to steal either money or more information.
The word “phishing” itself is a combination of “fishing” and “phreaks” which was what hackers used to call themselves. The practice of phishing is considered a form of social engineering, which is a term for manipulating people by falsely representing oneself in the context of web security.
Types of phishing techniques
Spear phishing
What is spear phishing? Spear phishing targets a specific person or organization rather than random users. This scam usually intends to steal sensitive data or information from the specific victim, such as account passwords or financial information for malicious purposes. It requires specific knowledge about the victim such as some personal details. The cybercriminals use this information, usually in an email, to pretend they’re a trustworthy organization or person and acquire the data they need.
Spear phishing vs phishing
Both of them are online attacks that intend to steal sensitive information. However, phishing is the more general term for this type of attack, as this is basically any attempt to trick victims to share sensitive data.
As per the spear phishing definition, it is personalized to the specific victim. It requires more thought, time and knowledge to achieve its goal. Since spear phishing’s messages are personalized, it’s more difficult to identify these types of attacks.
What helps protect from spear phishing is generally being careful with your online presence. Here are a few tips to follow in order to avoid spear phishing:
Be careful what personal information you post on the internet
Use smart and strong passwords
Update your software regularly
Watch out when opening emails and clicking on links
Microsoft 365 phishing
These types of attacks are phishing emails that target Microsoft 365 users. One of the most common things that attackers usually do is tricking victims into downloading a file by disguising its extension. Attackers use a special Unicode character, the right-to-left override. It allows them, for example, to disguise an “.exe” file as a “.txt” file. As a result, the victim downloads the “.exe” file which installs malicious software on their computer or laptop.
Whaling phishing
Whaling phishing is a highly targeted attack. This type of phishing attack targets particular individuals, such as senior executives, and disguises as a legitimate email. It attempts to encourage victims to do a particular action, usually related to transferring money or giving out specific information. Whaling phishing emails often target large financial institutions and are more complicated than general phishing emails because they target C-level executives.
These emails usually contain personalized information about the organization/C-level executive, create a sense of urgency, comply with the business tone, and they encourage you to do some of the following:
Click on a link that eventually brings malware
Transfer money to the attacker’s bank account
Provide further information about the business or individual
Voice phishing
Voice phishing is an attack which tricks individuals to provide important financial or personal information over the phone to third parties. You can become a victim of a voice phishing attack over various channels and devices, such as voice email, smartphone, landline phone, voice over IP, etc.
The message of such an attack usually informs the victim of a suspicious activity, related to their bank account/credit or debit card, etc. Then the attacker encourages the victim to call a phone number and provide more personal information or verify their account/identity.
To protect yourself from such an attack, the best approach is to call the given institution via a valid contact channel you have and make sure that your account has not been compromised.
Business email compromise (BEC)
Business email compromise is an email message that appears legitimate, requests a particular action, and targets a specific company. The request in the message is usually about transferring funds to the attacker’s bank account that:
Pretends to be the “regular supplier” that has sent an invoice from an updated mailing address
Pretends to be the CEO of the company
Pretends to be an employee of the company and has hacked their email address
Pretends to be the lawyer of the company
Social media phishing
Social media phishing is related to attacks via social media such as Facebook, Instagram, Twitter, LinkedIn, etc. It aims at stealing your personal information or taking over your social media account. Such an attack can also result in financial loss due to getting data for access to financial accounts. To protect yourself from a social media phishing attack, follow these simple rules:
Don’t add/accept strangers as friends
Don’t click on links to update your personal information
Don’t use the same username and password for all your accounts
Use the latest version of your operating system
How Can You Prevent Phishing?
Because phishing can truly cost you a lot – from stolen money to huge data breaches in your company – taking proper safety precautions is a must. We’ve put together a shortlist of the things you need to keep in mind in order to stay safe online.
1. Pay Attention To The Sender and The URL in Your Emails
One of the most common phishing scams is to spoof a big brand by sending an email with their name (and usually color palette), and say there is something wrong with your account and ask you to log in “to fix it”. Usually, the look of the email is very similar to the original brand, however, there is a sure way to distinguish whether you’re looking at the real deal.
A good way to identify phishing emails is to check the email address: scammers cannot create email addresses with the actual domain name of the company, so instead of help@bigbrandname.com it will usually look like bigbrandname@somethingelse.com. Look carefully at the email address and not just the name appearing in your email client!
You should also check the URL before clicking. This can be done by hovering the mouse over the URL provided in the email, it will usually reveal the domain it’s pointing at, so you can see where this email actually wants to take you. If it’s not the official domain of the brand, don’t click on it.
2. Avoid Downloading Email Attachments You Don’t Expect
Sometimes the email looks like legitime business emails, and they don’t pretend to be a big company, but instead send over an attachment containing some sort of malware. The email is often structured as a business offer or аn email sent by the recipient’s own company/management containing files with sensitive information.
If you don’t know who the sender is, definitely don’t open any attachments. If you know the sender, but you don’t expect anything from them, or there is something fishy about it, it’s better to be cautious. Call the sender and ask them if they meant to send you anything, as sometimes scammers hack into people’s email boxes and use them for phishing attacks by spamming their contacts.
The most common format for the attachments is zip (.exe is usually not allowed), however, even Microsoft Office files can contain viruses, which can contain macros that need to be enabled. Overall, keep an eye for all kinds of attachments.
