Download ArticleDownload Article

This How.com.vn teaches you how to ensure that your website is protected from attacks. Using an SSL certificate and HTTPS is the easiest way to secure an address, but there are a few other things you can do to prevent hackers and malware from compromising your website.

  1. How.com.vn English: Step 1 Keep your website up to date.
    Failing to update your website's software, security, and scripts when necessary is a sure way to allow intruders and malware to take advantage of your site.
    • This goes for patches from your website's hosting service as well (if applicable). Whenever an update for your website is available, install it as immediately as possible.
    • You should also keep your site's certificates up to date. While this won't directly affect your website's security, it will ensure that your website continues to show up in search engines.
  2. How.com.vn English: Step 2 Use security software or plugins.
    There are several different website firewalls to which you can subscribe for constant protection, and website hosting services like WordPress often offer security plugins as well. Just like protecting your computer with an antivirus program, it's wise to protect your website with security software.
    • Sucuri Firewall is a good paid option, and you should be able to find free firewall or security plugins for WordPress, Weebly, Wix, and other hosting services.
    • Website application firewalls (WAFs) are usually cloud-based, meaning you shouldn't have to download any software onto your computer in order to use them.
    Advertisement
  3. How.com.vn English: Step 3 Prevent users from uploading files.
    Allowing people to upload files to your website automatically creates a security vulnerability. If possible, remove any forms or areas to which website users can upload files.
    • Limiting forms which allow uploads to support only one file type (e.g., a JPG for photos) is another possible fix for this problem.
    • This can be tricky if your website relies on a webpage form for things like cover letter submissions. You can get around this problem by setting up an email address for submissions and adding the address to your "Contact" page so that users can email their files rather than uploading them to your website.
  4. How.com.vn English: Step 4 Install an SSL certificate.
    An SSL certificate essentially confirms that your website is secure and able to transfer encrypted information back and forth between your server and a person's browser. You'll usually have to pay a yearly fee to maintain your SSL certificate.[1]
    • Paid SSL distribution options include GoGetSSL and SSLs.com.
    • A free service called "Let's Encrypt" will also issue an SSL certificate.
    • When choosing an SSL certificate, you have three options: domain validation, business validation, and extended validation. Both business validation and extended validation are required by Google in order to receive the green "Secure" bar next to your site's URL.[2]
  5. How.com.vn English: Step 5 Use HTTPS encryption.
    Once you've installed an SSL certificate, your website should qualify for HTTPS encryption; you can usually activate the HTTPS encryption by installing your SSL certificate to your website's "Certificates" section.[3]
    • If you use a website platform such as WordPress or Weebly, your website probably already uses HTTPS.
    • An HTTPS certificate must be renewed every year.
  6. How.com.vn English: Step 6 Create secure passwords...
    Create secure passwords. Using unique passwords for your admin-level site aspects isn't enough; you'll need to come up with complicated, random passwords which aren't replicated anywhere else and store their key somewhere outside of the website's directory.[4]
    • For example, you might use a 16-digit jumble of letters and numbers as a password. You could then store the password in an offline file on a different computer or hard drive.
  7. How.com.vn English: Step 7 Hide your admin folders.
    Naming your website's sensitive files' folder "admin" or "root" is convenient; unfortunately, this goes for both you and hackers alike. Changing these files' location's name to something boring (e.g., "New folder (2)" or "history") can make it harder for would-be attackers to locate your files.[5]
  8. How.com.vn English: Step 8 Keep error messages simple.
    If your error message gives away too much information, hackers and malware can exploit the information to find and gain access to things like your website's root directory. Instead of adding explicit details to your website error messages, consider offering a concise apology and linking back to the main website.[6]
    • This goes for anything from 404 errors to 500-type server codes.
  9. How.com.vn English: Step 9 Always hash passwords.
    If you store user passwords on your website, be sure to store them in an hashed format. A common error among new website owners is storing passwords in plain text format, which makes the passwords easy to steal if a hacker manages to find the file.
    • Even prolific sites such as Twitter have been guilty of this error in the past.
  10. Advertisement

Community Q&A

Search
Add New Question
  • Question
    What is the meaning of the word "encryption"?
    How.com.vn English: Community Answer
    Community Answer
    Encryption is the process of converting information or data into a code, especially to prevent unauthorized access.
  • Question
    Do hosting websites provide complete security with the yearly fees?
    How.com.vn English: Community Answer
    Community Answer
    Yes, typically for three dollars a year, you can get full security for your website.
  • Question
    What is a hashed format password?
    How.com.vn English: Free Eagle
    Free Eagle
    Community Answer
    A hashed password becomes an encrypted password in on the server it is stored in. So if your password was something like "Salt&Pepp3r", the server would store the password as something like: "2fde1c67a2d28fced840ee1bb76". Since a hashed password operates in only one direction, it's almost impossible for someone to hack the server and reverse the password. In other words see the "2fde1c67a2d28fced840ee1bb76" in storage, enter that and have it translate back to "Salt&Pepp3r", it won't happen.
Ask a Question
200 characters left
Include your email address to get a message when this question is answered.
Submit
      Advertisement

      Tips

      • Hiring a web security consultant to take a look at your scripts is the quickest (albeit the most expensive) way to address potential flaws in your website.
      • Always test your website via a security tool (e.g., Observatory by Mozilla) before publishing the latest version.
      Submit a Tip
      All tip submissions are carefully reviewed before being published
      Thanks for submitting a tip for review!
      Advertisement

      Warnings

      • Security vulnerabilities often aren't discovered until after they've affected someone. To avoid as many negative consequences as possible, remember to back up your website to an external location (e.g., a non-networked computer or hard drive) every week.
      Advertisement

      About This Article

      How.com.vn English: Jack Lloyd
      Written by:
      How.com.vn Technology Writer
      This article was co-authored by How.com.vn staff writer, Jack Lloyd. Jack Lloyd is a Technology Writer and Editor for How.com.vn. He has over two years of experience writing and editing technology-related articles. He is technology enthusiast and an English teacher. This article has been viewed 192,096 times.
      How helpful is this?
      Co-authors: 17
      Updated: November 26, 2023
      Views: 192,096
      Thanks to all authors for creating a page that has been read 192,096 times.

      Is this article up to date?

      ⚠️ Disclaimer:

      Content from Wiki How English language website. Text is available under the Creative Commons Attribution-Share Alike License; additional terms may apply.
      Wiki How does not encourage the violation of any laws, and cannot be responsible for any violations of such laws, should you link to this domain, or use, reproduce, or republish the information contained herein.

      Notices:
      • - A few of these subjects are frequently censored by educational, governmental, corporate, parental and other filtering schemes.
      • - Some articles may contain names, images, artworks or descriptions of events that some cultures restrict access to
      • - Please note: Wiki How does not give you opinion about the law, or advice about medical. If you need specific advice (for example, medical, legal, financial or risk management), please seek a professional who is licensed or knowledgeable in that area.
      • - Readers should not judge the importance of topics based on their coverage on Wiki How, nor think a topic is important just because it is the subject of a Wiki article.

      Advertisement