A dangerous easy-to-exploit vulnerability called httpoxy discovered 15 years ago, reappeared again yesterday, leaving server-side website software potentially open to attackers. This security hole impacts a large number of PHP and CGI web-apps. This means that anything that runs on PHP, Apache, Go, HHVM, Python can be vulnerable. The exploit allows man-in-the-middle attacks that could compromise web servers and potentially access sensitive data or seize control of the code. Thanks to our unique in-house developed systems and some precautions taken ahead of time by our DevOps team, SiteGround customers are unaffected by the return of the vulnerability.
Continue reading “Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off”How our new backup system saved 24+ hours of downtime

Remember when we announced our new infrastructure in October last year? Part of the innovation, which we were particularly proud of, was our in-house created backup/restore system. A few days ago this system was put to its first critical real-life test and the results were impressive. We were able to restore 3 times more data, 7 times faster, compared to the previous such event when we were still using the old backup solution. Here is how we did it.
Continue reading “How our new backup system saved 24+ hours of downtime”
Jetpack Critical Security Vulnerability

Today a critical vulnerability was found in one of the most popular and widely used WordPress plugins – Jetpack. Fortunately, according to the plugin authors there is no evidence that this issue has been used to hack real sites. However, an update of the plugin was released – Jetpack 4.0.3.
As usual, our security team was pro-active and updated our WAF (web application firewall), adding rules to prevent the hack from being used. This means that even if your plugin is not updated to the latest version, your site will still be protected. However, we urge all Jetpack users to update the plugin to its latest version in which the vulnerability is patched.
[subscribe_cta]
We Are Recommended by WordPress.org!

DISCLAIMER
This blog post was published on May 17, 2016 and contains information relevant to that time period. Please note that circumstances, facts, and developments may have changed since the publication date.
We are very happy and honored that SiteGround has been listed as a recommended WordPress hosting provider on the WordPress.org hosting page. We perceive this as a high evaluation of the quality of our hosting product and work with the WordPress community.
Continue reading “We Are Recommended by WordPress.org!”More Value for Customers with SSL Certificates at SiteGround

Following the introduction of Let’s Encrypt free SSL certificates on our hosting platform, we are now launching more major upgrades in our SSL offerings. We will no longer provide Standard SSL certificates and all our customers that already bought Standard SSL will be upgraded for free to the premium Wildcard SSL. We are also dropping the price of Wildcard SSLs more than half. The range of SSL certificates offered at SiteGround will now consist of Let’s Encrypt, Wildcard and Extended Validation (EV).
Continue reading “More Value for Customers with SSL Certificates at SiteGround”
Supporting Indie Publishing Through Offscreen Magazine

Four years ago we stumbled on the following somewhere on the web: “Offscreen – a print-only magazine about the people behind the internet and technology.” Naturally, our first thought was “Why make a print magazine for people who spend most of their time online?” It certainly piqued our curiosity, and that’s how we came to order our first issue of Offscreen. It was also issue No1 – a brand new magazine. Today, we happily received Issue No14 at the SiteGround office.
Continue reading “Supporting Indie Publishing Through Offscreen Magazine”
ImageMagick Vulnerability Fixed

ImageMagick is one of the most widely used services to process images. Most of the web applications use it for many different purposes – to crop images, to resize them, to generate different thumbnail sizes, etc. Unfortunately, a serious vulnerability was discovered within the service, that allows an attacker to execute code remotely on your site. As usual our security team started working on a way to protect our customers immediately and came up with a solution hours after the vulnerability was disclosed.
Critical glibc Vulnerability Patched on all SiteGround Servers

Hours ago a critical vulnerability in the GNU C Library (glibc) was announced alongside a proof of concept for the attack. This library is one of the main components in the majority of Linux distributions (if not all) including those, used for server OS’es. Without getting into too much technicalities, the exploit allows an attacker to remotely execute code by following a simple link. That’s one of the most severe vulnerabilities discovered in the recent years and potentially affects pretty much any Linux server out there.
Given that all SiteGround servers run on CentOS – a Linux distribution, we took immediate measures to secure our machines. I am happy to announce that a patch has been applied on all our servers and our customers are well protected against this security threat!
[subscribe_cta]
2015: The Affiliates’ Assessment

We said goodbye to a very successful 2015 and the collaboration with our affiliates had a key role in achieving our great results. We have 100% increase in the number of sales generated by our affiliate partners and have paid out commissions worth 4 million dollars! What’s more, the results from our annual affiliate survey results proved that our affiliates are extremely happy with both our service and program features! Read on for the rest of the survey findings.
Let’s Encrypt is Here – Open Source Security Certificates Available at SiteGround

In December 2015 the new certificate authority Let’s Encrypt entered Public Beta and caused a wave of excitement. The groundbreaking news meant that website owners can obtain security certificates for their websites for free instead of paying for traditional SSL certificates and install them much easier. Naturally since then many of you have asked us when we would introduce the certificates on our hosting platform. For all of you who have been eagerly awaiting this moment, we are happy to say that Let’s Encrypt certificates are now available at SiteGround!
Continue reading “Let’s Encrypt is Here – Open Source Security Certificates Available at SiteGround”