3. Always Check The Site You’ve Landed On
If you happen to click on a phishing link (usually via email or through instant messages), it will often take you to a website with a form of some sort. The purpose of these forms most often aim to gather your most sensitive information – usernames and passwords.
In order to be sure you’re at the correct site and before filling in any data, check the website address in the browser address bar.
Scammers can create a website closely resembling the design of the respective brand, but they can’t use their official domain or have the brand name in the domain (assuming the brand is trademark protected). So, often, these domains may resemble a brand’s name, but will never be the original one, and will have additional symbols, letters, or words.
Usually, the scammy domains look completely nonsensical and sometimes the design and flow also feels odd, especially if it’s a known brand that you often see.
For example, when signing into Gmail, Google will never ask you to select your email provider or enter both your email and password on the same screen. So the flow you will often see on phishing sites is designed to resemble the original one, but it’s not.
4. Ignore Money Requests
Another type of online scam that social engineers often use is misrepresenting themselves and asking for money under some form. An example of such phishing emails is a person in trouble, asking for financial help; you’re asked to send a small amount of money with the promise you’ll get way more in return.
Sometimes these scams can take the form of extortion. A popular one was an email circulating in the past couple of years, stating that users have been recorded through their own webcams watching adult content and asking for money. Actually, this scam attack was so scary, it made the news as people were terrified – understandably so!
Either way, if you are getting a money request under any form by strangers, it’s usually a scam; never give out money or financial information no matter how the situation is presented.
What should you do if you receive a phishing email?
Every time you receive an email, you need to be extra careful of the email address, the URL, their spelling, etc. After checking these and identifying that the email is actually a phishing email, you need to follow all of the steps below:
Don’t click on any links & don’t open any attachments & don’t reply;
Contact the alleged sender via official channel for communication;
Report the email to your company & email provider & government body & the organization that allegedly sent the email;
Mark the sender as junk or spam;
Delete the email & remove from recycle bin/deleted items folder.
How to report phishing emails?
As previously mentioned, you need to report the phishing email to several people/institutions. Here we’ll show you how to report the email both to the email provider and to the government body.
How to report phishing emails to your email provider
Let’s take as an example, Gmail accounts. Next to the “Reply” option in Gmail, click the “More” option and select “Report phishing”.
If you are an Outlook user, you need to select the phishing email message from the message list and above the reading pane, select Junk > Phishing > Report.
Other email providers have similar easy to use options for reporting phishing emails.
How to report to a specific institution, based on the country you’re in
The Anti-Phishing Working Group (APWG) is an international coalition that attempts to eliminate cybercrime. If you receive a suspicious or malicious email, forward it to this organisation at reportphishing@apwg.org.Below you can see some other country-specific institutions that can help you too:
For the USA, forward phishing emails to the National Cybersecurity Communications and Integration Center (NCCIC) at phishing-report@us-cert.gov.
For the UK, report the phishing email to Action Fraud, the UK’s fraud and cyber crime reporting center.
If you’re living in a European Union country, here you can find the reporting website, corresponding to your country, in case you are a victim of a cybercrime.
Final thoughts
Now that you know what is a phishing attack, you are much better prepared to protect yourself from it with our simple actionable advice. You can further explore our blog for similar topics and read how to protect your reputation by protecting your email.
Website security should be on the mind of every site owner. It doesn’t matter if your site is large or small – if it is important to your business, you need to keep it safe and secure. As a site owner myself – and primarily a WordPress site owner – I’ve come up with a checklist I go through every time I spin up a new website for myself or a client. Let me share it with you in hopes that you will pick up a few new ideas. Let’s look at what it takes to secure a website.
Choosing A Secure Web Host
It should go without saying, but security starts with your web hosting company. I’ve used everything from ‘do it yourself web hosting’ to ‘concierge level hosting’. The trick is to find the level you need and the support you are comfortable with.
Check their support
The first thing I do when considering a new web host is to check their support and response time. I’ll sign up for a free trial, put up a site, and then ping support to ask a question. How quickly they respond and how well they understand the question gives me clues as to what I can expect from them if I host with them.
Check their security features
I’ll then check their website and hosting plans to see what security tools and features they provide. I’ll look for essential things like an SSL certificate to encrypt and protect my website data, domain privacy to hide my personal information from public Whois databases, 2-factor authentication to protect my website from unauthorized access, geographically distributed backups to have a safe copy of my website in case something goes wrong.
Other key security measures I’d like my website hosting provider to have in place is a Web Application Firewall – software that sits in front of my website and protects it from known bad traffic – to keep my host server safe from software exploits, DDOS and brute-force attacks protection, and the option for automatic updates to the latest PHP and WordPress versions to keep your site secure from malware.
If the host provides yet more security tools, that would be even better. For example, on top of all these features, available on the SiteGround platform, they also offer an in-house developed Site Scanner service and a free in-house built SiteGround WordPress Security plugin to make sure that your website would be as secure as possible.
Check their blog
Step 3 when selecting a web host is always to read the last 5 entries in their blog.
Are they recent?
Do they talk about security?
Do the blog posts seem helpful?
No, not all blog posts are going to be about security, but I’d better be able to find a recent one. The Security landscape changes quickly so they need to be posting regularly.
Check their price
Finally, I check their pricing tiers and figure out where my site will fall. Price is the last thing I check because if the first two boxes aren’t checked then the price doesn’t matter. They could be giving it away for free and I wouldn’t use them.
Build Your Site Securely From The Beginning
Once you’ve laid a secure foundation for your website, it’s time to start framing it and building it out. At every step, you need to make sure that security is “baked in” not “bolted on”.
Security is bolted on when you build out your entire website and then decide to just add a security-focused plugin to cover your bases.
Baked in is always better.
What does it mean to bake in security?
Install an SSL certificate as soon as you get the website set up
Don’t wait until you are ready to deploy your website before you remember to install your SSL certificate. These days a secure website is just a few clicks away. Take the time to do it now and then make sure you force all traffic to be https after it is installed. For those users hosting with SiteGround, your Site Tools makes setting up and enforcing SSL easy. Just a few clicks and you are in business.
Set a strong password policy before you start adding users
Passwords are the lock on the front door to your site. When building out your site, put a strong lock on the front door by requiring all users to use strong passwords. Doing this before you let users start coming into your site will make sure that no users set up weak passwords.
Require Two-Factor Authentication (2FA) for any user that will have admin-level rights in the system.
Two Factor Authentication is the deadbolt on the inner office of your site. Yes, a strong password is important for anyone to get into the site, but to get to things like financial information or user management, you want a strong deadbolt as well. Keep your system secure by implementing 2FA for all your admins. The SiteGround Security plugin makes setting up 2FA very easy.
Set up a backup system that will regularly backup your entire website and store those backups securely.
You need a 30-day backup system implemented from day 1. Not 1 day, not 7 days, 30 days. The reason is, that if your site gets hacked, you may not notice immediately. Once you do notice, you want to clean your site and one of the best ways to do that is to restore your site from a clean backup.
SiteGround’s Site Tools provides an intuitive tool for scheduling nightly backups and restoring from them when needed.
While we are talking about backups. Don’t forget to force a backup before any upgrade, major site redesign, or installing a new plugin. It never hurts to have a fresh backup in case things go bad.
Adhere To The Principle Of Least Privilege
Before you start letting users into your system, think about the roles that they will play. A role is a set of permissions or privileges and you want to give each user the absolute minimum level of privilege they need to use your site.
There are several good role editors for WordPress and I suggest you install one, learn how to use it, and then audit the roles you have in your site to make sure they have only those privileges they need to use your site.
On a regular basis – at the very least once a year – review these privileges to make sure they are still valid and to make sure that no role has been granted a privilege it does not need.
Most users are not trying to do bad things, but we have to assume they would if they could. Adhering to the Principle of Least Privilege will help make sure that bad actors, or curious users, can’t do things to your site they aren’t supposed to.
Only Use Software From A Trusted Source
In software development – as in building a house – your supplier’s reputation is critical to your project’s success. If you use a cut-rate supplier for the framing materials of your house, the entire project will suffer. Worse yet, it will cost you more later on to fix these problems than it would to just buy good materials to begin with.
Building your website with quality materials like plugins and themes from reputable vendors will usually cost you money in the short run. However, knowing that you have companies standing behind their products and updating them when issues arise is worth the money.
Yes, you can choose a free plugin or theme to build a critical feature of your website. However, what do you do if you discover that there is a security flaw? Worse yet, what do you do when you discover that flaw and then discover that the author has abandoned the project? At that point you have 2 options, neither good.
Hire a developer to fix the security flaw
Rip out the plugin, find another one that does the same thing, implement it and make any changes to your process that are necessary.
Both of these can be expensive propositions that could be avoided by simply choosing wisely in the beginning.
SiteGround recently looked at the data from a lot of compromised websites. What they found was that the majority of the compromised websites were compromised because they had unpatched plugins that had security flaws in them. Much of the time these were the free versions of paid plugins downloaded from untrustworthy sources. Only download plugins and themes from trusted sites like WordPress.org or vendors you trust.
The WordPress plugin repo is a reputable source. WordPress.org has implemented a review process – both human and scanning software – to help filter out plugins that have potential security issues or otherwise violate WordPress policy.
Scan Your Site Regularly
Just like you build a security system into your house, you want to set up a security scanner for your website as soon as you build it. Security scanners look at your site both internally and externally to make sure that there are no known vulnerabilities. It will check your website for viruses as well. No security scanner is perfect, just like no home security system is perfect. But your website is more secure with one.
A good scanner will look for things like cross-site scripting vulnerabilities among other things. These vulnerabilities can allow your site to be used in the attack of other sites or attacks on the end user themselves.
SiteGround has a great scanning system available. I get regular emails from it telling me which sites it has scanned and either that they are all clear or that there is an issue I need to address…immediately.
Beware of Phishing Scams Related To Your Site
Once you’ve built a new house, you don’t hand out keys to anyone who asks, even if they claim to have a good reason for wanting in. Similarly, you want to make sure that if you get an email that says it is from your site, you don’t automatically click on the link.
You should know every email your system is capable of sending. When you get one that you don’t remember setting up, you need to investigate. Don’t click, start looking at it. Check the headers, look at the exact URL any links go to. Most importantly, quarantine the email using your virus detection software.
Unknown emails purporting to come from your site are just another way that bad actors try to get into your site. These phishing attacks come from servers that are not under your control, so you can’t stop them. You can, however, be aware so that when you get them, you delete them. In almost all cases, if you don’t click, the email itself can’t do any damage.
Tools I Regularly Use To Bake Security Into My Sites
Keeping a WordPress website secure doesn’t have to be a full-time job if you bake security into it from the beginning. To do this, there are a couple of tools I use on almost every WordPress website I have.
The SiteGround Security Plugin is the first plugin I install on any new website I spin up. I install it, I install an SSL certificate, and I configure everything to be secure before I do anything else. If I get this part right, everything else is easier.
The SiteGround Optimizer plugin is a great way to make my site faster, but it is also where I check the “HTTPS Enforce” checkbox. This way all the traffic on my site goes over HTTPS even if it wasn’t originally. Having an SSL certificate is important, enforcing it on all traffic is equally important.
SiteGround’s Site Tools have a lot of great options to make managing a website easy. The one tool I use in setting things up though is the Backup tool. After I get SiteGround Security and SiteGround Optimizer setup and configured, I have my foundation laid – I force a backup. This is my fallback in case I mess something up while building out my site.
Then before I install each plugin or theme, I create a new one. I name these backups “BEFORE “ + the plugin or theme name. This way I can roll back to any point in the process.
Wrap Up
If you lay a secure foundation for your website and then think about security at every turn, then you can rest easy at night, knowing that your site is as secure as possible. No website, however, is bulletproof. Therefore, the last step is to build your Disaster Recovery plan. What steps do you take when your site has been hacked?
The SiteGround Security plugin has a series of steps you can take just for that situation. It is not a complete disaster recovery plan but when you combine it with 30 days of backups, you are well on your way to having one.
We have been talking about brute-force attacks in the past, but the truth is that many of our clients don’t even realize how real and how common the threat of these attacks is for anyone with a website. Based on our experience of hosting millions domains, we fully understand the destructive potential of brute-force and we have set defence mechanisms to prevent and mitigate such attempts directed at the websites we host. For years our AI brute-force prevention system has been successfully blocking millions of attacks every day. Now, we are happy to announce that the system got even better – by constantly learning from thousands of brute-force attempts per day and adding new functionality for traffic validation, it now filters 95% more of the bad queries!
Advanced AI system that recognizes & blocks brute-force attempts
Analyzing traffic behaviour and recognising patterns is the core feature that makes our AI brute-force prevention system so effective. When a behaviour that matches a certain pattern associated with brute-force is detected (like too many unsuccessful login attempts from an unrecognized location for example), the suspicious source is immediately challenged with a CAPTCHA page that only a real human can pass. This effectively stops brute-force attempts, adds up to the system knowledge and enables legitimate users who have accidentally mimicked a suspicious behaviour to reach the requested location by completing the captcha. The beauty of this constantly evolving system is that it gets better with every brute-force attempt it stops, it keeps sites under attack safe and it ultimately protects the other websites hosted on our servers by blocking bad traffic before it even targets them.
NEW: Traffic validation that minimizes the number of brute-force attacks
We have recently upgraded our system to become even more powerful. We are now able to more efficiently block the great majority of malicious non-human bots – e.g. incoming brute-force attacks or data hunting agents which aim to profile your site and later hack you through future software exploits. That significantly boosted the system success rate and reduced bad visits by roughly 95%.
The best example to illustrate how the system works is with the XML-RPC, a file in the root directory of every WordPress installation. Many (WordPress) hosts block its usage because it’s known to be insecure and blocking it is the easiest way to avoid XML-RPC-related hacks. However, XML-RPC also has many legitimate use cases for communicating with external systems and software. That is the reason we don’t aim at stopping XML-RPC – we want to empower our clients to use the tools and services they need to get the best of their websites. Instead of blocking it, we have looked for ways to harden its security and significantly decrease the potential for brute-force attacks. After our latest AI brute-force prevention system upgrade, we now validate all traffic coming through XML-RPC to stop all recognized malicious visits and eventually reduce the overall hits reaching the clients’ sites through XML-RPC by 99%. This means that we successfully filter potential brute-force sources before an attack is even attempted.
Less resource consumption, lower carbon footprint
The impact of this upgrade to our AI bruteforce prevention system is enormous. Not only are we further minimizing the chances for our sites to get brute-forced and potentially hacked, but we significantly reduce resource consumption (like CPU and RAM) generated by traffic coming from bots and brute-force attempts. Lower resource consumption effectively means more resources available for your legitimate visitors and a lower carbon footprint of your site.
Preventing brute-force attempts is just one of the many ways we constantly protect the websites we host, along with our Smart Web Application Firewall, DDoS protection, 24/7 server monitoring and many more. We believe that security is one of the foundations for any successful website, and we continuously develop new prevention and mitigation solutions, improve existing ones and keep adding new security features to our hosting, so you can have the peace of mind that your website is in good hands and focus on what’s important – your business.
As hackers become more and more ingenious, protecting your website is an on-going process. To help you boost your website security even further, we’ve recently enhanced our Site Scanner addon service with new features and introduced a Premium plan for ultimate website safety. As many of you wanted to learn more about this service improvement, we held a live webinar with our Product and Technology Lead, Daniel Kanchev. He explained how the latest Site Scanner update will boost your site security and replied to your most frequently asked questions. If you did not have a chance to attend, you can now catch up with the recording of our Site Scanner live webinar on YouTube. We also summarized some of the answers to your most popular questions, as well the ones that we didn’t have enough time to answer during the live webinar.
Why should you protect your website in the first place?
Contrary to popular belief, all websites – big or small – are targets to hacker attacks. At the end of the day, attackers don’t care whether you have a brochure website or a big eCommerce store, whether you have a couple of hundred users or hundreds of thousands of visitors. Their goal is to maximize the impact of the attack, causing harm to both your business and your users. Some of the ills they cause include stealing credit card details, sending spam emails, hosting malware on your site, storing files on your account, etc.
Bottom line is that everyone can be a target and get affected. That’s why it’s important to know how to protect your website. At SiteGround, we’re fanatical about the security of the websites hosted on our platform. We’re taking a multi-level approach to secure your sites on infrastructure, server, and application levels, but since the security of a website is also the responsibility of every website owner, we’re constantly adding new features and services to help you in this process and save you time, effort, and money, because dealing with the aftermath of a website attack is time consuming, generates losses and requires certain technical skills.
Isn’t SiteGround taking care of my website security?
SiteGround has adopted a security-first approach in our services and we are taking a comprehensive care of the websites hosted on our platform. Here are some of the things we do:
General website security measures
Hosting account isolation makes sure that your site is secured and will not be affected in case another website on the same server gets hacked.It isolates your website from all other websites. If another client’s website gets hacked, this won’t affect your website. It’s good to keep in mind, though, that multiple applications within the same website (e.g. in different folders, or subdomains of the same website) will need some more attention, as they share the same isolated protected space. Hacking one of them might lead to exploiting the other application as well. Therefore, it’s a good idea to protect all your sites with strong passwords, and our SiteGround Security plugin for WordPress websites, for example.
Web Application Firewall (WAF) rules, being written by our security experts, prevent your site from being hacked due to a security hole in a popular plugin, theme, etc. We write such smart firewall rules for a really big percentage of WordPress plugins, themes and other applications.
Smart AI anti-bot system analyzes all servers, websites and traffic, and blocks illegitimate website requests, or shows a CAPTCHA, when it’s not 100% sure the requests are legitimate. Our AI anti-bot system also takes care of brute-force attacks.
Geographically distributed backups to have your data safely available at another location, in case something happens to your server and data center.
24/7 server monitoring of the servers by our experienced system administrators to prevent security attacks, mitigate DDOS, and react in a timely manner against any known or unknown threat.
WordPress-specific website security measures
We offer automatic WordPress core and plugin updates to make sure your website is up-to-date and secure.
We have developed a free WordPress security plugin available to clients and non-clients alike – the SiteGround Security plugin. It allows you to put additional layers of security to your website and application.
Why do you need our Site Scanner security service then?
Even with all of the above security measures in place, there is always a chance that your site can be hacked by an attacker who has found a way to gain access to it.
Let’s imagine you’re connected to a public wifi network and you’re accessing your FTP account from it. If the hacker is on the same wifi network and it’s an open network, they can sniff the traffic and see your username and password. This is only one of the numerous examples of how attackers can “enter” the backdoor of your website.
That’s why our Site Scanner is useful – even if something happens to your site, it’ll notify you about the issue and you’ll be able to react, as it:
Checks regularly for websites threats and detects malware
Sends you timely threat alerts and notifications
Gives you tools for reaction, if your site is under attack (NEW)
Site Scanner is a great add-on to everything else we do, because it gives you visibility and control, if something suspicious is going on with your website, and provides you with a mechanism for a timely reaction to limit the scope of an attack.
FAQs on how Site Scanner works to protect your website
With the latest Site Scanner update, we offer two different Site Scanner plans – Basic and Premium that provide your website with various security features. Here you’ll find the answers to the most frequently asked questions about these features:
How often does Site Scanner run?
Both versions of the Site Scanner security service run daily scans of the crawlable URLs, while the Premium version includes automated daily scans of the files uploaded for that website.
Does Site Scanner scan the subdomains as well, or only the main website?
The part of Site Scanner that opens up the website in a browser and browses through pages works for the domain name for which you ordered the service. If you ordered a Site Scanner for yourname.com, then it will scan pages on this website. If you have subdomains like blog.yourname.com, they won’t be scanned by Site Scanner in this way – the service will only open the main website in a browser and scan through it.
On the Site Scanner Premium plan, the file scans will work for all the subdomains you have as part of this website. That’s because from a folder structure point of view, all the public HTML folders (the web root folders of the websites) are in one site.
Can Site Scanner scan files, as well as index.php, .htaccess, .txt? How does it work with old HTML sites?
No matter if it’s a PHP, .html, CSS, JavaScript, Python, Pearl, Go, or another type of file, the file scan will be performed. Our Site Scanner scans and looks for malicious patterns through the whole file system, no matter what type of files are in the folders.
If you have an HTML site, chances are that you will not be a target of an attack so often in comparison to a dynamic website; yet, HTML websites can still be hacked and malicious code can be inserted in the HTML. For example, if you have an index.html, someone can inject malicious JavaScript in those html pages, but Site Scanner will detect those.
Does Site Scanner affect website speed or CPU usage?
Site Scanner is lightweight and consists of two main things. The first one is the scanning from a browser perspective, and it runs on a different infrastructure, not on your server. Every day, it opens your website and browses through some pages, generating about 10 or 15 page hits per day which is quite minimal and can be ignored. Second, there are the file scans and the file upload scans. These are things that run on your hosting server, but they’re lightweight and consume very little CPU time. Thus, neither website loading speed, nor CPU usage are affected by Site Scanner.
Is Site Scanner white-labeled?
If you’re reselling services, your end users will see the Site Scanner interface inside Site Tools (it’s white-labeled in that way), but they will not get the email reports. These reports will be delivered to the owner of the website only (the SiteGround client that owns the website). Your clients will also be able to use the quarantine option, they will be able to see the history of scans, as these are also white-labeled.
How to activate Site Scanner?
You can simply log in to your SiteGround Client Area > Marketplace > Hosting services > Additional services and select Site Scanner. You will then see the comparison table between the Basic and Premium plans to choose from, along with their respective prices.
Site Scanner vs. SiteGround WordPress Security plugin
Site Scanner protects your website by detecting threats, attacks and vulnerabilities, sends you notifications, and gives you tools to react. The SiteGround Security plugin on the other hand gives you the ability to increase the level of security of your WordPress website by placing more firewall rules, e.g. you can enable 2FA, block an IP address that is trying to access your website too many times, etc.
While the plugin increases the security of your WordPress website, Site Scanner works for non-WordPress websites as well. If you have a WordPress website, we recommend that you get the plugin to boost your site security and also get Site Scanner to have a peace of mind that if something happens, you will be notified, able to react easily through the Site Scanner interface and do it on time.
Does 2FA work for the content users on WordPress?
In the SiteGround Security plugin, 2FA can only be enabled for users with elevated privileges, such as administrators, publishers, editors, etc. Once you enable 2FA, these users would have to fill in a token, generated on their Google Authenticator application, to be able to proceed with the login process.
We surely recommend enabling 2FA for your registered users. The only thing that you need to keep in mind is that this might require you to spend some more time supporting end users, when they don’t have access to their phone/email address.
At the end of the day, it depends on your business – if you want your clients to have easy access to your website and to the information you provide, it doesn’t make much sense to enable 2FA. If the website provides access to confidential information that should be protected, then it makes a lot of sense to enable 2FA for the end users of the website.
Does SiteGround have something similar to the “Limit Login Attempts” blacklist feature and how effective is it?
We have this feature in the SiteGround Security plugin and it has proven effective for preventing brute-force attacks.
Can you use Site Scanner and SiteGround Security plugin, if your website is hosted elsewhere?
Our Site Scanner service can be used only for websites that are hosted on our platform. However, the SiteGround Security plugin can be used for any WordPress website, regardless of your web hosting provider, so installing it is the least you can do for your WordPress website security.
What is the best way to prevent visitors or bots from sending emails that appear to come from the domain of your website?
When attackers forge the ‘From’ email address, that’s called email spoofing. There is no way to completely prevent that, but you can restrict it. To do that, you need to specify in the DNS zone of each of your domains which mail servers/IPs are authorized to send emails on behalf of that domain by creating these DNS records: SPF, DKIM, DMARC. In this way, the mail servers of the recipients will be able to better distinguish if the emails are legitimate ones, which were sent from your mailboxes, or phishing attempts.
Since its launch in 2011, our Site Scanner website security service has helped hundreds of thousands of website owners protect their sites from destructive hacks, data theft and reputation damages via early detection of malicious software. We’ve been constantly improving the service for even higher website security by adding more functionalities, such as deep file scan done directly on the server in its previous update last year. Now we’re enhancing the existing Site Scanner service by adding a Site protect feature to it and we are also introducing a new premium plan that includes two more types of automatic scans and a quarantine option for malicious files.
What Is Site Scanner
Our Site Scanner feature is a security service that’s crafted to protect your website by:
Detecting malware and the latest threats that might affect your website;
Warning you about such potential threats at an early stage and in a timely manner;
NEW: Providing you with tools for reaction if your site is under attack.
In order to do the above, Site Scanner runs a range of scans and checks on your website in search of any signs of malware daily. If it identifies a threat, you get notified by email which gives you enough time to react in case of any danger to your website security. With our latest Site Scanner version update we’re also adding tools that allow you to react and minimize the impact when your website is under attack.
The service now comes in two plans: Basic Site Scanner, which is an enhanced version of our current SG Site Scanner, and Premium Site Scanner, which includes a brand new set of features. Read on to learn more about each of these plans.
What’s Included in our Site Scanner Basic Plan
The Basic Site Scanner includes many functionalities that will detect and warn you about malware at an early stage, but now we’ve added a brand new feature that will allow you to minimize any damage in case of an attack, and further protect your website.
NEW FEATURE: Site protect
If you get a malware notification or you suspect that your website was compromised, you can now manage four different on/off options from the Site protect interface. They allow you to temporarily disable all file uploads to your website by three different methods: disabling FTP and/or SSH transfers, and disabling file upload via PHP. The fourth on/off option prevents the execution of malicious scripts on the server. While any of these options are enabled, you can safely review the site status and ensure that no additional threats can reach it. This gives you some time to assess the situation, take action to clean any malicious code on your site, and minimize the damage. Once you are sure that your site is safe, you can switch off the respective option from the Site protect interface and resume file uploads again.
URLs scan
The automatic URLs scan crawls your website URLs every day and checks if there is publicly detectable malware on your website.
Domain blacklist check
We automatically check whether your domain has been blacklisted for malware by some of the most popular and authoritative search engines, browsers and anti-virus databases. The blacklist check takes into consideration information from Google, Yandex, Chrome, Firefox, Norton, McAfee and many more.
On-demand manual scan (URLs, domain, and files)
With the Basic Site Scanner you can manually run an advanced scan of your site that will not only check your site URLs and your domain blacklist status, but will also make a comprehensive scan of all your files hosted on our server.
Email Reporting
You get immediately notified if our automatic scans detect anything suspicious with your site. Additionally, you will also get a weekly email summary of your website status.
30-day scan history
You can find a 30-day history of your site scans in your Site Scanner interface with the scan results and detailed information about threats and malware (if any).
NEW: Premium Plan With Awesome Additional Features
We now offer a Premium plan of our Site Scanner service that includes all the above-listed functionalities from the Basic plan, plus some premium-exclusive features for even more enhanced website security.
Daily automatic files scan
Whereas our Basic plan daily scan only checks your URLs and domain for publicly detectable threats, our Premium plan goes deeper. It includes our most thorough check, which goes automatically through every file of your website on the server and looks for malware, suspicious code that may remain publicly unnoticed.
File upload scan
With the file upload scan we will check every new file being uploaded to your site, through File Manager, FTP, WordPress backend or else. This is one of our best prevention tools that can detect malware as soon as it appears and notify you immediately with an instant email notification.
File upload quarantine
The Premium Site Scanner allows you to switch on an automatic quarantine. If you choose to do so, any newly uploaded file that is detected to be malicious will be automatically placed in quarantine (separate folder, outside of your document root), so that it does not become active on your website. You will then be able to manage each of these quarantined files separately, having the option to either restore them to their original location, or delete them. File upload quarantine is a powerful tool that may protect your site in times of an attack.
If you’d like to learn more about protecting your website and see the Site Scanner tool in action, watch the recording of our recent webinar that explains the different levels of protection websites get on our platform and the benefits of using our Site Scanner tool:
Activate or Upgrade Site Scanner for Your Site Now
If you still don’t use our Site Scanner service, we strongly recommend that you activate it to keep your site safe from malware. To purchase the Basic or Premium version of our Site Scanner security service for your site, go to your Client Area > Marketplace > Hosting Services > Additional Services.
If you’re already using our Site Scanner service, you’ve been automatically switched to the Basic plan and all its latest features are now available for you to use. As a special offer for all our long-time Site Scanner users, we now offer a free upgrade to the Premium Plan until the end of your current service period. (Your Site Scanner should have been activated before June 15, 2022, in order to be eligible for the offer, regular Premium Site Scanner renewal prices apply after the end of your current term.)
To upgrade to the Premium version log in to your Client Area.
The Elementor 3.6.0 version of the WordPress website builder plugin introduced a new functionality for easy plugin setup. Unfortunately a serious security vulnerability has been detected, which if exploited, allows full website access, rendering all Elementor 3.6.0 – 3.6.2 versions vulnerable. SiteGround took immediate action to protect our WordPress clients using the plugin, resulting in all instances on our servers being updated to resolve the issue on day 0 of the vulnerability report. Read on for more information on how we have protected our clients.
How severe is the vulnerability?
The issue is critical, since it allows regular website users, including subscribers, to fake an Elementor Pro .zip file, upload and activate it to a website, executing pretty much any code part of the archive. That means that if you are using Elementor version 3.6.0, 3.6.1 or 3.6.2 for your WordPress site, and user registration is enabled on it (for example WooCommerce websites, membership websites, etc.) an attacker could get full access to your site.
What did we do to protect SiteGround clients?
Due to the severity of the issue, we immediately updated all Elementor plugin instances on our hosting servers. We did that for all clients using the Elementor plugin for WordPress on SiteGround – both the free and the paid versions of the plugin – just to be on the safe side. So, if you’re a SiteGround client, your Elementor plugin version is updated to fix the vulnerability. If you have a WordPress website using the Elementor plugin hosted elsewhere, we recommend updating your plugin version immediately to avoid staying vulnerable.
We are now introducing our own Private DNS service, which allows you to customize the default name servers on our platform for enhanced online privacy and completely white-label hosting. It takes full advantage of our centralized DNS service, which was built to ensure faster domain name resolving for a faster website loading, enhanced reliability, and easy DNS management, and which also formed the basis for our own Cloud-based Content Delivery Network to additionally improve site performance.
Introducing our Private DNS service
The DNS service translates the domain names (pages’ URLs) to the numerical IP addresses of the servers hosting the website content. Thus instead of visitors having to type a combination of numbers in the browser, they can use letters and words. Thanks to our centralized DNS service, all domains registered with SiteGround are now using the same default name servers: ns1.siteground.net and ns2.siteground.net. Our Private DNS service makes it possible to change those to your own custom name servers, based on your own domain names or your brand. It allows you to point all your websites’ domains to these unique name servers. For example:
ns1.mydomainname.com
ns2.mydomainname.com
What are the benefits of our new Private DNS service?
Enhanced online privacy
Using custom domain server names helps enhance your online privacy. The Private DNS service hides the default ns1.siteground.net and ns2.siteground.net name servers. This obfuscation of the information makes it harder for third parties to find out where exactly your domain is located, which hinders them from taking advantage of potential issues that may arise on the servers.
Completely white-label hosting
The Private DNS service is especially useful for white-label resellers. If you wish to offer hosting to your clients, but you don’t wish them to know that the service is provided by SiteGround and have them communicate with us directly, using the Private DNS is a great idea. That will help you conceal who’s the original host, which makes you the sole provider and increases your brand name visibility.
How to activate and manage the Private DNS service?
You can activate Private DNS for your domain from Client Area > Marketplace > Hosting Services > Additional Services. You get this service for free if you are on a GoGeek or Cloud hosting plan. The Private DNS is also available on a yearly subscription basis for all other customers who want to use this service. To be able to enable Private DNS for your domain name, it must be registered with SiteGround.
To manage and view your DNS information, you can do so from Client Area > Services > Domains > Manage (for the associated domain) > Extras.
Earlier today our security team received confirmation about a critical vulnerability in Linux affecting all kernels since 5.8 (CVE-2022-0847). Dubbed The Dirty Pipe, the vulnerability poses an extremely high-security risk, allowing attackers to overwrite key website files and gain full access to servers. Needless to say, that is a huge security threat with a very large scope that allows unprivileged access to root processes and configuration files.
Our security team started working on it immediately after the initial reports. Even though the Linux kernel is a third-party software, at SiteGround we’ve always been proactive, with a dedicated hands-on expert security team instead of waiting for an official patch release. Our kernel specialists developed a custom mitigation which was extensively tested. Once we were certain no other functionalities were affected, the fix was deployed across all our systems and servers, hours after the vulnerability was discovered.
We were among the very first, if not the first host, to successfully write and deploy a patch against this high-risk security threat. At the moment, no SiteGround servers are affected by this vulnerability and there was zero downtime involved in the entire process. Our clients are fully protected and don’t need to make any changes!
At the end of every year, we turn to our clients for the most important mark that really matters – how you rate our efforts and services throughout the year in our traditional client satisfaction survey. Each year we are amazed and humbled by the positive feedback we receive, and every time we manage to raise the bar a tad higher. In 2021, the result is a stellar 98% overall client satisfaction rating, which is spectacular in any type of client service business, but especially so in the website hosting industry.
Of course it’s hard to put a number to satisfaction, but it’s a pointer that takes into account your ratings of the main pillars of our web hosting services – website speed, security and support, which we keep strengthening and improving on year after year. Here is a breakdown of some of the things we did in these key directions and the impact that they had on your websites, leading up to such staggering satisfaction numbers in all aspects of our service.
97.7% Client Satisfaction with Website Speed
We’ve always been famous for proactively adopting the latest web speed technologies for the benefit of our clients. In 2021 we again introduced multiple new website performance enhancements at no extra cost. We started off by enabling Google’s state-of-the art Brotli image compression algorithm on our servers, ensuring between 15% to 20% website speed gains for clients right out of the box. To add to that, our new MySQL setup allowed websites hosted with us to serve more visitors simultaneously, lowering the number of slow website queries between 10x to 20x times. And by enabling our unique Dynamic caching by default on all hosting plans, clients now enjoy up to 5x times faster page loading time. These are just some of the latest and major improvements we introduced to make your websites run faster, improve your website’s user experience, conversions, and SEO rankings. In return you rated our website speed efforts with the highest marks in the history of our end-of-year client survey – a stellar 97.7% Website Speed Satisfaction Rate!
98.5% Client Satisfaction with Website Security
Parallel to our website speed improvements, we’re always working on new ways to help you with the never-ending quest of securing your website. Our mission to provide the best data protection took another big step this year with the launch of our off-site backups. Apart from our free daily backups and easy restore, we deployed a geo-redundant backup system which minimizes the risk of data loss in case a whole data center facility is in jeopardy for whatever reason. That way we ensure a safe recovery of your site with minimum downtime. In addition to that, our SiteGround Site Scanner security service got improved to include a new scanning method that allows users to run a thorough file scan of their site directly on the host server with a single click. And we also introduced our new centralized DNS for faster, safer, and easier hosting.
4.3/5 Stars for our Client Tools and Services
This year was especially rich in new website tools and services for our WordPress users. We launched the SiteGround Security plugin for WordPress – a free tool that greatly improves WordPress security in just a few clicks. And it’s available for everyone, not just SiteGround clients. Just a few months after its release, the plugin was awarded Silver for Best WordPress Security Plugin in the biggest WordPress community award, Monster’s Award. And to round off our list with added-valued services and tools, we released a new version of our SiteGround Optimizer WordPress plugin to upgrade its functionality and add new features for even more site speed and convenience for webmasters. All of these efforts did not go unnoticed, and we got an average rating of 4.3 out of 5 stars for each of our latest tool releases.
SiteGround Optimizer WP plugin → 4.3/5 rating
SiteGround WP Security plugin → 4.3/5 rating
SiteGround Site Scanner → 4.4/5 rating
The New Central DNS → 4.3/5 rating
A Look Back and a Look Ahead
We’ve been doing our client end-of-year survey for 10 years now, the first one dating back to 2012. A decade later, with over 2,800,000 hosted domains, your feedback ratings still manage to go up – starting from 95% overall client satisfaction, up to а steady 98% in the last couple of years.
We are thankful for your feedback and for helping us improve our services year after year. In 2022 we will continue to improve our tools and services and launch new ones for existing and potential clients alike, and hopefully manage to further exceed your expectations yet again.